The Register Home Page

back to article Imgur yanks Brit access to memes as parent company faces fine

The UK's data watchdog has described Imgur's move to block UK users as "a commercial decision" after signaling plans to fine parent company MediaLab. It opened an investigation into various companies, including TikTok and Reddit, in March, focused on how these major platforms handle children's data and verify their ages, which …

  1. VoiceOfTruth Silver badge

    The ICO 'court'

    >> The Information Commissioner's Office's (ICO) interim executive director, Tim Capel, said on Tuesday that its findings from the investigation were provisional, and the regulator would consider any evidence presented by MediaLab before proceeding with a fine.

    Translation: we found them guilty. Let's see if they can present any evidence to get out of it.

    >> Capel also hinted that even if Imgur continues to block UK users, the ICO may still seek to penalize its parent company.

    Good luck with that. It's an American company. The last time I checked they had a revolution to kick out shit people like the ICO.

    The ICO has always been a bullshit organisation. It's a place where useless hand wringers go to polish seats as they squirm on their arses.

    1. Anonymous Coward
      Anonymous Coward

      Re: The ICO 'court'

      Given that Imgur has withdrawn from the UK, it looks like they believe the ICO has teeth. And doing business in the UK means you follow UK law *even if* you don't like those laws. The same applies for any internet based company doing business in any country. You follow the native laws, even if your servers are based outside that country. Sometimes that will mean you have to block geographical IP addresses because you can't or don't want to obey local laws.

      It's very similar to having to obey import and export laws for physical goods.

      1. Graham Dawson

        Re: The ICO 'court'

        They may believe it, but without a financial presence in the UK, there's not much the ICO can actually do to extract a fine. The only next step available is for OFCOM to require ISPs to block the site. Imgur has simply made that decision for them.

        As for following the law; as written, that is essentially impossible. The burden it places on websites is not only expensive, but technically insurmountable for any site that allows inter-personal communication. The only way to fully comply, without leaving yourself open to inevitable loopholes and oversights, is to block all traffic from the UK. Even that can be technically considered a material breach of the law, as it prevents the ICO from assessing compliance while still allowing UK visitors via VPN.

        When a law cannot be obeyed, it is objectively bad law.

        1. AMBxx Silver badge

          Re: The ICO 'court'

          It's no different to the various US sites blocking EU traffic as they can't or don't want to comply with GDPR.

          1. Tron Silver badge

            Re: The ICO 'court'

            The difference is that the UK sites blocking the EU are typically US local news sites that few outside the US visit. The services that are being and will be blocked from the UK are major sites. Basically, the UK is now China. If you were considering a job or Uni place in the UK, ask yourself if you would be happy working in China, with all its internet blocks. If not, don't get a job or Uni place in the UK.

          2. Anonymous Coward
            Anonymous Coward

            Re: The ICO 'court'

            "It's no different to the various US sites blocking EU traffic as they can't or don't want to comply with GDPR."

            It is *a lot* different. ICO here demands that sites collect data they literally *can't* legally collect under GDPR. In EU anyway.

            So ICO demands that sites *break* GDPR in order to satisfy OSA.

            GDPR specifially forbids anyone to collect anything not needed for the site operation and the actual name or age of the person browsing is a legal minefield to anyone, so literally no-one want's to know those.

            Except data thieves, who then sell everything. Like X or Facebook.

            They obviously had better bribes so this law doesn't apply to them at all. They of course break GPDR too, but too big to fail, obviously.

        2. VoiceOfTruth Silver badge

          Re: The ICO 'court'

          >> They may believe it, but without a financial presence in the UK, there's not much the ICO can actually do to extract a fine.

          This. The ICO can pass round the plate of biscuits and tut.

          1. elsergiovolador Silver badge

            Re: The ICO 'court'

            They can also huff and puff or simply pretend everything is fine instead of extracting a fine.

            1. Anonymous Coward
              Anonymous Coward

              Re: The ICO 'court'

              Or, you know, they can place enough pressure on credit card companies and advertisers that Imgur's revenue streams are damaged enough that Imgur cought up the fine.

