Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

131–140 of 150 posts

Re: 2018 reform of EU data protection rules

#131
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…

Extradition is an extreme example and not applicable here.

My whole point is, just because the EU makes a law doesn't mean it can enforce it.

https://en.wikipedia.org/wiki/Extraterritorial_jurisdiction

Re: 2018 reform of EU data protection rules

#132

Earlier quoted context omitted.

Where would "non-targeted" ads even come from? How can you use an ad network or even run a standard ad server in a way that doesn't share at least the reader's IP Address? Mom and pop publishers who don't have the resources or ability to staff their own ad sales team are going to be in trouble. The big players who can work around this obstacle are going to be fine. I'm not happy about this.

IP address is only personally identifable info if it is coupled with other info that links it to a real person. Storing an IP address by itself and sharing it is not, by itself PII

That is incorrect.

In the US, legally thats fine. In the EU they classify it as personal information.

Re: 2018 reform of EU data protection rules

#133

Earlier quoted context omitted.

Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?

Because I apparently need affirmative check-the-box consent before I can actually use those ad networks. I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.

Correct. There are a few things to note here:

One single ad unit may try and load several tracking services so that it can re-target you later, track that the ad was served, and also load in extra services (Facebook Like button) that in turn track you for their own reasons.

On any given Page Load you DO not know in advance what ads will be in your page.

In getting User Consent before you load ads you cannot possibly know what the services are that will eb injected into the page ahead of time.

Thats an impossible situation.

Even if, and I stress this is hard, even if you were able to limit your ads from one network to direct-sold campaigns under the control of just a few agencies that agree to use only a subset of trackers and other services, you might still be talking 20 to 80 items you need to provide the user in a Consent Form.

Re: 2018 reform of EU data protection rules

#134
post #64
post #36

Earlier quoted context omitted.

Hmm. You just agreed with me and then disagreed me :) Again, I say this as someone who is implementing GDPR for a US-based company, and is also a EU citizen (Irish) and has sat more meetings with various legal groups than I care to remember (again, stress I'm not a lawyer). It is all about a companies appetite for risk and how tied the are __PHYSICALLY__ to the EU (offices/employees/parent-companies/subsidiaries). Th…

The GDPR goes beyond physical presence. It's strange that your legal team would not know this. See my previous comment [1]. My own understanding based on conversations with lawyers (who spoke to regulators in France) is that the law is designed to target any business that targets EU citizens. The territorial scope is formally global but obviously this is very much narrowed to businesses who (1) are pursuing EU custom…

OK. I think we agree on the core parts. Its a question of being able to enforce and your level of risk.

Right now, everyone is in "wait and see" mode on how this will play out.

Re: 2018 reform of EU data protection rules

#135
post #129
post #124

Earlier quoted context omitted.

Article 3 says it applies when -EITHER- of the following is true: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

Yes, that's right. Are you implying that our notional Guatemalan banjo seller is monitoring the behaviour of EU based subjects? I confess I was working on the basis that out the two potential options, Art 3(2)(b) would be inapplicable here, but you may know more than me about their activities!

They're responsible for whatever user monitoring their third-party ecommerce platform does, right? All the ones I've seen process and retain user data. And maybe their web analytics, A/B testing, email newsletter tracking, etc.

If your point is that static brochureware sites that don't target EU members at all and don't do anything interesting on the web probably don't have much to worry about... then I agree, but I don't think that's very insightful.

Your earlier comment said that GDPR required "at least some active targeting of EU users." But a less contrived example, say a US-based SaaS that accepts credit card payments, probably needs to be very worried about GDPR even with absolutely no active targeting of EU users.

Re: 2018 reform of EU data protection rules

#137

Earlier quoted context omitted.

Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?

Because I apparently need affirmative check-the-box consent before I can actually use those ad networks. I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.

As a joke I might make a popup for each URL in our ads.txt files (at work) asking for consent. There are over 300 lines which I've always thought was ridiculous but maybe this will drive the point home to my boss.

Re: 2018 reform of EU data protection rules

#138
post #104

Earlier quoted context omitted.

They're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.

How can an alternative be more profitable? Targeted ads allow to TARGET someone. That means that instead of wasting views on someone that won't be interested (and thus, be a waste of money) you use it on people that will care. For sure if you have 5$ of budget per sale, if it takes 1000 views to get a sale or 1 views, you won't pay the same for views in both situation depending on the efficiency of the ad.

He did not say that an alternative would be more profitable.

What he meant is that right now, because targeted ads exist, non-targeted ads sell far worse. Once targeted ads are not an option anymore, non-targeted ads will get more attention again, because the demand for advertising will not go away.

There will be somewhat of a drop in demand, because advertising might be less effective, so it makes more sense for companies to invest into developing their products instead. But you can hardly justify unethical behaviour with some industry making money off of it. Drug dealing, slavery, forced prostitution etc. are also illegal, even though there's a hugely profitable market for those.

You have to draw the line somewhere. Governments are supposed to draw the line there, where the effect of doing something results in a net negative for this society by given values that this society considers important.

But even assuming a society only cares about its overall profit, I would be surprised if there's not some effects going on, due to targeted advertising being sharp enough of a tool to psychologically influence people to buy useless crap they don't need. And people buying useless crap they don't need is not good for the overall profit of a society. They could be buying useful crap that they can use to make more of a profit instead.

Re: 2018 reform of EU data protection rules

#139
post #82

Earlier quoted context omitted.

Heh, I'd say that it's even worse than "misunderstanding". Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled... So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/ Caricaturizing (a bit): "HN1: The GDPR takes away our freedom to make tons…

Please do not violate the Prime Directive. Thanks.

> Be civil. Don't say things you wouldn't say face-to-face. Don't be snarky. Comments should get more civil and substantive, not less, as a topic gets more divisive.

I was snarky but it is definitely something I would say to you face-to-face.

The quality of discussion around the GDPR here on HN was not up to the standard quality. Part of it was because, in my opinion, a lot of people here are entrepreneurs and this made them really subjective and almost blind-sided them to the benefits for users.

The GDPR is not perfect but it's a great long term measure, one I hope will be followed (and improved upon!) by other administrations.

Re: 2018 reform of EU data protection rules

#140
post #129

Earlier quoted context omitted.

Yes, that's right. Are you implying that our notional Guatemalan banjo seller is monitoring the behaviour of EU based subjects? I confess I was working on the basis that out the two potential options, Art 3(2)(b) would be inapplicable here, but you may know more than me about their activities!

They're responsible for whatever user monitoring their third-party ecommerce platform does, right? All the ones I've seen process and retain user data. And maybe their web analytics, A/B testing, email newsletter tracking, etc. If your point is that static brochureware sites that don't target EU members at all and don't do anything interesting on the web probably don't have much to worry about... then I agree, but I…

Heh, apologies for not being more insightful! I was simply rebutting your point over the GDPR applying once you’ve made a few sales to customers in the EU which is not the case on those facts alone.

Obviously each case should be dealt with on its own facts to assess the application of GDPR. In the example you give, GDPR may well apply. Some companies may be worried, others may see it as an opportunity.

I know lots of US SaaS companies are embracing GDPR rather than being worried about it. Clearly if you are looking to get business from EU customers but want to argue GDPR doesn’t apply due to the fact you are not strictly speaking targeting EU users then that might present an issue for certain potential EU customers (or maybe they could offer a cost discount because they haven't had to go through a GDPR compliance exercise). On that basis lots of companies outside the EU are pro-actively looking to comply with GDPR.

Arguments over the appropriateness of extra-territoriality applicability are a separate matter of course!

Post reply on HN