Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

321–330 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#321
post #134

There are so many wrong things with this approach. First, what do you do when you have existing users, delete them? Second, I believe the law protects EU citizens regardless of where they are. If you're an EU citizen and register for a service somewhere in the US using VPN or while physically being outside the EU, that service/company will still need to comply. The safest approach is to comply. We're a tiny startup,…

Do you think a US business that has no intention of ever operating in the EU cares about European fines?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#322
post #11

The response to GDPR is interesting. If they are handling and selling your data in ways that are not compatible with GDPR, then you should seriously consider using someone else for that information.

> If they are handling and selling your data in ways that are not compatible with GDPR

Very few businesses actually sell data the way you are imagining and if all GDPR did was ban that business model I would be happy with the existence of GDPR. GDPR is much more than that and this insinuation that every business that doesn't want to deal with this hassle is somehow evil and selling ultra detailed profiles on you to the highest bidder is highly mistaken.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#324

Earlier quoted context omitted.

I wonder if it's really necessary to stop using e-mail addresses as usernames / unique identifiers. Presumably you need some sort of unique identifier for each user, and such an identifier can, by definition, be tied to an individual. Would such an identifier not fall under "data required to provide the service"?. And since any such identifier is effectively PII, does it really matter if you use an e-mail address vs.…

Not using an email address will effectively ensure the person can never recover their account.

You could also use a hash of the email so that you don't retain and can't reconstruct the original address. Then the recovery process can look for a valid account based on the provided email's hash, and if one is found, a recovery email can be sent to the provided address. Include an expiring, one-time-use token in the recovery link so you can immediately forget the address again.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#325

I am worried regulations will make the Internet more geographically fragmented. The best thing about the Internet is how it captures the long tail. A random person in Slovenia can read a local news site in Kansas if they wish. Even if spending just one minute of effort making itself available in Slovenia would be a loss for said news site. The Internet is by default global and everything is available to everyone. It…

There's no scenario where the 'open' Internet doesn't rip apart. Globally there will be dozens of GDPR type regulations, and that's just covering privacy. There will be a lot more for economic rules, cultural rules (eg governing speech), etc. Want to operate a service in 100+ countries? You'll have to comply with thousands of rules. Only giant companies will be able to do it. It's already extremely difficult to do. I…

I really think the EU guaranteed US tech dominance with this law. How many months of work did the EU just add to getting out an MVP? How are EU startups even going to do AB testing to improve their product without collecting user data?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#326
I have a profitable, bootstrapped SaaS business. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying.

I've been talking to a very well known giant corporation for months. The VP and director love my product and want to start using it right away. But their legal team is scared shitless with 4% fines in GDPR. They are putting some draconian clauses, (various ISO certifications and such) in the contract that I, as a small company, cannot comply. That's their interpretation of GDPR. It doesn't matter whether it's right or wrong.

The VP and Director are really nice people and I've developed very good rapport with them. But I'm afraid their patience will run out soon and they'll go back to using spreadsheets. A lose-lose situation.

This is the casualty of GDPR.

I'm all up for GDPR. I have uBlock, have blackholed all Facebook domains, etc. But don't assume that GDPR doesn't affect normal business transactions. Anyone who thinks, "Oh, how hard could it be?" has no idea what they are talking about.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#327

Earlier quoted context omitted.

Does your website serve users from EU region or do you intend to block incoming traffic form EU? If you serve them then you might want to collect some data points about them. It is like being on the internet you are by default given a chance to operate business (website in this case) in whatever country a user access your website from. You are not going to open a franchise in Germany and not abide by their local laws…

So, you're saying if someone from Saudi Arabia sees a German website that shows a woman's bare knees, that the German site will have to pay Saudi fines?

Did you just compare a data privacy law with some hypothetical obscure privacy law? Amusing. Per your analogy, if German website still wants to be shown in SA then either they get SA govt on board with w/e content they are serving (bare knees in this case) or they stop traffic coming in from SA altogether or they simply comply with SA local laws and censor content (bare knees). You should do some research on how US based website show content in Chinese region.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#328

Earlier quoted context omitted.

I think the phrase "You're oversimplifying a complex situation to the point of no longer adding anything to the discussion" applies to your comment. No one here is saying that ALL regulations are bad or should be removed, just that all regulations have unintended consequences.

The grand parent did the exactly the same thing.

He was certainly quite terse, but I wouldn't necessarily call that an oversimplification

Re: GDPR: US news sites unavailable to EU users over data protection rules

#329

Earlier quoted context omitted.

By the US and 2.8B is a fraction of what they deserved to be fined. All VW execs should be in prison for the rest of their lives for what they have done.

> All VW execs should be in prison for the rest of their lives for what they have done. You must point to the laws violated. E.g. Schmidt made a false statement to the California Air Resources Board under the Clean Air Act. Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law.

>You must point to the laws violated. E.g. Schmidt made a false statement to the California Air Resources Board under the Clean Air Act.

>Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law.

Stop trying to shift goalposts, my point is that if any company deserved to be fined 4% of global turnover it's VW and they have currently received a total of $0 in fines even though they have probably increased the likelihood of you getting cancer.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#330

Earlier quoted context omitted.

So, you're saying if someone from Saudi Arabia sees a German website that shows a woman's bare knees, that the German site will have to pay Saudi fines?

Did you just compare a data privacy law with some hypothetical obscure privacy law? Amusing. Per your analogy, if German website still wants to be shown in SA then either they get SA govt on board with w/e content they are serving (bare knees in this case) or they stop traffic coming in from SA altogether or they simply comply with SA local laws and censor content (bare knees). You should do some research on how US b…

By any means I am not a fan of GDPR.
Post reply on HN