Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

181–190 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#181
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

And when it comes to European business law in particular, there's no reason to believe favoring incumbents and decreasing competition isn't an intended benefit.

When Amazon entered the French market, it tripped over laws putting a floor on discounts allowed that are intended to protect book sellers, not purchasers.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#182
post #102

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

That looks fantastic, I would actually read USA Today if this lean site sticks around. If they want to monetize, publishers should control their own generic ad inventory (like they used to in old pre internet days) and ask for opt-in if you want customization. Easy on paper but hard in reality.

I call BS on this. You’re going to read a publication because of the relevance and quality of the content. USA Today Europe will no longer have metrics to sell advertising which may then force them to dial back on their writers salaries.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#183

GDPR is significant because for the first time in this history of the Internet an (EU) user no longer has a marginal cost of zero. The cost to write an application to be GDPR compliant is high and frankly will not be worth it for many entepreurs developing an MVP.

No; the cost of supporting GDPR for a new product is essentially zero over good data management in the first place.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#184

Earlier quoted context omitted.

Why is HN non-compliant? They use Cloudflare which has gone out of their way to be compliant (to the point of offering US citizens and the rest of the world the same protections as EU citizens), and nothing else is included on the page that could track you (check it if you don't believe me). You can anonymize your profile, you can edit it and you can use one of several services to get your data out. On the whole it i…

AFAIK you can't delete all your messages on HN, nor even delete your profile. They also do fingerprinting, or else how can they detect people with multiple accounts?

> AFAIK you can't delete all your messages on HN

Not in an automated way. Have you asked the moderators to remove all your messages?

> nor even delete your profile.

You can anonymize it.

> They also do fingerprinting, or else how can they detect people with multiple accounts?

Who says they do?

Or is that written from personal experience?

Note that 'for the purpose of running the service' is a lawful basis for processing.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#185
post #135

Earlier quoted context omitted.

And that it isn't even an option to recognize a bad law and repeal it, even if it had good intentions, speaks volumes.

As an EU citizen, I don't think the law is bad but you are free to be upset about it, of course. Please respect our laws and privacy or don't do business with us. We will be very sorry if your product is irreplaceable or we will use a competing product that complies with GDPR.

Please respect our laws and privacy or don't do business with us.

Stop sending us your data and money? I don’t leave the US to deal with EU customers. You send requests to my server in the US. If you’re unhappy with me, stop doing that.

And it’s pretty rich to complain about companies not complying and leaving the market, while also using VPNs to use their service anyway. Apparently protecting your data isn’t as important as you say?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#186

Earlier quoted context omitted.

As someone else is pointing out, a business needs to have a positive reason to follow this regulation. If the very vast majority of my business is from US readers/customers and practically no money comes in from European readers why would I put any effort in at all to comply rather than just block. The only scenario where this would happen is of compliance was cheaper than blocking.

Because bitter HN users will call you shady if you don’t fully comply with their pet law, no matter how ambiguous or onerous :)

This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws.

It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#187
post #134

There are so many wrong things with this approach. First, what do you do when you have existing users, delete them? Second, I believe the law protects EU citizens regardless of where they are. If you're an EU citizen and register for a service somewhere in the US using VPN or while physically being outside the EU, that service/company will still need to comply. The safest approach is to comply. We're a tiny startup,…

> Second, I believe the law protects EU citizens regardless of where they are. If you're an EU citizen and register for a service somewhere in the US using VPN or while physically being outside the EU, that service/company will still need to comply.

If the controller or processor is established in the Union (regardless of where they actually process data), then GDPR applies to all processing of personal data regardless of citizenship or location of the data subject.

If the controller or processor is not established in the Union, GDPR applies to processing of personal data if (1) they are offering goods or services to data subjects in the Union, or (2) they are monitoring behavior of such data subjects that takes place in the Union.

See Article 3 for details.

If a US site that is not also established in the Union is trying to block access from the EU, and someone uses a VPN to get around that, the site would probably not be subject to GDPR, as they are probably not offering goods or services to data subjects in the Union. Recital 23 explains that offering goods or services means more than just their site can be reached from in the Union:

" In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."

Re: GDPR: US news sites unavailable to EU users over data protection rules

#188
post #128

On one hand I can understand why some orgs are having trouble with GDPR. On the other hand it’s pretty clear the actions of more than a few have gotten GDPR to where it is. My takeaway at the moment is something along the lines of this is why we can’t have nice things.

I attribute it to European jealously over american tech success. Hi tech success that flies in the face of their supposed social, cultural and moral superiority. User tracking is not really why we don't have nice things, look at the success of moviepass even after they publicly admitted what they were tracking. People want part of the spoils which is exactly the purpose of GDPR.

Isn't Moviepass hæmmoraging $20 million a day while its share price tanks?

No, if you knew how Europeans think, you'd realise that this is really just about securing privacy. Most of the regulators are really focussed on ensuring compliance, not levying fines.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#189
post #135

Earlier quoted context omitted.

As an EU citizen, I don't think the law is bad but you are free to be upset about it, of course. Please respect our laws and privacy or don't do business with us. We will be very sorry if your product is irreplaceable or we will use a competing product that complies with GDPR.

I didn't say the law was bad, I was saying if it turns out to be, repealing it should be an option. Too often there is no going back from these things because it's not considered an option. Instead only options like revolt, go elsewhere or use a VPN are presented. Obviously the last incarnation of the GDPR didn't work for multiple reasons, the most oft-cited one being non-enforcement. Was the option to repeal and tak…

Of course, it is an option, the problem is that you claim not to be and you claim that "the EU and GDPR proponents' mindsets make a lot more sense" because I asked a question to emphasize the "test" on the EU citizens.

I see you're in Texas. Don't worry too much about EU, we are doing fine. We will figure this thing out if it turns out to be more bad than good.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#190
post #114

Earlier quoted context omitted.

My next sentence is literally a third option, describing what happens with geo-blocked content.

And that it isn't even an option to recognize a bad law and repeal it, even if it had good intentions, speaks volumes.

[deleted]
Post reply on HN