Live data from Hacker News

GDPR and Google Analytics

adactio.com

41–50 of 130 posts

Re: GDPR and Google Analytics

#41
post #24

Earlier quoted context omitted.

What makes you imagine your government has any jurisdiction over me? EU citizens can choose to use services offered under other countries' laws, or not. The EU can choose to implement their own Great Firewall to block such services, or not. Frankly I don't care either way.

>What makes you imagine your government has any jurisdiction over me? It doesn't. But once you enter Europe expect to be in trouble (if there is anything going on against you). Also forget to do business in Europe (with EU citizens). So if you don't care about these, then you don't have to care about this law.

Right, hypothetically if I were to physically enter the EU I could expect trouble, and that's the EU's right. But in the meanwhile, if EU citizens wanted to do business with me, that's not my problem.

I basically agree with your assessment.

Re: GDPR and Google Analytics

#42
post #10

My problem with the GDPR is the EU can't even be bothered to tell us what it is before the effective date. And the GDPR itself is quite vague; lots of balancing tests and blah blah with very little guidelines on what those mean in practice. So where do the guidelines come from? Funny you should ask. Consider the ICO -- the UK privacy commission -- has been promising final GDPR guidance for perhaps half a year now, an…

While I largely agree with you, for the most part enough guidance has been available that many companies have been preparing to handle GDPR. They should have done a far, far better job with this but it's not entirely a "We won't know anything until late Feb" kind of thing.

Re: GDPR and Google Analytics

#43
post #29

Earlier quoted context omitted.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.

Re: GDPR and Google Analytics

#44
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

To me this reads with the focus in reverse. The EU's aim is not specifically to regulate or punish non-EU service providers - rather, that's (one effect of) the tool they are using to protect the rights of its citizens which is the real focus here. Since service providers the world over have been unwilling to voluntarily protect those rights, what alternative approach could they take?

Re: GDPR and Google Analytics

#45
Why doesn't the main browsers implement some mechanism to help with the notification and consent of cookies?

Some standards based description about the cookies/etc. that could be consented. Non-consent means the cookie isn't accepted by the browser.

Re: GDPR and Google Analytics

#46
post #43

Earlier quoted context omitted.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website." The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.

Looking at the EUs antitrust fine for Google - https://www.google.ch/amp/s/www.bloomberg.com/amp/news/artic... it's clear it does have the ability. The message is "you want to profit from EU citizens? You follow the rules"

Re: GDPR and Google Analytics

#47
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

Maybe I’m misunderstanding GDPR, can you explain how tracking your users through logs is OK within the GDPR, but Google Analytics isn’t Ok.

Re: GDPR and Google Analytics

#48

Earlier quoted context omitted.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

Indeed. The idea that a country would zealously protect it's citizens' rights is practically unheard of these days, but that's what's starting to happen. GDPR is a great example, another one was Canada pushing a Right To Be Forgotten ruling worldwide as well. It's a statement that someone's private data and intellectual property is theirs. You aren't free to steal it just because you're in another country. Google and…

>It's a statement that someone's private data and intellectual property is theirs

Private data is data you don't share. Under some very limited circumstances, you might entrust private data to a third party for safekeeping, i.e. Dropbox, Google Photos, iCloud Drive, and it's important that they not leak or abuse it.

But that's only a tiny portion of what the GDPR is about. It concerns records of your interactions with others. It's a statement that one side of an interaction is entitled to force the other side to delete their memory of that interaction, or to dictate the situations under which they are permitted to remember it.

Re: GDPR and Google Analytics

#49
post #36
post #21

Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen o…

Imagine you’re living in a country which allows you to sell drugs freely, then it’s clear that you can sell them in a country where they are banned. I don’t really think this is different regarding privacy. You have to obey to the law where you run your business. It’s up to you wether you change your business or leave the market. Your argument that it’s weird that you have to “adhere to their laws” is a fallacy. Your…

While I agree with most of what you said, where my perspective differs is this - The WWW is called the World Wide Web for a reason. A platform to showcase your service globally, without borders.

Suddenly, the EU thinks "Oh, if you have a website that is accessible from the EU, then you need to display X". Sorry, then what was the point of WWW? And more important, why should I update my code? It costs me money and you're not paying me, obviously (you = GOV). Why don't you ask your citizens to stop visiting websites that track them? I showcase my service on a global platform. Don't like it? Don't visit it.

Re: GDPR and Google Analytics

#50
post #29

Earlier quoted context omitted.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

To which the entirely reasonable response from anyone without a legal nexus in the EU (or physical products to ship) is "we don't care and you have no legal right or ability to enforce that". And the entirely reasonable response from anyone thinking of creating a legal nexus in the EU without an extremely business-critical reason is "let's stay in our own country where it's safer and we only have one jurisdiction to care about".

For the record, when I build services, I personally don't intend to ever keep any records that aren't absolutely necessary to provide the service. That's a personal decision, a voluntary one, and also one that can be marketed to certain customers, though that isn't the reason. I also believe that if you send data to a website then it becomes subject to whatever terms they want to apply to it, and if you don't like how they use your data then don't send it to them, and block them.

Post reply on HN