              1. Anonymous Coward
                Anonymous Coward

                Re: The ICO 'court'

                Imgur are sacrificing the UK part of their business - they largely rely on advertising so the chances of the ICO being able to put pressure on anyone is minimal BUT Imgur has lost access to the UK market.

                This is likely the one of many social media companies that will geofence the UK or introduce a UK government approved ID scheme - either way will likely result in economic consequences for the UK in either jobs or taxes.

                Will the gains actually be measurable or will the rise on VPN services just make seeing what UK users are doing even harder for the government until the rise in "piracy" or loss of disability of what UK citizens are doing online means the UK government has to back down or double down and try and ban VPNs?

              2. botfap

                Re: The ICO 'court'

                Thats just dumb. Credit card companies are not going to sacrifice a global market for a tiny UK market. Especially one that can be bypassed by anyone with a VPN. Get your head out of your arse

        3. DavCrav2

          Re: The ICO 'court'

          You know this isn't about the Online Safety Act, right? A quick Googling reckons the reason the Imgur is in trouble with the ICO is that it:

          1) Did not ask users to state their age when signing up

          2) Did not use any techniques to estimate or verify users’ ages during account setup

          3) Did not ensure children’s profiles are high privacy by default

          4) Did show adverts to children, including targeted ads based on age and location

          These are GDPR-related and not difficult to comply with, unlike some provisions of the OSA.

          1. Graham Dawson

            Re: The ICO 'court'

            That's a fair point. I've had the OSA on my mind a lot recently, so I guess I defaulted to arguing against it. However, you can be certain they've received a OSA notification to imgur as well within the last couple of months. That letter, combined with the recent threat of a fine for the issues you've outlined, is likely what prompted them to throw up their hands and reach for a geoblock.

            Besides, GDPR is a more difficult to comply with that you seem to think. One might say just record the absolute minimum PII necessary to operate, but they're specifically being dinged for not implementing special considerations for juvenile accounts, which requires obtaining some quantity of PII beyond an e-mail and IP address. Ultimately, whatever magic techniques people might believe exist, there is no way to fully determine if someone is a child without asking for some form of ID (and even then they might lie). Asking for ID means at least temporarily obtaining sensitive PII, which in the case of a subsequent subject access request then opens you up to liability for potential failure to prove you've removed it. Proving you don't have something is not an easy task.

            Anyone who actually has to deal with GDPR knows it's difficult and costly to comply with at the best of times, even when you're making the best effort and operating well in the black. When you're starting from the back foot and already operating at a near-loss, it's going to be a expensive nightmare. Much easier to just cut off the problem at source, as so many other non-european services have done.

            1. rg287 Silver badge

              Re: The ICO 'court'

              but they're specifically being dinged for not implementing special considerations for juvenile accounts, which requires obtaining some quantity of PII beyond an e-mail and IP address.

              Treat all accounts as juvenile until proven otherwise. Not hard to do, but it also might affect shareholder value - unacceptable!

              1. Anonymous Coward
                Anonymous Coward

                Re: The ICO 'court'

                I was confused for a moment. I was dealing with an entirely different OSA.

                Are they now even recycling TLAs?

                :)

              2. Anonymous Coward
                Anonymous Coward

                Re: The ICO 'court'

                "Treat all accounts as juvenile until proven otherwise."

                No, that's just fascism: Everyone is a criminal/sub-human unless proven otherwise. But of course fascists love that kind of ideology.

                1. Anonymous Coward
                  Anonymous Coward

                  Re: The ICO 'court'

                  Not being able to read the naughty bits of a website is the same as being treated like a subhuman or a criminal?

                  If you don't show the right ID, the website will - chase you through the streets? What would the equivalent of that be - never allowing you to log off or close the webpage?

                  1. Anonymous Coward
                    Anonymous Coward

                    Re: The ICO 'court'

                    Auto-subscribe you to other social media? That's pretty much the same.

