There are so many wrong things with this approach. First, what do you do when you have existing users, delete them? Second, I believe the law protects EU citizens regardless of where they are. If you're an EU citizen and register for a service somewhere in the US using VPN or while physically being outside the EU, that service/company will still need to comply. The safest approach is to comply. We're a tiny startup,…
> Second, I believe the law protects EU citizens regardless of where they are. That's incorrect. That is the attempted naive reach of the EU in action. The correct formulation is: the EU would like for GDPR to apply to all EU citizen data globally. US sites/services with no business reach into the EU, do not need to comply with EU privacy laws. 99% of businesses around the world (most small businesses), those outside…
GDPR: US news sites unavailable to EU users over data protection rules
201–210 of 680 posts
Re: GDPR: US news sites unavailable to EU users over data protection rules
#202Honest hypothetical question... my website is in the US, my servers in the US, why would I care about the GDPR?
Asking for a friend.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#203I'm in the EU, and a couple of the corporate VPNs I have used here have had their exit IP in the U.S. or Canada. Which means that when I'm at work, I appear to be in Seattle, and these sites are not blocked. Based just on that, I'd argue that "Blocking 500M Users Easier Than Complying with GDPR" is probably not even a true statement. I doubt EU regulators will go after these sites because they really aren't that cons…
What exactly do you want here? Do you want every site to have you upload your passport? Or are you just saying that any jurisdiction in the world should be able to effectively force every company globally to comply with their laws, and that they can’t pull out of those markets if they find the law too onerous? Forget about the intent of the GDPR, what about the broader principle when applied to laws you don’t like? W…
_If_ it is true that the GDPR covers an EU person's data held by any company worldwide, regardless of how or whether it should, an IP block might not be accepted as compliance. Or it might, if the EU regulators decide that best-effort is enough.
The important point is that many Europeans are browsing the net through non-EU IP addresses without the knowledge that they are doing so. Most people do not pay attention to what their corporate public IP address is. They may use "non-EU" services entirely unintentionally, and EU regulators may or may not take that into account in the unlikely case that they investigate one of these companies.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#204Earlier quoted context omitted.
So you're saying that if I block my site to EU IPs, and someone uses a VPN to look like they're coming from the US and bypass that, they can then sue me under the GDPR? No way.
No, they can't 'sue' you; they can make a complaint to their data authority who will then decide if and what to do about it. So if your site blocks EU IPs and you then violate the privacy of someone in the EU grossly enough to warrant the data authority to make a case out of it, then yes. (provided everything else also applies, e.g. the things being talked about in the rest of this thread).
Re: GDPR: US news sites unavailable to EU users over data protection rules
#205Earlier quoted context omitted.
As an EU citizen, I don't think the law is bad but you are free to be upset about it, of course. Please respect our laws and privacy or don't do business with us. We will be very sorry if your product is irreplaceable or we will use a competing product that complies with GDPR.
Please respect our laws and privacy or don't do business with us. Stop sending us your data and money? I don’t leave the US to deal with EU customers. You send requests to my server in the US. If you’re unhappy with me, stop doing that. And it’s pretty rich to complain about companies not complying and leaving the market, while also using VPNs to use their service anyway. Apparently protecting your data isn’t as impo…
See, how browsers work is that they load this thing called HTML that describes the content and can load other stuff without asking me. Apologies if I accidentally sent any data or money, it wasn't my call. It was in the HTML that I loaded because I was offered to view a free article.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#206Things like this will test how much EU citizens value their privacy. Of course there will be some sites they will not be able to visit but time will show if they are okay with that. These rules are very similar to rules limiting loans. No matter how desperate a person is and how low credit they have, in the US you can't give them a loan for above a certain amount of interest. That could be terrible for a poor person…
> the result will probably be that a lot of free websites ban EU users Good riddance, at least we know what websites we shouldn't have visited in the first place. > smaller companies take their place with products that either cost money or will be a bit worse. Or they will be better and still be free. News companies are dying, news is commodity, if I can't read something on the LA times, I'm sure I'll find that same…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#207Earlier quoted context omitted.
Because bitter HN users will call you shady if you don’t fully comply with their pet law, no matter how ambiguous or onerous :)
This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws. It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#208Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…
Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#209Earlier quoted context omitted.
Ha. You’re insane if you think that the US Congress is going to start letting 28 agencies in the EU start fining small businesses that have no EU presence whatsoever. The political ads write themselves.
I guess the question is what does the EU value more, privacy or their relationship with the US? I don't have an answer but I suppose we'll find out soon enough.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#210They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…
appoint, not hire.