Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

221–230 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#221
post #19

Earlier quoted context omitted.

You can still run a free website and be compliant with the GDPR. The EU/EEA is the largest market in the world, closing yourself for an market that size will hurt more than changing a few thing to be compliant.

False. The marginal cost of an EU customer is no longer zero. Why should I put in a bunch of work for GDPR compliance if the cost to implement it exceeds the initial marginal cost of an EU user. There is still the rest of the world.

Good. if you do not value my privacy, I dont want you to do business here. another product will replace your own. And in all likeness an EU one, meaning less euros leaving the eurozone.

I'm all for it.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#222
post #161
post #10

Things like this will test how much EU citizens value their privacy. Of course there will be some sites they will not be able to visit but time will show if they are okay with that. These rules are very similar to rules limiting loans. No matter how desperate a person is and how low credit they have, in the US you can't give them a loan for above a certain amount of interest. That could be terrible for a poor person…

> then the result will probably be that a lot of free websites ban EU users and smaller companies take their place with products that either cost money or will be a bit worse. Availability of quality free content is not a problem, the content will just be available from other source. The big problem on the ads-monetized web today is ranking high enough, and the site that don't want to apply GDPR will just have to com…

>Availability of quality free content is not a problem

Only if all content on every web site around the world is equal. Which it is not.

If the quality was the same everywhere, and the same content was available everywhere, then people in Europe wouldn't have to go to web sites in other countries.

There are lots of reasons for companies in Europe to need to read the Chicago Tribune (PR clipping service, for example). But the Tribune's content is no longer available to the E.U., and will not be replicated elsewhere for copyright reasons.

As much as I dislike Tronc as an entity, I don't blame it for this decision. Within hours of GDPR going into effect, the lawsuits started flying. That's exactly why some companies decided it was easier to just opt out of Europe.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#223

Well we still have HN, even if non-compliant.

Why is HN non-compliant? They use Cloudflare which has gone out of their way to be compliant (to the point of offering US citizens and the rest of the world the same protections as EU citizens), and nothing else is included on the page that could track you (check it if you don't believe me). You can anonymize your profile, you can edit it and you can use one of several services to get your data out. On the whole it i…

Do they have an EU representative? Then non compliant.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#224

Earlier quoted context omitted.

This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws. It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.

Pass whatever law you want, just don’t expect me to care. This law has nothing to do with me. If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money.

> Pass whatever law you want, just don’t expect me to care.

That was exactly the position of too many companies: pass whatever law, I don't care.

Well. It has gone on for too long, so, hopefully, now companies will start to care.

> If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money.

The EU is 500 million people. It looks to me that it's you who doesn't want to do business just because you think that other countries' laws and other countries' rights are bullshit and you don't care about them.

I say, good riddance.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#225

Earlier quoted context omitted.

I attribute it to European jealously over american tech success. Hi tech success that flies in the face of their supposed social, cultural and moral superiority. User tracking is not really why we don't have nice things, look at the success of moviepass even after they publicly admitted what they were tracking. People want part of the spoils which is exactly the purpose of GDPR.

Isn't Moviepass hæmmoraging $20 million a day while its share price tanks? No, if you knew how Europeans think, you'd realise that this is really just about securing privacy. Most of the regulators are really focussed on ensuring compliance, not levying fines.

They're losing $20 million a month, if they were losing that per day that'd really be something. Probably would be out of business in a few weeks.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#226
Well - what does this mean for US citizens then?

If those site violate GDPR laws, what exactly are they doing with user data, how are they securing it? Do they even know what's going on?

Good litmus test for privacy/info sec readiness in corporations.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#227
I hope we get a LOT more of this.

If the EU wants to pass laws that say every company around the world (almost all of which have ZERO democratic representation in EU government) has to fully comply or face huge fines that will drive them out of business, let’s see how they feel when all those companies just shrug and turn their back on the market.

I know the GDPR fans here will just say “good, we’re better off without them!” and I guess on that we agree. Go in peace.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#228

Earlier quoted context omitted.

Because the risk and costs of compliance are borne by all, not just the non-compliant. I would hope that "but laws only affect the bad guys" or "if you're doing nothing wrong you have nothing to worry about" would no longer be reasonable arguments these days.

> Because the risk and costs of compliance are borne by all, not just the non-compliant. I would hope that "but laws only affect the bad guys" or "if you're doing nothing wrong you have nothing to worry about" would no longer be reasonable arguments these days. That's like saying that drug regulations are bad, because all opiate producers take on "the risk and costs of compliance," not just the street pushers. The wh…

If you had used drug laws, e.g. marijuana laws, in your analogy it would make more sense. They think they are raising standards too. It's not about what the point is, it is about the implementation. It's so tough to have reasonable discourse about the topic because if you are against the approach people think you are against the whole point.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#229

GDPR is significant because for the first time in this history of the Internet an (EU) user no longer has a marginal cost of zero. The cost to write an application to be GDPR compliant is high and frankly will not be worth it for many entepreurs developing an MVP.

Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.

I wonder if it's really necessary to stop using e-mail addresses as usernames / unique identifiers. Presumably you need some sort of unique identifier for each user, and such an identifier can, by definition, be tied to an individual. Would such an identifier not fall under "data required to provide the service"?. And since any such identifier is effectively PII, does it really matter if you use an e-mail address vs. some other user name?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#230
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.
Post reply on HN