Earlier quoted context omitted.
To me it's overreach because smaller measures could have been a better first step, this won't help the problem much, and it hurts the non-targets. I understand it's why you asked your government to work on the problem. We just need to stop pretending that any way they work on the problem is a good one.
> We just need to stop pretending that any way they work on the problem is a good one. Just because the government does something, that thing is bad? I don't understand your logic... I quite like what they've done.
GDPR: US news sites unavailable to EU users over data protection rules
241–250 of 680 posts
Re: GDPR: US news sites unavailable to EU users over data protection rules
#242Earlier quoted context omitted.
Doing business in the EU is only one path that causes the GDPR apply to you, processing personal data of people located within the EU, not necessarily EU citizens, is another one and probably the one relevant here. Article 3(2): This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are…
But what's the worst that could happen? Your site would get dns blocked in the EU?
Re: GDPR: US news sites unavailable to EU users over data protection rules
#243Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…
Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#244Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…
I just get redirected back to https://usatoday.com :( Perks of living in the US, I guess.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#245Earlier quoted context omitted.
Does your website serve users from EU region or do you intend to block incoming traffic form EU? If you serve them then you might want to collect some data points about them. It is like being on the internet you are by default given a chance to operate business (website in this case) in whatever country a user access your website from. You are not going to open a franchise in Germany and not abide by their local laws…
So, you're saying if someone from Saudi Arabia sees a German website that shows a woman's bare knees, that the German site will have to pay Saudi fines?
Re: GDPR: US news sites unavailable to EU users over data protection rules
#246Earlier quoted context omitted.
I see this 'VPN' argument a lot, but it's wrong. If the Chicago Tribune tracks users accessing their site through a VPN, without informed consent, they are in violation. Art 3 para 2 in b makes the Regulation apply to them and doesn't make provisions about whether the controller or processor has a way to find out if the behaviour of the data subject takes place within the Union. I don't see any reason for a different…
So you're saying that if I block my site to EU IPs, and someone uses a VPN to look like they're coming from the US and bypass that, they can then sue me under the GDPR? No way.
https://gdpr-info.eu/recitals/no-23/
Short version: GDPR does not apply if you happen to collect data on a few EU residents by accident (assuming you're not otherwise based in the EU).
Re: GDPR: US news sites unavailable to EU users over data protection rules
#247Earlier quoted context omitted.
Does your website serve users from EU region or do you intend to block incoming traffic form EU? If you serve them then you might want to collect some data points about them. It is like being on the internet you are by default given a chance to operate business (website in this case) in whatever country a user access your website from. You are not going to open a franchise in Germany and not abide by their local laws…
This is an insane argument. So now by having a blog, I’m under the jurisdiction of 200 countries and countless other small jurisdictions? What happens when they all contradict each other? Or when I can’t tell what jurisdiction a user belongs to? Or when they pass crazy laws like anti-blasphemy or demand half my revenue, or whatever? I don’t think you’ve thought this through.
Guess what? You already are. For example, if you insult the Thai king on your blog and you visit Thailand you can be prosecuted. This has happened.
Of course, you can't be extradited for this. But if you are a notorious online controversialist you should be careful where you travel.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#248Earlier quoted context omitted.
Really? Do you have an EU representative for your MVP? Did you hire a legal team to review your site and write up your terms of service? Send me your MVP and I’ll show you 10 thing a that are wrong with it and if you are complaint somehow then I doubt the product will be viable at all.
So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
> Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data
Are there exemptions for very small companies?
If you can prove you don't process any user data, at all, does this exempt you from having to appoint a DPO?
Re: GDPR: US news sites unavailable to EU users over data protection rules
#249Earlier quoted context omitted.
That looks fantastic, I would actually read USA Today if this lean site sticks around. If they want to monetize, publishers should control their own generic ad inventory (like they used to in old pre internet days) and ask for opt-in if you want customization. Easy on paper but hard in reality.
I call BS on this. You’re going to read a publication because of the relevance and quality of the content. USA Today Europe will no longer have metrics to sell advertising which may then force them to dial back on their writers salaries.
Still it's hard to deny that the (presumably temporary) EU site is a much nicer experience. It's certainly faster.
They have plenty of metrics on the ads still, just not on the users. It's not going to be an issue to see how often an ad is shown, they just don't know if it's relevant to the reader. The good thing is that no they have a way of measuring the effectiveness of targetted ads, because the entire EU is available as a control group.
For a newspaper, like USA Today, I honestly doubt that targetted ads convert much better than random ones. EDIT: Random or based on the content of the article.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#250Earlier quoted context omitted.
No, they can't 'sue' you; they can make a complaint to their data authority who will then decide if and what to do about it. So if your site blocks EU IPs and you then violate the privacy of someone in the EU grossly enough to warrant the data authority to make a case out of it, then yes. (provided everything else also applies, e.g. the things being talked about in the rest of this thread).
The Cambridge Analytica whistleblower is using Facebook and Google for incomplete compliance so yes, you can get sued.