                2. Anonymous Coward
                  Anonymous Coward

                  Re: The ICO 'court'

                  That's not fascism, that's totalitarianism. Pol Pot is sad at you for calling him a fascist.

            2. Anonymous Coward
              Anonymous Coward

              Re: The ICO 'court'

              "they're specifically being dinged for not implementing special considerations for juvenile accounts, "

              Technically Imgur does not have juvenile accounts and ICO is just lying about it claiming they have, without any proof whatsoever: "You don't verify age so you must be a criminal" is the attitude here.

              Guilty unless proven innocent- fascism in action.

              All based on proper fascist piece of legislation designed to find names and IDs of the people who say bad things about UK government in Imgur (or Reddit). That's the only *actual* reason for ASO: Collecting real identities of commenters/posters to be prosecuted later.

              Whatever ICO says is patentable BS, they will never admit the Stasi-nature of the law.

          2. Anonymous Coward
            Anonymous Coward

            Re: The ICO 'court'

            1) Did not ask users to state their age when signing up

            2) Did not use any techniques to estimate or verify users’ ages during account setup

            3) Did not ensure children’s profiles are high privacy by default

            4) Did show adverts to children, including targeted ads based on age and location

            Curiously (4) appears to imply (2) was satisfied.

            The whole exercise seems on the verge of becoming Pythonesque theatre undoubtedly inspired by The Ministry of Silly Walks or The Fish Slapping Dance.

            When "thinking of the children" it is worth remembering they will grow very quickly into adulthood to look back at their elders and think, quite rightly, "what a lot of silly bunts."

          3. Inkey
            Headmaster

            Re: The ICO 'court'

            If it's GDPR related how come they are still active in the rest of Europe? ... From what i understand it's only the UK, which would imply online save the children bollocks

            1. This post has been deleted by its author

              1. rg287 Silver badge

                Re: The ICO 'court'

                It has nothing to do with GDPR and its all down to the UK specific OSA

                The ICO have brought an investigation against Imgur for failing to comply with GDPR. Specifically Article 8 - "Conditions applicable to child's consent in relation to information society services". This was brought in February BEFORE the OSA even came into force.

                Nothing to do with the execrable OSA, which is under the remit of OfCom, not the ICO.

            2. rg287 Silver badge

              Re: The ICO 'court'

              If it's GDPR related how come they are still active in the rest of Europe? ... From what i understand it's only the UK, which would imply online save the children bollocks

              Because GDPR is enforced on a country-by-country basis, although rulings in one country could make cases in other countries easier. Imgur have been dinged by the UK regulator have have blocked the UK. To confuse matter further, some countries - in enacting GDPR - may exceed that minimum baseline, so if they required stricter handling of some particular data then a ruling under that specific countries act (which is not really GDPR, but GDPR-adjacent) would only be locally relevant. That's not really the case here though.

              GDPR requires lawful purpose to process personal data, and it requires that to be handled especially robustly when it relates to especially sensitive data, such as health data and that relating to children. Since Imgur have made basically no effort to comply, they are in breach.

              It's nothing to do with the excreable Online Safety Act, whose enforcement falls to OfCom, not the ICO.

          4. Anonymous Coward
            Anonymous Coward

            Re: The ICO 'court'

            "These are GDPR-related and not difficult to comply with, unlike some provisions of the OSA."

            Bullshit. GDPR doesn't say anything about age and it's *all* OSA (and other non-GDPR legislation about advertising to minors).

            Shifting the blame from ICO to Brussels, aren't we? How much you get paid for that?

            1. rg287 Silver badge

              Re: The ICO 'court'

              Bullshit. GDPR doesn't say anything about age and it's *all* OSA (and other non-GDPR legislation about advertising to minors).

              Wrong. And not just wrong, but trivially checkable. Try harder. The entire world's information at your fingertips and you can't be bothered to do a simple google.

              Are there any specific safeguards for data about children?

