Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

331–340 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#331

Earlier quoted context omitted.

So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.

Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…

There's a lot of confusion around this because GDPR actually specifies two different kinds of representative.

There is the Data Protection Officer (DPO), which comes from Article 37, and a representative in the Union (EU Rep), which comes from Article 27.

The purpose of the DPO is to oversee data protection. Whether or not a company needs one depends on the nature and volume of data they handle. I'd expect most small companies that are selling a product or service would not need one.

The purpose of the EU Rep is to provide a point of contact in the Union for data subjects and regulators to contact the company. It is only required for companies that are not in the Union. If the company only occasionally processes data, does not process data from certain particularly sensitive categories, and the processing is unlikely to result in a risk to rights and freedoms of natural persons, no EU Rep is required.

The DPO requirement seems to generate a lot more discussion than the EU Rep requirement, which I find odd. The EU Rep seems to me a much bigger deal from the point of view of small non-EU companies, because the EU Rep has to be in the Union.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#332

Earlier quoted context omitted.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

Ones related to safety. The other ones related to a nebulous concept of data privacy

If my car crashes or I am extorted due to my sexuality or killed for my religion. All the same. It is deadly. Data Privacy is not a nebulous concept. It is a human right.

It is for that reason in the German constitution.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#333

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

Vast difference between those examples, not least of which is that there are concrete rules around automotive safety to easily calculate the cost of implementation and verify compliance.

GDPR is full of vague terms and is global regulation based on principle rather than actual hard rules, which will increase costs and come nowhere near accomplishing the objectives it claims to do.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#334

Earlier quoted context omitted.

From the same site: """ Under the GDPR, you must appoint a DPO if: you are a public authority (except for courts acting in their judicial capacity); your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offen…

> 'large scale' in terms of the GDPR. I have no idea what that means. If my B2B business has a lot of revenue but few customers, am I 'large scale'? If my B2C business has little revenue but a lot of customers, am I 'large scale'? Or maybe 'large scale' applies to the number of servers I use? I have no idea the criteria.

The keyword here is "large scale behavior tracking". Let's not elide over that.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#335
post #134

There are so many wrong things with this approach. First, what do you do when you have existing users, delete them? Second, I believe the law protects EU citizens regardless of where they are. If you're an EU citizen and register for a service somewhere in the US using VPN or while physically being outside the EU, that service/company will still need to comply. The safest approach is to comply. We're a tiny startup,…

> Second, I believe the law protects EU citizens regardless of where they are. That's incorrect. That is the attempted naive reach of the EU in action. The correct formulation is: the EU would like for GDPR to apply to all EU citizen data globally. US sites/services with no business reach into the EU, do not need to comply with EU privacy laws. 99% of businesses around the world (most small businesses), those outside…

> the EU does not lord over the US, their laws do not rule the US. This is legally how GDPR actually works

The number of people who have lost sight of this is unbelievable. It actually seems especially rampant on HN, which is kind of surprising, to be honest.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#336

Earlier quoted context omitted.

The US and EU have a good relationship. The EU can (probably will) use international law to hold you accountable and the US is likely to comply. EDIT: you is the hypothetical you. If the EU targets you then they will use international law to do so.

Enforcement in practice is almost certain to be "at the edge" with things like payment processors and ad networks that have direct business operations in the EU and are easy to demand third-party compliance from. If you literally don't do any business with EU entities, even at arm's length, enforcement is going to be impractical and unlikely.

If you plan on doing business with EU entities at any point in the future there could be risk

Re: GDPR: US news sites unavailable to EU users over data protection rules

#337

Earlier quoted context omitted.

There are ads. Just above the footer - 'Ad Content by Taboola'. I am accessing it from India. Edit: There many other ads as well not just from taboola.

Those ads are on www.usatoday.com, not eu.usatoday.com.

Right, but it seems Americans (and probably everyone outside the EU) are being redirected like the parent. I was, which is a shame since I’d love to see that version of the site. It’s almost like a good unintended consequence of the regulation.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#338

Honest hypothetical question... my website is in the US, my servers in the US, why would I care about the GDPR?

Honest hypothetical question... my file hosting website is in New Zealand, my servers are in New Zealand. Why would I care about US laws? Asking for a friend.

Can you explain to me the point of this comment? I'm too dense.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#339
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

The biggest area of regulations are food safety, health care, mining and transportation. There is a large theme for why does exist and rather established history on how things were before it.

And while all those has their share of monopolies, I do not see how the current data handlers on the web before GDPR is better. Google is massive. Facebook is massive. The number of online news papers that hold 90% of the market are few. Talking about how regulations is going to increase monopolies where its already monopolized seems strange.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#340

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

It will certainly depend on the application. Compliance could be as simple for many apps as deleting a user's data manually when you get a support ticket/email from them asking to. You don't need to build automated systems. Same if they ask for the data collected on them. It would be prudent for these companies to spend an afternoon creating a list of all the places where data is being stored about a user. That would…

Manual data deletion without an automated process sounds like a recipe for disaster.
Post reply on HN