Live data from Hacker News

GDPR and Google Analytics

adactio.com

61–70 of 130 posts

Re: GDPR and Google Analytics

#61
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

You are aware that this does not make sense, since to do business with people from other countries you already have to comply with their laws in terms of taxes and accounting anyway. Selling to EU customers as US business already requires you to have a VAT ID in EU, so what does this change for you? In the end the main provision is to only require and store customer data which is effectively needed for providing the…

> Selling to EU customers as US business already requires you to have a VAT ID in EU

That's not quite right. If you are digital service provider based in the US, no, you don't need EU VAT ID.

Re: GDPR and Google Analytics

#62
post #31
post #24

Earlier quoted context omitted.

What makes you imagine your government has any jurisdiction over me? EU citizens can choose to use services offered under other countries' laws, or not. The EU can choose to implement their own Great Firewall to block such services, or not. Frankly I don't care either way.

Uh? This is already how the world works. It does not matter where you are located as long are you are transacting with EU citizens. In extreme cases of non-compliance, avenues for enforcement that have been discussed reuse existing Anti Money Laundering mechanisms: once flagged in the system, banks will simply freeze your business assets connected to EU countries and you might be arrested upon crossing any EU border.

I have no business assets connected to any EU countries, and I don't have any desire to cross any EU borders. So I will continue to enjoy life in my home country and ignore your provincial laws.

Re: GDPR and Google Analytics

#63

Earlier quoted context omitted.

>It's a statement that someone's private data and intellectual property is theirs Private data is data you don't share. Under some very limited circumstances, you might entrust private data to a third party for safekeeping, i.e. Dropbox, Google Photos, iCloud Drive, and it's important that they not leak or abuse it. But that's only a tiny portion of what the GDPR is about. It concerns records of your interactions wit…

You are anthropomorphizing companies here, and I think it's a pretty poor analogy. Corporations do not have a memory, they have records, and those records comprise the personal data of everyone who encounters them; data those companies don't own. You seem to be characterizing GDPR as unfair towards the corporate end of the interaction, but that ignores the massive power differential that currently exists. Corporation…

>data those companies don't own

I don't know if it's possible to have a productive discussion about what seems to be a question of fundamental philosophy and values, but that's ridiculous on its face.

If I'm a shop owner and a customer buys something from me, the cash register prints two receipts: one the customer owns, one I own. If a customer writes me an email, I own my copy of that email. If a customer comes in and makes a scene, and I ban him from my stores's premises, the paper I generate telling my staff to call the police if they seem him is mine.

If I follow him around and write down everywhere he goes... at some point a line gets crossed, sure. If I start asking other shopkeepers if they've seen him or what he purchased, yeah, something's wrong. But to claim that my records of the interactions he knowingly, willingly had with me are his property just sounds bizarre.

>Realistically, this is not going to impact small companies a lot. This is about big ad and tech companies, and giving citizens some minor semblance of tools to resist them.

The GDPR does not discriminate by the size of the operation. It's large companies which can reliably afford the consultant, lawyer, and engineering time to understand and adapt to new regulation. The violators are going to be those without security and compliance departments.

Re: GDPR and Google Analytics

#64
post #47

Earlier quoted context omitted.

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

Maybe I’m misunderstanding GDPR, can you explain how tracking your users through logs is OK within the GDPR, but Google Analytics isn’t Ok.

Logfiles are necessary to operate a service securely and guarantee quality of service. This is one form of implicit consent that users are giving you without you having to ask them for it.

But Storing IP addresses for each access indefinitely (> some days) is the problem.

If you rotate the files into a version where IP addresses are without the last part after a few days, then this is considered pseudonymous data and GDPR has no problem with you keeping this for a long time anymore.

Re: GDPR and Google Analytics

#65
post #21

Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen o…

If your website is of any use, they will be copied from an EU-internal website that adheres to local legislation. If you subsequently tried to sue according to your country's legal concepts, whatever, why should they adhere to another country's legal requirements?

Re: GDPR and Google Analytics

#66

Why doesn't the main browsers implement some mechanism to help with the notification and consent of cookies? Some standards based description about the cookies/etc. that could be consented. Non-consent means the cookie isn't accepted by the browser.

Certainly with the cookie law, I feel the EU should have legislated the top browser makers to make this a spec and be implemented in the browser, than to rely on each and every website.

Re: GDPR and Google Analytics

#67
post #29

Can the US please just pass this too? The EU's current stance on privacy and individual rights makes me want to pack up my life and move there. I'd much rather the law just come here though.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

> I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

They aren't capable of doing that, if those companies do not do business within the EU. As soon as those companies have the power to negatively impact EU citizens, however, the EU has the power to protect those citizens.

Re: GDPR and Google Analytics

#68
post #39

Earlier quoted context omitted.

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

It is remarkable how many websites use Google fonts. I wasn't really aware until I used uBlock to disable third party fonts, and icons started disappearing on many fonts. Web designers are inadvertently enabling mass corporate surveillance by simply trying to save bandwidth on font icons.

Google Fonts is actually not a problem from a GDPR perspective as long as the EU-US 'Privacy Shield' is in force. All in all, Google's data privacy compliance is outstanding in comparison with most other US companies, only Amazon and Microsoft are probably on the same level.

Re: GDPR and Google Analytics

#69

Earlier quoted context omitted.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

To which the entirely reasonable response from anyone without a legal nexus in the EU (or physical products to ship) is "we don't care and you have no legal right or ability to enforce that". And the entirely reasonable response from anyone thinking of creating a legal nexus in the EU without an extremely business-critical reason is "let's stay in our own country where it's safer and we only have one jurisdiction to…

And the "reasonable" response to this is to act like China: block those services. China showed it is possible so now the "lol it is Internet you can't stop people accessing things, VPN, crypto blablabla" spiel is proven to do jack-shit for services which need a lot of people and their data.

Re: GDPR and Google Analytics

#70
post #35

I hope everyone is nice and busy setting up encryption, access control and timely erasure for all their server and application logs: https://www.ctrl.blog/entry/gdpr-web-server-logs

The article is full of misunderstandings. The following sentence for example is just wrong:

'You can’t collect and store any personal data without having obtained, and being able to document that you obtained, consent from the persons you’re collecting data from.'

Consent is just one option. You can do logging without personal data. You might have a legal obligation do to (full) logging. You might have a legitimate interest. And so one …

It is wrong to summarise the GDPR as 'consent is always necessary'.

Post reply on HN