              Your company/organisation can only process a child’s personal data on grounds of consent with the explicit consent of their parent or guardian up to a certain age. The age threshold for obtaining parental consent varies between 13 and 16 years, depending on the age established in each EU Member State. Check with your National Data Protection Authority.

              A reasonable effort must be made, taking into consideration available technology, to verify that the consent given is truly in line with the law. That means that your company/organisation must implement age-verification measures (for example control questions, actions on the website).

              It is this which Imgur basically just said "Nah" to.

              -----------------------------

              Article 8 makes specific provisions to the legality of processing children's data - "Conditions applicable to child's consent in relation to information society services"

              1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years.

              2. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology.

              -----------------------------

              This is further expounded in Recital 38, which is not technically an article of GDPR, but it part of it's raison d'être and would therefore be considered in interpreting and ruling on GDPR.

              Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. 2Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child. 3The consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.

        4. This post has been deleted by its author

    2. DavCrav2

      Re: The ICO 'court'

      "Good luck with that. It's an American company."

      1) MediaLab AI Inc. has other brands that currently operate in the UK.A full withdrawal of all services would be required.

      2) MediaLab AI will want to not do business in any country that is a Hague Convention signatory either, I guess?

      Enforcement of fines in other jurisdictions is patchy at the moment, but since this is a protecting-children-online related fine, and MediaLab AI is based in California, and California has recently created a similar law, it might be easier than you think. (Enforcement of foreign judgments is not a federal matter in the US.)

      1. Blazde Silver badge

        Re: The ICO 'court'

        MediaLab AI Inc. has other brands that currently operate in the UK.A full withdrawal of all services would be required

        Worth mentioning they also own Kik Messenger, which has it's own controversy surrounding use by minors which pre-dates acquisition by Medialab. Also Whisper which seems to have shut-down(*).

        The common theme for these brands is anonymity, so they may feel that's a core value incompatible with the UK market. But it's obviously not an easy offering in a lot of other places too now. Or they may just be running these brands into the ground on purpose while collecting data or who knows what.

        (*) https://www.forbes.com/sites/thomasbrewster/2025/04/08/the-wiretap-plagued-by-child-predators-former-200-million-whisper-app-has-disappeared/

      2. Anonymous Coward
        Anonymous Coward

        Re: The ICO 'court'

        " since this is a protecting-children-online related fine"

        No it's not, that's pure bullshit and charge like that would *never* fly in any other country.

        It is a law which mandates that you need to verify your real name and age and ID to *every site there exists* and then they need to give that data to UK government if they happen to ask for it. Which specifially would be illegal under GDPR.

        Tracking users by real name/ID is *a very bad thing* everywhere. Does Stasi sound familiar? Because that's what it is.

        UK is a fascism now, just by this piece of legislation: There's no free speech anymore and this legislation is *designed* to kill anonymous use of internet.

        Anyone who doesn't understand that, hasn't been paying attention.

  2. Anonymous Coward
    Anonymous Coward

    Yet more Starmer authoritarian stateism

    Coming soon to GB land, a China-style social credit system :o

    1. Empire of the Pussycat Silver badge

      Re: Yet more Starmer authoritarian stateism - Oh no it isn't

      It's a tory-brexiter law passed by the tory-brexiters in 2023.

      1. DavCrav2

        Re: Yet more Starmer authoritarian stateism - Oh no it isn't

        This isn't the Online Safety Act. It's a GDPR thing. Imgur aren't putting in any measures to try to determine if a user is a child and still sends them targeted ads, which is against GDPR.

        1. Blazde Silver badge

          Re: Yet more Starmer authoritarian stateism - Oh no it isn't

          It isn't vanilla GDPR though. It's an extra added to the Data Protection Act over-and-above EU requirements.

          Passed under the Tories, but the Lords amendment had cross-party support and was initiated by a genuinely cross-bench peer and debated with - as far as I can see - no real opposition (in fact very enthusiastic support from all parties):

          https://hansard.parliament.uk/lords/2017-12-11/debates/154E7186-2803-46F1-BE15-36387D09B1C3/DataProtectionBill(HL)

          1. rg287 Silver badge

            Re: Yet more Starmer authoritarian stateism - Oh no it isn't

            It isn't vanilla GDPR though. It's an extra added to the Data Protection Act over-and-above EU requirements.

