Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

231–240 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#231

Earlier quoted context omitted.

That's not true at all. It's really easy to build an MVP that complies with GDPR.

Regardless of whether the app has a cost in and of itself, the process of appointing a compliance officer and making sure that they understand their responsibilities under EU law is a necessary cost unless you happen to be developing the app yourself and already understand everything involved.

Read Article 27(2). There's a good chance that you don't need an EU representative unless your product is based around the processing of personal data. Also read Article 37(1), you _don't_ need a compliance officer unless you are dealing with one of the special classes of personal data or performing "regular and systematic monitoring".

https://gdpr-info.eu/art-27-gdpr/ / https://gdpr-info.eu/art-37-gdpr/

Re: GDPR: US news sites unavailable to EU users over data protection rules

#232
post #168

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

I just get redirected back to https://usatoday.com :( Perks of living in the US, I guess.

For a news site, it loads quite fast.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#233
post #142
post #128

On one hand I can understand why some orgs are having trouble with GDPR. On the other hand it’s pretty clear the actions of more than a few have gotten GDPR to where it is. My takeaway at the moment is something along the lines of this is why we can’t have nice things.

That's the takeaway I'm arriving at as well. We (as an industry) had about two decades to be responsible and hold others to account with user data online. Instead we opted to pretend like a weasely Terms of Service replaced a sense of morality. Now we face regulation because, as it turns out, people care about how we use their data and how we influence them. Not exactly shocking that we ended up here.

Do people care that much about we use their data? I mean they care a little bit, but I still think given the choice between where we're at technologically and where we'd be if no one had access to users data -- I think the vast majority would take where we're at today.

The funny thing is that I generally wish companies did more with my user data. Why don't events sites do a better job just showing me events it thinks I'll like -- when was the last time I showed any interest in country music? I think customization is a huge value.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#234
post #153

Earlier quoted context omitted.

> Honestly, I don't. I don't want this precedent of government overreach to stand. Why is it overreach? It's literally why we invented government! I, the little guy, couldn't find giants like Facebook or Google. That's why I asked my democratically elected government to work on the problem.

To me it's overreach because smaller measures could have been a better first step, this won't help the problem much, and it hurts the non-targets. I understand it's why you asked your government to work on the problem. We just need to stop pretending that any way they work on the problem is a good one.

> We just need to stop pretending that any way they work on the problem is a good one.

Just because the government does something, that thing is bad? I don't understand your logic...

I quite like what they've done.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#235

GDPR is significant because for the first time in this history of the Internet an (EU) user no longer has a marginal cost of zero. The cost to write an application to be GDPR compliant is high and frankly will not be worth it for many entepreurs developing an MVP.

Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#236
post #208

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

Can you back up such strong and broad claims with something?

Not every claim on HN needs a backup. This one makes total sense to me. In this case, the article itself shows that regulation is definitely decreasing alternatives, which in turn can lead to monopolies

Re: GDPR: US news sites unavailable to EU users over data protection rules

#237

Earlier quoted context omitted.

That's not true at all. It's really easy to build an MVP that complies with GDPR.

Really? Do you have an EU representative for your MVP? Did you hire a legal team to review your site and write up your terms of service? Send me your MVP and I’ll show you 10 thing a that are wrong with it and if you are complaint somehow then I doubt the product will be viable at all.

Really disappointed when I see these kinds of scare tactics. Compliance (or at least a good-faith attempt at compliance) is quite easy for small/new projects. I'm willing to bet that courts aren't out to make an example of every small infringement, and there's really no reason to discourage people from starting new projects.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#238

Earlier quoted context omitted.

Pass whatever law you want, just don’t expect me to care. This law has nothing to do with me. If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money.

> Pass whatever law you want, just don’t expect me to care. That was exactly the position of too many companies: pass whatever law, I don't care. Well. It has gone on for too long, so, hopefully, now companies will start to care. > If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money. The EU is 500 million people. It looks to me that it's you who doesn't wa…

I treat all my users fairly and protect their data, and I am not intentionally targeting any EU users with anything I do online.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#239
post #12

Earlier quoted context omitted.

Doing business in the EU is only one path that causes the GDPR apply to you, processing personal data of people located within the EU, not necessarily EU citizens, is another one and probably the one relevant here. Article 3(2): This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are…

But what's the worst that could happen? Your site would get dns blocked in the EU?

Maybe they could arrest employees on a visit to the EU? Maybe you could even get arrested at home due to extradition agreements? Or get assets in the EU frozen or seized? But that is all pure speculation, I have no idea what actually can and can not be done or what is likely to happen.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#240
post #19
post #10

Things like this will test how much EU citizens value their privacy. Of course there will be some sites they will not be able to visit but time will show if they are okay with that. These rules are very similar to rules limiting loans. No matter how desperate a person is and how low credit they have, in the US you can't give them a loan for above a certain amount of interest. That could be terrible for a poor person…

You can still run a free website and be compliant with the GDPR. The EU/EEA is the largest market in the world, closing yourself for an market that size will hurt more than changing a few thing to be compliant.

Launch in the rest of the world first, if you're successful then think about the EU. Seems like the way to go.
Post reply on HN