Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

301–310 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#301

Earlier quoted context omitted.

>I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents. I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as…

> VW haven't even been fined for cheating on their emissions test. Exec has been fined and sentenced to 7 years[0] VW have been fined $2.8B[1] [0] https://arstechnica.com/tech-policy/2017/12/judge-sentences-... [1] https://www.nbcnews.com/business/autos/judge-approves-larges...

By the US and 2.8B is a fraction of what they deserved to be fined. All VW execs should be in prison for the rest of their lives for what they have done.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#302

Earlier quoted context omitted.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

>I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents. I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as…

My comparison is simply to show the standard laissez faire talking point of "oh, regulation exists just to protect incumbent market players" as bullshit: regulations exist to protect consumers from negligence and misbehaviour on the part of the companies.

The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR.

Equifax lost millions and millions of records and have so far faced no meaningful punishment from the UK regulators: as far as I can tell, they've so far made one brief statement on their website, and one tweet.

Major ISPs like TalkTalk lost millions of records (and ignored security researchers telling them about gaping security holes) and were given a slap on the wrist - £400,000 by the UK ICO. Mere pennies per user in fines; a drop in the bucket compared to their annual revenue. There is no economic interest to change their behaviour.

The negligence of these companies has led to millions of people having their personal and financial data stolen, having to keep eagle-eyed over bank statements and credit cards, having to worry that their transactions (or their travel bookings) might get flagged up as suspicious, that their credit rating gets eaten, and much else besides.

If a company you've entrusted your personal data with—not just your tweets or whatever, but sensitive personal data including health data, data about your religious affiliation, sexual orientation, etc. loses that data, as a UK citizen, you currently have no right to appeal the ICO failing to take action. GDPR/DPA2018 changes that balance.

Companies tell consumers "hey, trust us with your personal data". Consumers do in the false belief that there is some protection or basic responsibility taken. When they colossally fail to take the most basic steps to protect consumers from data loss, the status quo was this: nothing happens to them.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#304

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

> hire an EU Representative

It's called Data Protection Officer and you only need to appoint one if processing personal data is your core business, which is reasonable.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

And yes, I expect the EU to enforce the consent rules. It's very central to the GDPR.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#305
post #153

Earlier quoted context omitted.

> However, I hope they will rectify and allow access again for EU users at some point soon. Honestly, I don't. I don't want this precedent of government overreach to stand. I wish more international companies would stop doing business with US citizens for the same reasons. > It seems to go against the idea of a borderless internet, and I blame the companies for that, not the EU. You don't blame border-based rules for…

> Honestly, I don't. I don't want this precedent of government overreach to stand. Why is it overreach? It's literally why we invented government! I, the little guy, couldn't find giants like Facebook or Google. That's why I asked my democratically elected government to work on the problem.

You don't have to use Facebook or Google if you don't like them.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#306

Earlier quoted context omitted.

This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws. It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.

Pass whatever law you want, just don’t expect me to care. This law has nothing to do with me. If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money.

Cool dude. You don't plan to take care of my data I certainly don't want to be entrusting you with it.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#307

Earlier quoted context omitted.

Why is HN non-compliant? They use Cloudflare which has gone out of their way to be compliant (to the point of offering US citizens and the rest of the world the same protections as EU citizens), and nothing else is included on the page that could track you (check it if you don't believe me). You can anonymize your profile, you can edit it and you can use one of several services to get your data out. On the whole it i…

> Why is HN non-compliant? > They use Cloudflare Just the fact that you use some GDPR-compliant service doesn't mean that your product is GDPR-compliant. Because your product has to make sure that it stores, processes, removes, rotates etc. personally-identifiable data in a GDPR-compliant way. E.g. HN doesn't offer a way to request the data they have on me, or to delete my account. This is not GDPR-compliant.

It only "doesn't offer a way" if you write an email to HN and they refuse to do it, or don't answer. I haven't requested that myself, so I don't know what answer you'd get. But I think, unless there's evidence that someone's got such an answer from them, it would be wrong to assume they won't/can't do it.

Deleting data etc. doesn't have to be automated i.e. with a button to do it. Writing to them and them doing it is sufficient.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#308

Earlier quoted context omitted.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

I think the phrase "You're oversimplifying a complex situation to the point of no longer adding anything to the discussion" applies to your comment. No one here is saying that ALL regulations are bad or should be removed, just that all regulations have unintended consequences.

The grand parent did the exactly the same thing.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#309

Earlier quoted context omitted.

> And how can be a business sustainable in this way? There are millions of businesses around the world that don't give a fig about European customers or the E.U. Hurts to hear it, but it's true. They manage to survive an thrive without any interaction with anyone in the E.E.A. It's a very European thing to think of the E.U. as the indispensable center of the world.

It works both ways.

You are correct. That's what makes visiting another country/region fun for many people. They like to explore and encounter things they don't have available to them where they live. Otherwise, why leave home?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#310
post #304

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

> hire an EU Representative It's called Data Protection Officer and you only need to appoint one if processing personal data is your core business, which is reasonable. https://ico.org.uk/for-organisations/guide-to-the-general-da... And yes, I expect the EU to enforce the consent rules. It's very central to the GDPR.

>It's called Data Protection Officer and you only need to appoint one if processing personal data is your core business, which is reasonable.

Not commenting on the validity of this statement but it's interesting how I can tell from which continent you are from just by you saying that the regulation forcing a business to hire DPO is reasonable.

Post reply on HN