            The EU disagree! See Article 8 - "Conditions applicable to child's consent in relation to information society services", which is backed by Recital 38 - "Special Protection of Children's Personal Data".

            You've just managed to link to a specific Lords discussion about the UK implementation of this article and inferred that it's UK-specific. But the underlying law is vanilla GDPR and EU-wide.

            The ICO have brought an investigation against Imgur for failing to comply with GDPR.

            1. Blazde Silver badge

              Re: Yet more Starmer authoritarian stateism - Oh no it isn't

              Nope, it's much more broad. I linked the Lords discussion because it's relevant to which political party is responsible, but you can also infer from the debate that this is something achieved over-and-above basic GDPR responsibilities. The Children's Code itself is here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/

              It's compatible with EU GDPR in the sense that it adheres to the two or three age-related quotes you've produced as well as the rest of the GDPR, but it imposes many more requirements on online service design than a website owner would ever imagine they'd have by reading EU legislation and waiting for court precedents to trickle in. Sure, Recital 38 is a starting point but it's up to member states (+ UK) how far they run with that.

              The most critical part of the primary UK legislation is perhaps:

              “standards of age-appropriate design of relevant information society services” means such standards of age-appropriate design of such services as appear to the Commissioner to be desirable having regard to the best interests of children
              [Emphasis mine].

              In other words whatever the ICO thinks is best (the Code was subsequently given the nod by Parliament). Among other things they've decided 16 and 17 year olds come under this remit, while EU GDPR child-specific requirements stop at under-16 as far as I know(*), and they spend a lot of words on user interface design rather than data processing itself.

              (*)Confusingly perhaps, the UK's implementation of GDPR opts to use 13 years old rather than 16 in Article 8.1 about consent.

        2. Anonymous Coward
          Anonymous Coward

          Re: Yet more Starmer authoritarian stateism - Oh no it isn't

          " Imgur aren't putting in any measures to try to determine if a user is a child and still sends them targeted ads, which is against GDPR."

          False. Not a single site checks that as it's *not* against GDPR.

          Does theregister check user age? Of course not. But shows ads. What are you talking about even?

      2. SsiethAnabuki

        Re: Yet more Starmer authoritarian stateism - Oh no it isn't

        GDPR isn't a Tory law. It's adopted from the EU and is actually a pretty damn good bit of legislation. If you can't comply with GDPR then you really shouldn't be providing web services of any sort.

        1. 42656e4d203239

          Re: Yet more Starmer authoritarian stateism - Oh no it isn't

          >>GDPR isn't a Tory law. It's adopted from the EU

          Err I think you will find the main driver behind the GDPR (EU) was.... the UK! When we divorced our geographical neighbours we just copied the GDPR(EU) legislation into our own as an interim measure (and we all know how interim measures go)

          >>is actually a pretty damn good bit of legislation

          Yup. It, unusually, does what it says on the tin

          >>If you can't comply with GDPR then you really shouldn't be providing web services of any sort.

          Indeed.

          1. rg287 Silver badge

            Re: Yet more Starmer authoritarian stateism - Oh no it isn't

            When we divorced our geographical neighbours we just copied the GDPR(EU) legislation into our own as an interim measure (and we all know how interim measures go)

            Not quite right. We enacted the EU Regulation into UK law via the Data Protection Act 2018. This is normal - you require a bit of domestic legislation to deal with local/domestic legalities of things like "you must have a regulator".

            So we didn't copy GDPR into UK law at the point of Brexit. It was already a part of UK law which would require manual repeal by Parliament, and we haven't bothered (although such a move would be Very BadTM for British business given that it would halt data transfers between us and our biggest trading partner).

        2. Anonymous Coward
          Anonymous Coward

          Re: Yet more Starmer authoritarian stateism - Oh no it isn't

          GDPR isn't a Tory law. It's adopted from the EU..

