# GDPR  trolls 防御？

**URL:** <https://meta.discourse.org/t/gdpr-troll-defense/89026>\
**Category:** Community Building\
**Tags:** gdpr\
**Created:** [2018年六月3日 04:50 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026 "2018-06-03T04:50:16Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)\
**Post date:** [2018年六月4日 14:31 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/22 "2018-06-04T14:31:56Z")

</div>

> [@KajMagnus](#):
>
> What if Discourse looked at the troll email, and created a standard response + instructions to Discourse forum admins, about how to reply to these requests?

When dealing with spammers, Discourse typically flags their posts, or automatically hides/deletes them.

If Discourse could recognize this copy-pasted nightmare letter, it could (optionally) do something similar. Suspend/silence the user and then notify moderators and admins that there is a user who should be anonymized or nuked. This could be a useful plugin. Some sort of Clippy response? “It looks like you are writing a letter to be forgotten from the forums!”

---

<div class="post-metadata">

**Author:** ![jtbayly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jtbayly/32/119510_2.png) [@jtbayly](https://meta.discourse.org/u/jtbayly)\
**Post date:** [2018年六月4日 14:46 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/23 "2018-06-04T14:46:11Z")

</div>

Sounds like a waste of energy to me. I highly doubt these letters would be sent via the forum itself.

---

<div class="post-metadata">

**Author:** ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)\
**Post date:** [2018年六月4日 14:49 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/24 "2018-06-04T14:49:19Z")

</div>

> [@jtbayly](#):
>
> I highly doubt these letters would be sent via the forum itself.

Agreed, which makes the OP pointless. But if there’s a Discourse feature here somewhere, then gdpr trolls should be treated like regular trolls.

---

<div class="post-metadata">

**Author:** ![notriddle](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/notriddle/32/133055_2.png) [@notriddle](https://meta.discourse.org/u/notriddle)\
**Post date:** [2018年六月4日 15:32 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/25 "2018-06-04T15:32:28Z")

</div>

You don’t just need to deal with trolls, though. You also need to be able to deal with actual contributors who want to know how much data you’re collecting and sharing.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2018年六月4日 20:15 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/26 "2018-06-04T20:15:22Z")

</div>

> [@KajMagnus](#):
>
> I think the CC-By license doesn’t allow that — attribution required, but anonymizing the account = attribution gone.

Yes it does, if the author requests it.

> [@KajMagnus](#):
>
> I don’t think the troll request asked for that though

Yes, they did.

> [@notriddle](#):
>
> You don’t just need to deal with trolls, though

Refer to the title of the topic, please.

---

<div class="post-metadata">

**Author:** ![KajMagnus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/kajmagnus/32/49264_2.png) [@KajMagnus](https://meta.discourse.org/u/KajMagnus)\
**Post date:** [2018年六月5日 03:06 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/27 "2018-06-05T03:06:46Z")

</div>

> [@codinghorror](#):
>
> > I don’t think the troll request asked for that [= to be made anonymous] though
> 
> Yes, they did.

Ok. I’m thinking that you’ve been in contact with `bradrydzewski` then (i.e. he who runs the Drone .io forum and decided to move to Reddit), and he has told you a bit more details than what is available in the threads linked above (?). In those threads (_Shutting Down Forum (GDPR)_ and the two about _the Nightmare GDPR Letter_) I don’t see any request about deleting or anonymizing one’s data. (The letter asks for a copy of, or access to, one’s data though)

---

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [2018年六月5日 06:26 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/28 "2018-06-05T06:26:40Z")

</div>

> [@codinghorror](#):
>
> So if you get a scarygram, confirm it’s a valid user (not a troll with no account), then anonymize the account with a few clicks. Done and done.

If you were performing any kind of unlawful processing, this could be considered destroying evidence of a criminal act. If you were not performing any kind of unlawful processing, you could just have a template with all the answers.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2018年六月5日 06:54 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/29 "2018-06-05T06:54:31Z")

</div>

Again I refer you to the topic title. I’ll bold the relevant words.

