Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

281–290 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#281
post #235

Earlier quoted context omitted.

Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

Sure. But let’s not pretend that it is cheap to do. All I’m saying that if you are cheering govt stepping into the equation then let’s have an honest discussion on who it hurts and who it benefits. Let’s take a stock of the impact to garage innovations. That is all.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#282
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

> Regulations tend to favor incumbents, decreasing competition

Except in Europe where it has done the exact opposite for telecom, especially compared to the unregulated US.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#283

Earlier quoted context omitted.

So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.

Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…

> Are there exemptions for very small companies? If you can prove you don't process any user data, at all, does this exempt you from having to appoint a DPO?

From the site:

> Under the GDPR, you must appoint a DPO if:

> * you are a public authority (except for courts acting in their judicial capacity);

> * your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or

> * your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.

So as far as I can see, yes, for small companies or side projects (i.e. not a public authorities, not working with large scale monitoring of individuals, not dealing with criminal convictions) you don't need a DPO.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#284

Honest hypothetical question... my website is in the US, my servers in the US, why would I care about the GDPR?

Honest hypothetical question... my file hosting website is in New Zealand, my servers are in New Zealand. Why would I care about US laws? Asking for a friend.

Because the US will strong-arm the NZ govt into arresting you for piracy.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#285
post #270

Earlier quoted context omitted.

If it’s your right to use an adblocker under the theory that you should control what requests your browser makes from your device, then which requests it makes are also your responsibility. Regardless, whether you intended to send my server a request is your problem. The fact is that you did, and that hardly gives full control of my business to whatever legal jurisdictions claim you as their subject.

Well, as it turns out, it's your problem. Like, literally :) Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers. I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that…

Well, as it turns out, it's your problem. Like, literally :)

Only if the EU can enforce it, which they can’t. I don’t pay attention to laws from other countries that don’t apply to me and have no teeth, and I’ll ignore this one as well, until there’s some enforcement mechanism. At that point I’ll evaluate. I’d probably just block the EU though; not worth the hassle.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#286
post #79

Earlier quoted context omitted.

> clear signal they don't care Or, it could mean they hadn't realised how much work it'd take to be GDPR compliant, and decided to temporarily use geographical blocking until they can be compliant.

It took them 2 years to realise that? That’s the same as not caring.

They were not remotely thinking about this 2 years ago.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#287

Earlier quoted context omitted.

So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.

Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…

Not an expert or anything, but this was linked on the page.

"Does my organisation need a data protection officer (DPO)?"

https://ico.org.uk/for-organisations/does-my-organisation-ne...

1. Are you a public authority? (not sure what this is)

2. Do your organisation's core activities involve tracking and monitoring people's behaviour (for example on the internet, or on CCTV) on a large scale?

3. Do your organisation's core activities involve processing on a large scale 'special categories' of personal data, or large scale criminal convictions or offences data?

(By 'special categories' we mean personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, data concerning health or data about a person's sex life or sexual orientation, or genetic or biometric data where it woiuld [sic] identify a living person.)

Re: GDPR: US news sites unavailable to EU users over data protection rules

#288

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

[deleted]

Re: GDPR: US news sites unavailable to EU users over data protection rules

#289

Earlier quoted context omitted.

So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.

Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…

[deleted]

Re: GDPR: US news sites unavailable to EU users over data protection rules

#290
post #236

Earlier quoted context omitted.

Not every claim on HN needs a backup. This one makes total sense to me. In this case, the article itself shows that regulation is definitely decreasing alternatives, which in turn can lead to monopolies

Glad you can tell how regulation affects a market after less than one day of being active law, and zero enforcement actions or cases suggesting how courts/regulators are going to interpret the rules.

You do know that GDPR is not the first regulation that has ever been written correct? There is a huge body of economic literature already dedicated to the subject.
Post reply on HN