          .. which based it on all the rather well worked out parts of then already established Data Protection Act. Yes, the UK got there first.

          Shame they seem to be abandoning bits of it post Brexit.

        3. Anonymous Coward
          Anonymous Coward

          Re: Yet more Starmer authoritarian stateism - Oh no it isn't

          "GDPR isn't a Tory law."

          But this isn't about GDPR, it's about OSA. Irrelevant argument.

          1. rg287 Silver badge

            Re: Yet more Starmer authoritarian stateism - Oh no it isn't

            But this isn't about GDPR, it's about OSA. Irrelevant argument.

            The ICO have brought an investigation against Imgur for failing to comply with GDPR. Specifically Article 8 - "Conditions applicable to child's consent in relation to information society services". This was brought in February BEFORE the OSA even came into force.

            It's not about adult content. It's about serving personalised ads to children, through the unlawful processing of PII.

            Nothing to do with the execrable OSA, which is under the remit of OfCom, not the ICO.

      3. hoola Silver badge

        Re: Yet more Starmer authoritarian stateism - Oh no it isn't

        Maybe I am mistaken, I thought GDPR is a European Union piece of legislation

        After the UK formally left the EU GDPR was adopted. There was a top up that added some more details that had cross party support in the Commons and Lords.

        Nothing to do with Brexit of a particular political party.

  3. Alan J. Wylie

    "a 400 error page"

    I hope that was 451 (Ray Bradbury reference).

  4. Nedly

    what an absolute shambles of a country we live in

    This is just utterly atrocious news, a big pile of steaming poo

  5. Empire of the Pussycat Silver badge

    I can't see the UK being a major profit source for many of these companies

    Easy option is to exit the UK, it just doesn't matter.

    The inevitable consequence of squandering genuine power and influence in return for the fantasy of sovereignty.

  6. Anonymous Coward
    Anonymous Coward

    Crazed bureaucrats

    These power-crazed goons hurt only the UK. US companies will just disconnect the UK from the Internet.

    I saw that Bible Gateway, the main site for looking up bible verses in all sorts of languages, vanished. No doubt the ICO threatened them too.

    So authoritarian.

    1. VoiceOfTruth Silver badge

      Re: Crazed bureaucrats

      Britain is not a free country. Think of the children is now the excuse for every kind of state surveillance.

      1. elsergiovolador Silver badge

        Re: Crazed bureaucrats

        Not sure why you getting downvotes. Government is bought by big corporations. They "voted" for these changes with their brown envelopes, which carry more weight than ballot papers. Politician cannot buy a mansion showing the poll results.

    2. SsiethAnabuki

      Re: Crazed bureaucrats

      It's not a UK-originated law that was broken but GDPR which applies across the EU (and the UK).

      The breaches of GDPR are pretty damn obvious and easy to rectify.

      Bible Gateway is readily accessible from the UK.

      US companies will do nothing that hits their bottom line.

      1. Anonymous Coward
        Anonymous Coward

        Re: Crazed bureaucrats

        "It's not a UK-originated law that was broken but GDPR which applies across the EU (and the UK)."

        Irrelevant as they weren't charged for that. And the law they *were* charged with, *is* wholly UK made.

      2. This post has been deleted by its author

        1. rg287 Silver badge

          Re: Crazed bureaucrats

          It has nothing to do with GDPR. Why do people keep repeating this lie? Its due to the OSA

          Why do YOU keep repeating this lie?

          The ICO have brought an investigation against Imgur for failing to comply with GDPR. Specifically Article 8 - "Conditions applicable to child's consent in relation to information society services". This was brought in February BEFORE the OSA even came into force.

          It's not about adult content. It's about serving personalised ads to children, through the unlawful processing of PII.

          Nothing to do with the execrable OSA, which is under the remit of OfCom, not the ICO.

