Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

291–300 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#291

Earlier quoted context omitted.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

>I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents. I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as…

> VW haven't even been fined for cheating on their emissions test.

Exec has been fined and sentenced to 7 years[0] VW have been fined $2.8B[1]

[0] https://arstechnica.com/tech-policy/2017/12/judge-sentences-...

[1] https://www.nbcnews.com/business/autos/judge-approves-larges...

Re: GDPR: US news sites unavailable to EU users over data protection rules

#292
post #87

Earlier quoted context omitted.

People have tried lots of other stuff in the last 10-15 years, it was not sustainable (micro-transactions never took off, subscription-based newspapers are the exception rather than the norm etc). I'm personally fine with newspapers like the LA Times collecting and selling my personal data as long as I can read articles for "free" on their website, I think it's a pretty fair deal.

Part of the reason for the failure of those other models is their need to compete with an exploitative ad driven model. When you remove the lowest common denominator, you make it is easier for the market to accomplish something better.

And the other part of that failure is people don't want to pay for content, games, etc. They want it all to be free.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#293

Earlier quoted context omitted.

Regardless of whether the app has a cost in and of itself, the process of appointing a compliance officer and making sure that they understand their responsibilities under EU law is a necessary cost unless you happen to be developing the app yourself and already understand everything involved.

Read Article 27(2). There's a good chance that you don't need an EU representative unless your product is based around the processing of personal data. Also read Article 37(1), you _don't_ need a compliance officer unless you are dealing with one of the special classes of personal data or performing "regular and systematic monitoring". https://gdpr-info.eu/art-27-gdpr/ / https://gdpr-info.eu/art-37-gdpr/

> Read Article 27(2). There's a good chance that you don't need an EU representative unless your product is based around the processing of personal data.

To fall under that, the processing has to be "occasional". I've not been able to find any authoritative guidance on what that means.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#294

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

If your startup doesn’t have any business in the EU, they can’t go after you.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#295

Earlier quoted context omitted.

Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.

I wonder if it's really necessary to stop using e-mail addresses as usernames / unique identifiers. Presumably you need some sort of unique identifier for each user, and such an identifier can, by definition, be tied to an individual. Would such an identifier not fall under "data required to provide the service"?. And since any such identifier is effectively PII, does it really matter if you use an e-mail address vs.…

Not using an email address will effectively ensure the person can never recover their account.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#296

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

> Regulations tend to favor incumbents, decreasing competition Except in Europe where it has done the exact opposite for telecom, especially compared to the unregulated US.

> telecom

> unregulated US

On the contrary, telecoms are very much regulated in the US. There is an entire commission for regulating radio/television/cable communications: the FCC.

I could hardly choose a more regulated industry than telecommunications.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#297
post #270

Earlier quoted context omitted.

Well, as it turns out, it's your problem. Like, literally :) Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers. I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that…

Well, as it turns out, it's your problem. Like, literally :) Only if the EU can enforce it, which they can’t. I don’t pay attention to laws from other countries that don’t apply to me and have no teeth, and I’ll ignore this one as well, until there’s some enforcement mechanism. At that point I’ll evaluate. I’d probably just block the EU though; not worth the hassle.

>not worth the hassle

There you get it. If your business is not profitable when you respect the privacy preferences of your users you simply don't do business.

It's not your god given right to violate user's privacy so that you can turn a profit.

In other words, if you can't make a profit by selling 1$ burgers when you meet hygiene requirements just get out of the 1$ burger business.

No need for hard feelings.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#298
post #235

Earlier quoted context omitted.

Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

>You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

Where in your statement do you refute the fact that it is hard to comply with GDPR?

Even if you have a legitimate use case you still need to provide users a way to access all their information and delete all their information.

If you already are using more than one database this is not trivial.

This is my guesstimate but I am confident in saying that GDPR adds $25k worth of work to the cost of starting up a business in the EU assuming an experienced software engineer is worth $150k a year. There will simply be a huge layer of boiler plate code added to every project now that will be necessary whenever you are processing data.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#299

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

It will certainly depend on the application. Compliance could be as simple for many apps as deleting a user's data manually when you get a support ticket/email from them asking to. You don't need to build automated systems. Same if they ask for the data collected on them.

It would be prudent for these companies to spend an afternoon creating a list of all the places where data is being stored about a user. That would just help if it ever becomes necessary to actually delete data.

See elsewhere in these comments for information on appointing an EU representative. It is not required in most cases.

"Bespoke permissioning" is also required if you have tiers of users with different feature sets (free, basic, premium). So just treat whatever private-data-requiring-thing as a feature that needs consent.

Incidently, the evolution of smartphone permissions has also gone in this way, allowing fine grained allowing/disallowing. You have to expect that you wont have all the permissions you want. The GDPR just makes it so that you don't get to say "all or nothing" for the things that don't need permission. But, the good apps were already doing this anyways.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#300

Earlier quoted context omitted.

This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws. It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.

It's not necessarily that American companies are having trouble complying. Some of them like the ones the article is about just have little incentive to do so. If I'm in essence doing no business in Europe it's more efficient to just block European visitors. Having grown up in Europe I'm much more sensitive to privacy concerns than most Americans, but it's not proper to assume that anyone who just blocks European vis…

Whether they are "nefarious" might depend on who you ask, I suppose, but anyway, fair enough. As an American who cares deeply about online privacy, I will be actively avoiding US companies who don't comply with European privacy laws (easy way to filter). I'm willing to bet the real incentives will turn out to be bigger than many of these companies think.
Post reply on HN