> GDPR **TROLL** defense

this isn’t a good faith user, this is someone out to use GDPR to annoy and harass others.

---

<div class="post-metadata">

**Author:** ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)\
**Post date:** [2018年六月5日 07:36 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/34 "2018-06-05T07:36:24Z")

</div>

Let’s all keep cool 🍦

> [@RGJ](#):
>
> In Europe it’s not very common to send letters to regulatory institutes or to your congressman or senator. In the EU there is no perception of a ‘mania’ regarding GDPR either - there is no overwhelming feeling of vagueness.

Actually I disagree on one level. I have written to my Member of Parliament and found it very effective. He is very responsive and responsible and you do feel he is listening and will take action if you can convince him there is a genuine issue - but the onus is on you to do that.

However, I do agree if you are inferring that Members of the European Parliament are one step removed from your national MPs and this makes them seem less directly accountable. However, I have also found them very responsive to communication. I think they appreciate the engagement and interest. But again you really have to convince them there is a genuine issue. People need to get more used to engaging with their MEPs in the EU.

I also agree with you that GDPR seems reasonable. In some ways it’s simply a structured statement of what is simply good practice. I am just keen to find the right balance and an efficient way to implement it.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2018年六月5日 07:48 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/36 "2018-06-05T07:48:41Z")

</div>

To summarize…

 ![image](https://global.discourse-cdn.com/meta/original/3X/2/b/2b0330ce243464d309cf910c57d570e1cc60917b.png)

… when a GDPR request is made **IN BAD FAITH** , by someone who is **CLEARLY trolling**..

1. Your public privacy policy and general hosting info should cover all the basic reasonable questions anyone rational and non-trolly would ask related to GDPR. If not, edit them to do so. Otherwise you’ll be answering people individually, which doesn’t scale. This is probably the main action item that would come out of this topic.

2. Verify this person is actually a real user, e.g. did they provide proof that they have a functional account on your site? You’ll need to know the account for the next step as well.

3. Compose your reply. Refer them to the public info from step 1 (or edit the public info so it covers the reasonable parts), then anonymize their account, and indicate that all their data has, per their request, been anonymized and is no longer associated with any person.

So, now the amount of effort **expended on a troll acting in bad faith** is rather reasonable – a form reply with link to public info, plus a click or tap on the anonymization button for their account to ensure there’s no personal info to trouble them any more.

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [2018年六月5日 07:54 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/37 "2018-06-05T07:54:05Z")

</div>

I would add a “give the 24-48” hours to click download button on profile

You have like 30 days to respond to these things it’s not like the world needs to stop for the troll

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [2018年六月5日 08:19 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/39 "2018-06-05T08:19:19Z")

</div>

I actually think this is stressing me out, every suggestion I made came back with OH but laws and read through all this giant list of things I prepared earlier etc.

I need a break from this topic, someone email your government rep or the EFF, closing this for 1 week

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [2018年六月5日 08:19 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/40 "2018-06-05T08:19:44Z")

</div>



---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [2018年六月10日 22:00 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/41 "2018-06-10T22:00:05Z")

</div>

This topic was automatically opened after 5 days.

---

<div class="post-metadata">

**Author:** ![thephotographyblog](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thephotographyblog/32/124018_2.png) [@thephotographyblog](https://meta.discourse.org/u/thephotographyblog)\
**Post date:** [2018年六月11日 06:12 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/42 "2018-06-11T06:12:20Z")

</div>

Not only for people who can’t afford lawyers. So many lawyers have refused to give guidance, because they don’t want to accept responsibility for something that they don’t understand. The whole thing is a mess, but if I’m not wrong, if the Drone forum owner would have written a response explaining to the troll, he wouldn’t have had to shut down the forum. I mean, the troll wouldn’t have gone as far as to file a lawsuit anyway, because they’re just a troll, so the sending the letter doesn’t really mean anything.

For example, if I personally send the letter to every single one of you, that doesn’t mean that you all have to close your forums now. Don’t worry, I won’t, but my point still stands.