    3. Irongut Silver badge

      Re: Crazed bureaucrats

      That's ok we'll do fine without your Christian fundamentalist crap. In fact we forced you to travel across an entire ocean to subjugate another country because we didn't want it in the first place.

  7. Robin Bradshaw

    Reddit next

    While looking at the age verification of Reddit I noticed it only forces you to verifiy your age if you are logged in. To view adult subreddits without verifying your age you can logout or open an incognito window then right click and inspect element on the mature content warning and delete the "blocking-modal" to view it. Ublock origin already has rules for this in its optional "uBlock filters – Annoyances" list.

    With blocking that innefective im sure they will be next for a fine from the ICO/Ofcom and posibly blocking the UK as its easier.

    1. DavCrav2

      Re: Reddit next

      Reddit is indeed under investigation for almost exactly the same GDPR offences.

      1. Anonymous Coward
        Anonymous Coward

        Re: Reddit next

        "Reddit is indeed under investigation for almost exactly the same GDPR offences."

        GDPR doesn't say anything at all about age, so no, that's pure bullshit.

        Also: GDPR says you have to have a reason to collect data you do collect and how you need to store it. No more, no less.

        Everything else is made-up BS by ICO. And of course they know it, they aren't stupid, they are criminals: Data hoarders like Stasi.

        1. Anonymous Coward
          Anonymous Coward

          Re: Reddit next

          https://www.europarl.europa.eu/RegData/etudes/ATAG/2023/739350/EPRS_ATA(2023)739350_EN.pdf

          "Prior to the adoption of the General Data Protection Regulation (GDPR), which came into effect in 2018,

          there were no specific restrictions on the online processing of children's data in Europe. The GDPR requires

          the use of verification with regard to age and parental consent. "

          Found that on the 3rd result on a Google search for "gdpr age verification". Even the Gemini result got it right, why can't you? Why are you deliberately trying to mislead?

          Being legally required to collect a piece of data also counts as a reason to collect and store that data.

    2. mark l 2 Silver badge

      Re: Reddit next

      Since the ICO is a gov dept they are almost certainly just using Windows and Google Chrome as their browser.

      Any mention of Firefox or Ublock Origin an they will probably look at you with their head tilted like a confused puppy.

    3. Irongut Silver badge

      Re: Reddit next

      Reddit has age verification?

      I have not seen it and my account is not old enough to vote.

      1. Outski

        Re: Reddit next

        It does for certain elements deemed to be NSFM (M being minors), using facial age estimation.

        1. Anonymous Coward
          Anonymous Coward

          Re: Reddit next

          I'm guessing hits to https://thispersondoesnotexist.com/ must have gone up then ..

      2. Anonymous Coward
        Anonymous Coward

        Re: Reddit next

        Kind of, if you want to see NSFW-subreddits.

        Basically irrelevant as it's just a yes/no -question. Obviously that's not enough for ICO.

  8. tim 13

    Imgur are still serving image files to people in the UK

    Its just one image, a purple one, but legally no different, surely?

  9. Anonymous Coward
    Anonymous Coward

    I wonder

    With this sort of thing and the Online Safety Act, maybe all social media companies will have to withdraw from the UK,

    Making the UK instantly the happiest and most productive country in the world.

    1. elsergiovolador Silver badge

      Re: I wonder

      All small social media companies. The law is glaringly obviously written for benefit of Facebooks. Corrupt to the core.

  10. Anonymous Coward
    Anonymous Coward

    Just shut off all internet for the UK until their government stops the BS.

  11. AVR Silver badge

    VPNs still work

    It's still possible for UK residents to access Imgur via VPN. It does make it unlikely that Brits will see imbedded images but those with enough interest to log into the site can still get there.

  12. Claptrap314 Silver badge

    US vs GDPR

    I was involved with compliance (among other things) at my last job--at a US health care company. EVERY survey asked about GDPR compliance. We responded that we were not responsive to it, but that we did comply with the California act.

    LOTs of SMBs in the US will respond that way.

  13. ABugNamedJune

    Imgur still exists?

