Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

261–270 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#261
post #110
post #97

Earlier quoted context omitted.

No, they can't 'sue' you; they can make a complaint to their data authority who will then decide if and what to do about it. So if your site blocks EU IPs and you then violate the privacy of someone in the EU grossly enough to warrant the data authority to make a case out of it, then yes. (provided everything else also applies, e.g. the things being talked about in the rest of this thread).

Put it in your TOS that European users are forbidden from using your site, and then if they complain to a data authority press charges under the CFAA, and sue them for damages you incurred due to their violation. Then let the courts hash it out.

Such TOS would most likely be 'unduely onerous' or whatever the local term for this concept is in other EU jurisdictions.

I've said this many times here already, but law is not a closed rule based decision tree. Intent matters, and laws are written in a way that they can be interpreted so that their meaning can be adapted to new circumstances or different times. Now, I'm not going to argue about whether that's how it should be (because that's such a trite 1L discussion), but it's a fact that it is.

So no, that's not how it works.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#263

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

I think the phrase "You're oversimplifying a complex situation to the point of no longer adding anything to the discussion" applies to your comment.

No one here is saying that ALL regulations are bad or should be removed, just that all regulations have unintended consequences.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#264

Earlier quoted context omitted.

Really? Do you have an EU representative for your MVP? Did you hire a legal team to review your site and write up your terms of service? Send me your MVP and I’ll show you 10 thing a that are wrong with it and if you are complaint somehow then I doubt the product will be viable at all.

Really disappointed when I see these kinds of scare tactics. Compliance (or at least a good-faith attempt at compliance) is quite easy for small/new projects. I'm willing to bet that courts aren't out to make an example of every small infringement, and there's really no reason to discourage people from starting new projects.

Please send me a link to your project for analysis before you say it’s easy.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#265

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

You jest, but to use another example, aggressive regulations is exactly why manufactures produce private aircraft designed 50 years ago.

Onerous regulations are always overcome, one way or another. (And airbags are not onerous.)

Re: GDPR: US news sites unavailable to EU users over data protection rules

#266

Earlier quoted context omitted.

Part of the reason for the failure of those other models is their need to compete with an exploitative ad driven model. When you remove the lowest common denominator, you make it is easier for the market to accomplish something better.

i.e. "It's easier for horses to compete with cars if you set the speed limit everywhere to 5 miles per hour."

> i.e. "It's easier for horses to compete with cars if you set the speed limit everywhere to 5 miles per hour."

I think that elides pretty important aspects from the equation. In reality, it's more like: "It's easier for Bill-brand horses to compete with John-brand horses; if you ban the steroids, amphetamines, and cruel practices John uses to get his results."

Re: GDPR: US news sites unavailable to EU users over data protection rules

#267
post #19
post #10

Things like this will test how much EU citizens value their privacy. Of course there will be some sites they will not be able to visit but time will show if they are okay with that. These rules are very similar to rules limiting loans. No matter how desperate a person is and how low credit they have, in the US you can't give them a loan for above a certain amount of interest. That could be terrible for a poor person…

You can still run a free website and be compliant with the GDPR. The EU/EEA is the largest market in the world, closing yourself for an market that size will hurt more than changing a few thing to be compliant.

If I run a free website, I have 0 revenue. Why would I care how big the EU market is?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#268

GDPR is significant because for the first time in this history of the Internet an (EU) user no longer has a marginal cost of zero. The cost to write an application to be GDPR compliant is high and frankly will not be worth it for many entepreurs developing an MVP.

No; the cost of supporting GDPR for a new product is essentially zero over good data management in the first place.

Sort of. The technical cost is effectively zero, as everything technical which is required by GDPR ought to be done anyways. However, there are a lot of non-technical compliance issues in meatspace that have a very real cost. Most of that cost may be deferred until the first GDPR-based request, however that just means you're kicking the can down the road. The cost is still there.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#269

Earlier quoted context omitted.

This is an insane argument. So now by having a blog, I’m under the jurisdiction of 200 countries and countless other small jurisdictions? What happens when they all contradict each other? Or when I can’t tell what jurisdiction a user belongs to? Or when they pass crazy laws like anti-blasphemy or demand half my revenue, or whatever? I don’t think you’ve thought this through.

> So now by having a blog, I’m under the jurisdiction of 200 countries and countless other small jurisdictions? Guess what? You already are. For example, if you insult the Thai king on your blog and you visit Thailand you can be prosecuted. This has happened. Of course, you can't be extradited for this. But if you are a notorious online controversialist you should be careful where you travel.

There’s a difference between actually being under the jurisdiction of a government and them claiming that you are. My contention here is with so many people claiming that I should care as a matter of morality or something. That the EU’s claim here is right and just. Under that logic, so is Thailand’s. Is that really the world we want?

Obviously if the EU has some enforcement mechanism, I should be cautious, even if they’re in the wrong (like Thailand). But they don’t have any actual enforcement mechanism, so this just seems irrelevant to me.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#270
post #205

Earlier quoted context omitted.

I haven't been given an option not to make calls to your servers, those websites used to load 20 tracking scripts without asking me. Thanks to the GDPR now I will be able to stop sending requests. What's the problem? See, how browsers work is that they load this thing called HTML that describes the content and can load other stuff without asking me. Apologies if I accidentally sent any data or money, it wasn't my cal…

If it’s your right to use an adblocker under the theory that you should control what requests your browser makes from your device, then which requests it makes are also your responsibility. Regardless, whether you intended to send my server a request is your problem. The fact is that you did, and that hardly gives full control of my business to whatever legal jurisdictions claim you as their subject.

Well, as it turns out, it's your problem. Like, literally :)

Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers.

I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that is, if you can find a way to serve me or solve a problem of mine I might choose to do a business with you if I decide that the compensation you demand fair.

If your business is unprofitable when you have to ask me for permission in plain English maybe it simply means that you don't have a profitable Business and you should consider doing something else.

We don't see business people complaining that government regulations are hurting their organ harvesting businesses, right? People decided that they don't want other people to sell their kidneys on open markets, so that business doesn't exist.

People at some point decided that they don't want to get cancer from Asbestos, regulations kicked in and the Asbestos businesses were destroyed.

This time around people seem to be in control of their data, if that makes your business unprofitable or impossible do what others did: Something else.

Post reply on HN