Live data from Hacker News

GDPR and Google Analytics

adactio.com

21–30 of 130 posts

Re: GDPR and Google Analytics

#21
Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters.

What bothers me the most is, as a non-European citizen of a country that has nothing to do with Europe, I'm expected to modify the source code of my website to adhere to their laws, which aren't from my country. The important part: WWW is a global platform to showcase your service/work globally. I have a problem because one entity thinks the global service needs to be customised specifically for them. How about "don't like it, don't visit it?"

Simply put, I don't want to get into an argument whether this GDPR is bad/good, but, I know that I didn't vote for or against this and it's not in my jurisdiction. I don't belong to Europe either, so what are you going to do?

This is what I'm going to do: I'm going to block access to my services to anyone based in Europe. It WILL affect our cash flow in the long run, but, I'm tired of governments that I don't care about expect me to follow some nonsense I have no part of under the guise of compliance on a global platform that is WWW ("WORLD WIDE Web"). I think, if enough webmasters fight back, then they'll realise. And the only way is to block your services to EU.

As a cherry on top, I'll even put up a redirect notice stating:

    "Sorry, you belong to the EU and we're not going to follow 
    your laws. Please fight back with your GOV if you wish to 
    have access to our services. This has nothing to do with 
    us."

So, what are you going to do?

edit: clarity

Re: GDPR and Google Analytics

#22
post #13

Earlier quoted context omitted.

Why are you storing and processing their data if not for profit?

personal data in the GDPR has a very expansive definition, and definitely includes things like IP. Processing likewise has an expansive definition, including collection and recording. Lots of sites will be processing and storing this data for internal analytics.

> Lots of sites will be processing and storing this data for internal analytics.

Just because you can doesn't mean you should. And not asking that questions has got us where we are today.

Re: GDPR and Google Analytics

#23
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

> It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries.

If you don't process PII about people from EU then GDRP does not apply. Merely accessing the page from EU does not trigger GDRP.

Re: GDPR and Google Analytics

#24
post #20
post #16

Earlier quoted context omitted.

It isn't my responsibility to block them, or to take any action whatsoever to comply with another country's laws.

Well, the point of the GDPR is to make you aware that collecting personal data of EU citizens requires their explicit consent. Just ask me for it, that's not a big deal, is it? If you don't, you're effectively stealing from me and I shall expect my government to go after you to the full extent of the law.

What makes you imagine your government has any jurisdiction over me?

EU citizens can choose to use services offered under other countries' laws, or not. The EU can choose to implement their own Great Firewall to block such services, or not. Frankly I don't care either way.

Re: GDPR and Google Analytics

#25
post #15

Earlier quoted context omitted.

It's not their money, it's if you store or process personal data about individuals in the European Economic Area (slightly larger than the EU). If you're running a Chinese site aimed at Chinese you're good. If you're running an Indonesian site aimed at Germans you need to honour the GDPR.

You don't need any personal data to conduct most of the business. I work in a place that would be beyond heavily affected by GDPR and I find the legislation a good change as companies should not hoard data they don't need - just in case... or just to sell.

Wouldn't you need personal data to accept payments? Or maybe a broker (like Stripe) would store these and the end business just a reference to payment.

Re: GDPR and Google Analytics

#26
post #24
post #20

Earlier quoted context omitted.

Well, the point of the GDPR is to make you aware that collecting personal data of EU citizens requires their explicit consent. Just ask me for it, that's not a big deal, is it? If you don't, you're effectively stealing from me and I shall expect my government to go after you to the full extent of the law.

What makes you imagine your government has any jurisdiction over me? EU citizens can choose to use services offered under other countries' laws, or not. The EU can choose to implement their own Great Firewall to block such services, or not. Frankly I don't care either way.

>What makes you imagine your government has any jurisdiction over me?

It doesn't. But once you enter Europe expect to be in trouble (if there is anything going on against you). Also forget to do business in Europe (with EU citizens).

So if you don't care about these, then you don't have to care about this law.

Re: GDPR and Google Analytics

#27
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

You are aware that this does not make sense, since to do business with people from other countries you already have to comply with their laws in terms of taxes and accounting anyway.

Selling to EU customers as US business already requires you to have a VAT ID in EU, so what does this change for you? In the end the main provision is to only require and store customer data which is effectively needed for providing the services and goods you offer. If you are doing business responsibly, this should not affect you at large as it mainly formalises these processes and requires you to actually write down and document what data you need for what processing steps. If you can not do that, your business is already flawed and not because GDPR does not work for you.

Re: GDPR and Google Analytics

#28
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

> It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries.

If you open shop in a different country, you follow their laws. Your website being accessible in a country is seen as the same thing. It's not hard to implement geo blocking if you want to show best effort and thereby opt out of it.

Re: GDPR and Google Analytics

#29

Can the US please just pass this too? The EU's current stance on privacy and individual rights makes me want to pack up my life and move there. I'd much rather the law just come here though.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country.

I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

Re: GDPR and Google Analytics

#30
post #13

Earlier quoted context omitted.

Why are you storing and processing their data if not for profit?

personal data in the GDPR has a very expansive definition, and definitely includes things like IP. Processing likewise has an expansive definition, including collection and recording. Lots of sites will be processing and storing this data for internal analytics.

Did your customers consent to what is effectively someone following them round the store with a clipboard?
Post reply on HN