    I assumed it stopped existing after Reddit finally got around to hosting images themselves. Who the hell is still using Imgur?

    1. DS999 Silver badge

      Re: Imgur still exists?

      I suppose it will be a problem for older links that break, but this would be just another in a long line broken links from companies going out of business, URL shortening URLs no longer active, websites changing their layout breaking direct links, etc. etc.

    2. Anonymous Coward
      Anonymous Coward

      Re: Imgur still exists?

      "Who the hell is still using Imgur?"

      Have you ever used the picture browser Reddit offers? I see you haven't, otherwise you wouldn't ask.

      Imgur had 16M users before the owner went moralistic and banned everything NSFW from there, but they still have something like 6M.

      Which also makes ICOs point absolutely moot: There's literally nothing there a kid shouldn't see: All banned.

      Ads? You see more ads on Google's homepage and that *definitely* does not ask your age, so ICO is lying and there are other reasons behind this crusade.

    3. tim 13

      Re: Imgur still exists?

      I used to host images for a small web forum I'm a member of.

  14. Anonymous Coward
    Anonymous Coward

    It's *not* about children. It newer was.

    Anyone who believes it's about children, is a moron.

    What you have, is a legislation forcing *everyone* to have a real identity just for seeing *any* content. And proof of said identity, i.e. age, i.e. passport number and a picture or something like that.

    That is not an accident or even a by-product, it's intentional and the sole real reason for whole legislation to exist.

    Stasi-level monitoring for *everyone*. Just by spewing a lot of "think of the children" BS. That's how easy it is.

    Not only that, that information is collected by 3rd parties and they can do whatever they want with that information: A literal gold mine for data collector: Confirmed identities and browsing history.

    Imgur specifially is an insteresting case, as whole site is as kid safe as BBC television broacasts. Probably even more so. So ICO is just being an asshole here, while Facebook and X aren't suitable for anyone, even less for kids. They obviously had more money for bribes, so it's time to attack small fish instead of the big ones.

  15. may_i Silver badge

    Oh, the irony!

    The law of 'unintended consequences' comes back to bite the fools that drafted this idiotic legislation.

    UK Internet users get a great education about using VPNs.

    Fake VPN sites harvest UK identities and credit cards like never before.

    Companies not based in the UK, cut UK users off from their services rather than act as gatekeepers for their customers.

    Just wait until the Danish government is done with pushing through Chat Control and client side scanning in the EU. Then you'll see US companies abandoning the EU in droves. Or most likely not. The big ones will just comply. A revolution in the use of retro mobile telephones will begin. Hopefully.

  16. Anonymous Coward
    Anonymous Coward

    Tried to delete my account

    Which went well. "Go to our support page and put in a GDPR/CCPA account deletion request!"

    So I do that, giving them my email address etc in the provided fields. Get an auto responder:

    "We have received your request to delete your Imgur account and all associated data. To move forward, we need to verify your identity. Please log into your Imgur account and follow the instructions provided here to complete the deletion process."

    Guess what you explicitly cannot do in the UK.

    (it's log in)

    Sidestepping the chuntering about the whys of all this, I think we can all agree that "You have to do the thing we explicitly and deliberately stopped you from being able to do, to delete your account" is a fantastic bit of stupidity.

    And not likely to help them defend any assertions from the ICO that they are in breach of GDPR, as they appear to be suggesting - I'm fairly sure "fuck you we got your data and we're now gonna prevent you from telling us you want to delete it" is a pretty flagrant breach of GDPR, probably in multiple ways.

    Oh well, a separate support ticket under "I am having difficulty deactivating my account" (as opposed to the recommended paths as noted here: https://help.imgur.com/hc/en-us/articles/41592665292443-Imgur-access-in-the-United-Kingdom - the GDPR one is the one that didn't work ) has been put in.

    (And no, I'm not setting up a VPN to deal with this problem; Imgur want to pull out of the UK? That was their choice, and thus it's their responsibility to allow me to delete my account and remove my data from their systems, without going through unnecessary additional hoops)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like