---

<div class="post-metadata">

**Author:** ![Bas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bas/32/294929_2.png) [@Bas](https://meta.discourse.org/u/Bas)\
**Post date:** [2018年六月11日 07:33 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/43 "2018-06-11T07:33:25Z")

</div>

> [@thephotographyblog](#):
>
> the troll wouldn’t have gone as far as to file a lawsuit anyway

Please note: Suing is a very American way of looking at this, that’s basically not what the European GDPR is focused on. The troll can file a report at the Privacy Agency of the country. They will most likely ignore it until there are more.  
If there is gross negligence, then they (the agency) will take action (which most likely will consider of a written warning before any fines are filed.)

---

<div class="post-metadata">

**Author:** ![thephotographyblog](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thephotographyblog/32/124018_2.png) [@thephotographyblog](https://meta.discourse.org/u/thephotographyblog)\
**Post date:** [2018年六月11日 07:46 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/44 "2018-06-11T07:46:39Z")

</div>

Yeah exactly my point entirely.

They would have had to take further action before the troll could have been taken seriously. I can’t believe they closed the forum just for something like that.

---

<div class="post-metadata">

**Author:** ![thephotographyblog](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thephotographyblog/32/124018_2.png) [@thephotographyblog](https://meta.discourse.org/u/thephotographyblog)\
**Post date:** [2018年六月18日 05:10 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/45 "2018-06-18T05:10:10Z")

</div>

If someone would have sent you the same letter, would you have just dropped everything and deleted your forum?

---

<div class="post-metadata">

**Author:** ![Bas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bas/32/294929_2.png) [@Bas](https://meta.discourse.org/u/Bas)\
**Post date:** [2018年六月18日 08:12 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/46 "2018-06-18T08:12:41Z")

</div>

No, I would not have deleted my forum

That said, if I had contemplated deleting it before, it might be the straw that broke the camel’s back though.

---

<div class="post-metadata">

**Author:** ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)\
**Post date:** [2018年六月18日 14:35 UTC](https://meta.discourse.org/t/gdpr-troll-defense/89026/47 "2018-06-18T14:35:36Z")

</div>

I learned yesterday that there is an important twist to this “horror letter thing” (at least in Germany, but possibly in other countries too): so far we have been talking about letters which have their legal base directly in the GDPR. But there is another kind of letter which has its base in [the law against unfair competition](https://dejure.org/gesetze/UWG). The aim of this law is, well, to prevent unfair competition and one way you can engage in unfair competition is by not following regulations which are “[also aimed at regulating market behaviour](https://dejure.org/gesetze/UWG/3a.html)” (the idea being that your law abiding competitor would have a disadvantage by following the law). If you become aware that your competitor not following some relevant regulation, you can ask your lawyer to send a letter of caution to your competitor, asking them to stop whatever they are doing.

So far so good. The problem is that the fees that lawyers charge for these letters can be quite high, depending on the (assumed) value of the litigation. And, you guessed right, it is the recipient who will be billed the fee for that letter.

This law has long been abused by certain lawyers by sending letters of caution for minor offences (or even no offences at all) with the sole purpose of cashing the fee for the letter. From their perspective, GDPR looks like an excellent opportunity for sending some more letters of caution. The [easiest way to start](https://www.heise.de/newsticker/meldung/DSGVO-Die-Abmahn-Maschinerie-ist-angelaufen-4061044.html) is by looking at the websites of their colleagues (i.e. other lawyers) to see if they are providing all the information required by the GDPR. If not: Bingo! 💵

I’m mentioning this because the legal construct is fundamentally different from what we have been talking about so far. What both types of letters have in common is the uncertainty connected to a new law that hasn’t yet been tested in court. But in the case of the second type of letter, the unknown is not the GDPR itselöf but whether the GDPR actually constitutes a regulation that is “[also aimed at regulating market market behaviour](https://dejure.org/gesetze/UWG/3a.html)”. If it does not, the whole business model described above collapses. But until that has been ruled by a high court, there is plenty of time for sending those letters anyway.

[上一頁](https://meta.discourse.org/t/gdpr-troll-defense/89026.md?page=1)
