Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

411–420 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#411
post #165

It seems to me that GDPR restricts economic growth. For example, I'd be quite happy to let my local supermarket sell my personal data to Google in exchange for a 3% discount on my grocery prices. Everone would benefit: (1) The supermarket gets an additional source of revenue; (2) Google can charge more for ads; (3) The toothpaste company gets better return on it's advertising; (4) I pay less for my groceries. GDPR pr…

Win-win for you. Not for others among us.

> It seems to me that GDPR restricts economic growth.

It does, but fortunately economic growth is not the central point of human existence.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#412
post #166

Thanks EU, we'll have more popups than ever that everyone's going to agree out of habit. It's not fun seeing a popup on every site you visit. This should have been a brower-based implementation globally that every site must adhere to. Even worse for me, I browse exclusively in private/incognito mode and this is going to make that unusable with consent popups on sites on every visit.

The popups have to allow users to say no. They can't require your consent for if it is not directly related to providing the service.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#413

Earlier quoted context omitted.

It’s not about being able to “mess with [your] users”. It’s about sites that don’t need EU traffic anyway being unnecessarily exposed to fines for even accidental violations of a very complex law.

But any of your sites should protect user data, it's the respectful thing to do. Right ? In which case would you you think it's alright for any site to not protect, say, a user home address ?

Reasonably protecting user data and complying with the GDPR are two entirely different things. There are many ways to accidentally run afoul of this law while still protecting user data.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#414
post #73

Earlier quoted context omitted.

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

It raises interesting question. What if some publisher, say, newspaper, can show highly targeted ads for $3 CPM, or generic ads for $1 CPM. Can such publisher claim that collecting data is strictly necessary to provide the service? With threefold difference in ad revenue, that could be actually the case.

IANAL, but most probably not. When thinking about "strictly necessary to provide the service", one should think in terms of technical feasibility, as in "can the service be technically provided without that data?" not in terms of profitability.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#415
post #142

Earlier quoted context omitted.

> No, it will basically make a newsmedia site unprofitable. I think it is the EU that has not fully thought this through. Most of the news industry is already sickly, financially, and they mostly have no model other than advertising (with a very few exceptions). We have publicly funded broadcasters in most EU countries. The ad-supported news sites, on the other hand, are generally doing more harm than good. News outl…

Let me tell you how it works in central/eastern europe - ad-supported sites are financially sick, but more and more 'info' is spread out by well funded russian propaganda sites (imo they carry the ads only to seem 'legit'). They will thrive even more :(.

Is there anything that can be done about this? The whole situation is surreal. Surely it must be possible to decrease these sites impact without having to resort to censorship. It's just 21st century propaganda.

Fun fact: oligarchs in Greece have been doing this to their own country for financial gain for decades. Most Greek newspapers are mouthpieces for the interests of the great families.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#416
post #166

Thanks EU, we'll have more popups than ever that everyone's going to agree out of habit. It's not fun seeing a popup on every site you visit. This should have been a brower-based implementation globally that every site must adhere to. Even worse for me, I browse exclusively in private/incognito mode and this is going to make that unusable with consent popups on sites on every visit.

I'm not bothered by it. If websites see their engagement fall due to so many popups, maybe they'll stop asking for so many things that require consent. Come to think of it, maybe that's the point.

A few weeks ago the internet was on fire because the abolishment of net neutrality law would kill the small startups who were trying to compete with giants. It's interesting to see people supporting the exact opposite situation now.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#417

Earlier quoted context omitted.

Why? Having insight into website traffic is hugely valuable to webmasters.

They shouldn't have to feed information to Google -- they just need to look at the logs on their servers. Y'know... the way we did it before Google Analytics came along.

sounds like advocating going back to the middle ages because "people were simpler"

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#418

Earlier quoted context omitted.

Sounds good to me but that would be only needed if you’re sending personal data (like usernames) to Google Analytics, right? If you’re anonymising IP and have no personal data in your URLs, there is no need for consent for GA tracking I think.

It doesn’t have to be personally identifying info to qualify. If you are storing data on behalf of the user, you have to get consent from the user.

Which pages were visited is not information stored on behalf of the user though. It is information stored for business analysis.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#419

As a matter of morals/competitive edge, companies should try to keep personal data safe and perhaps not collect it at all. That said, GDPR is ridiculous and in many countries, contradictory. This leads to litigation spaghetti code. It will be exploited in ways we can't yet imagine. It is dangerous to assume GDPR applies to YOU if you are based in the US. As the world (thankfully) doesn't operate under a one-world gov…

Most business will want to comply because the EU market is quite large.

its a big market but not crucial. EU users are notoriously risk-averse and won't try new things, and wait for others to set the trends. EU is important for global giants, but for more specialized, less competitive services, a cost-benefit analysis is needed to decide whether EU is worth serving.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#420
post #173

Earlier quoted context omitted.

According to art. 27 GDPR, affected data processors outside the EU have to establish a data privacy representative in the EU. In addition, authorities could for example seize local servers in the case of non-compliance. In many EU countries including Germany, data privacy violations can also be prosecuted as criminal offenses.

But this doesn't answer my question: I'm running a little side project here in Australia but with customers who happen to be in the EU. I have nothing in the EU - no sales office or support in Ireland, no hosting anywhere in the EU. How is the EU supposed to mandate that I do anything ?

The EU can (and in fact does) mandate that you comply with the GDPR. It cannot, however, enforce compliance since there is limited legal leverage. The Australian government is unlikely to help the EU to bring a case unless there'd be a treaty or an agreement (Safe Haven laws in the US for example). They could theoretically go via your revenue stream and seize your European customers payments or hold you or any officer of your company liable if you ever set foot on European soil or hold any assets that your company has in or moves via Europe. That's all very unlikely to happen over minor infractions, but some business folks already had their private jets impounded for outstanding payments as for example the Thai Prince learned the hard way: http://www.airliners.de/kronprinzen-boeing-in-muenchen-besch... (sorry, german only, but google translate should correctly translate the gist of the story)

All of this is nothing new, it's been working like that for centuries, back when business correspondence was still on old-fashioned paper.

Post reply on HN