Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

361–370 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#361
post #297

Earlier quoted context omitted.

Well, as it turns out, it's your problem. Like, literally :) Only if the EU can enforce it, which they can’t. I don’t pay attention to laws from other countries that don’t apply to me and have no teeth, and I’ll ignore this one as well, until there’s some enforcement mechanism. At that point I’ll evaluate. I’d probably just block the EU though; not worth the hassle.

>not worth the hassle There you get it. If your business is not profitable when you respect the privacy preferences of your users you simply don't do business. It's not your god given right to violate user's privacy so that you can turn a profit. In other words, if you can't make a profit by selling 1$ burgers when you meet hygiene requirements just get out of the 1$ burger business. No need for hard feelings.

If your business is not profitable when you respect the privacy preferences of your users you simply don't do business.

This is a false dichotomy:

1. Fully comply with the GDPR, no matter the cost, even if that's just legal and administrative because you're not actually doing anything in terms of data practices that would violate the law.

2. Go out of business, because you clearly are intending to do shady things that violate user privacy.

if you can't make a profit by selling 1$ burgers when you meet hygiene requirements just get out of the 1$ burger business

Perfect example.

Say I run a burger shop that is perfectly clean and in compliance with all local laws, but the EU passes a law that says I need to fully audit all my food safety practices, publish them in a public place with their format, appoint a food safety rep in the EU, and comply with other vague requirements that they deem necessary, just in case an EU citizen visiting the US comes and eats at my shop.

Now, if I ignore that, am I "breaking the law"? I guess so. Just like I might be breaking some Indian law by serving beef at all (hypothetical). But does it actually matter? Can the law be enforced? Should I care as a matter of civic duty? Very likely not.

Worse, should the entire citizenry of the EU suddenly decide that my small town burger shop in Iowa clearly intends to feed every customer tainted beef and deserves their opprobrium and any fines that can possibly be levied by the EU, just because I didn't fully comply with their law?

And if they do develop some enforcement mechanism to use against small town USA burger shop, how is it not my right to put up a sign that says "Sorry, EU customers, but please don't eat here, as I don't comply with your laws"? Is your argument seriously that I should comply with every law from every jurisdiction in the world, just because a customer from that jurisdiction might wander into my shop, even when I've expressly told them not to?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#362
post #257

Earlier quoted context omitted.

> You assume that just because someone doesn’t want to got through all the hassle of being GDPR compliant that the website is somehow bad? If they are not collecting any personal data, there is no hassle. Do you think it's somehow bad for a car manufacturer to not want to go through the hassle of making their cars conform to the safety standards? > Among other things this includes setting up an EU represeneitive Cita…

>Obviously from what? Are you a GDPR compliance expert? You don't need to be a GDPR compliance expert to know that the costs of implementing GDPR are huge and I doubt any GDPR experts actually even exist today.

> You don't need to be a GDPR compliance expert to know that the costs of implementing GDPR are huge

So you don't actually know anything, but you are going to pretend to know that it's "huge".

> I doubt any GDPR experts actually even exist today

Then why be so condescending and pretend that you are actually one?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#363
post #270

Earlier quoted context omitted.

If it’s your right to use an adblocker under the theory that you should control what requests your browser makes from your device, then which requests it makes are also your responsibility. Regardless, whether you intended to send my server a request is your problem. The fact is that you did, and that hardly gives full control of my business to whatever legal jurisdictions claim you as their subject.

Well, as it turns out, it's your problem. Like, literally :) Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers. I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that…

Well played sir.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#364
Facebook, Google, Instagram and WhatsApp are accused of forcing users to consent to targeted advertising to use the services.

Privacy group noyb.eu, led by activist Max Schrems, said people were not being given a "free choice".

I mean, that just isn't a valid complaint IMO. You have a choice -- you can not use Facebook, or not use Google, or not use Instagram, or not use WhatsApp.

If you're using a "free" service that is ad-funded, why do you think you have a right to use it without consenting to the ads?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#365

They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…

If your startup doesn’t have any business in the EU, they can’t go after you.

"Business" means website visit from a US/EU citizen travelling Europe. And even blocking them by IP and logging it is a violation.

User can file a complaint against you, resulting in a ruling. Whether you ever see an "invoice" or see police officers is another topic. But you violate the regulation/law in another country.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#366

Earlier quoted context omitted.

What exactly do you want here? Do you want every site to have you upload your passport? Or are you just saying that any jurisdiction in the world should be able to effectively force every company globally to comply with their laws, and that they can’t pull out of those markets if they find the law too onerous? Forget about the intent of the GDPR, what about the broader principle when applied to laws you don’t like? W…

My comment doesn't make a statement about how things should be. It's a statement about the complexities of a technical implementation: _If_ it is true that the GDPR covers an EU person's data held by any company worldwide, regardless of how or whether it should, an IP block might not be accepted as compliance. Or it might, if the EU regulators decide that best-effort is enough. The important point is that many Europe…

I am curious how this will play out. I am not sure how else EU regulators could play it out without essentially saying that all users must identify themselves honestly to a site.

What happens if a person marks their country of origin as US even if they aren't in the US and their IP isn't. They lie in that case, but are they still protected?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#367
post #355

Earlier quoted context omitted.

>It's called Data Protection Officer and you only need to appoint one if processing personal data is your core business, which is reasonable. Not commenting on the validity of this statement but it's interesting how I can tell from which continent you are from just by you saying that the regulation forcing a business to hire DPO is reasonable.

I am writing replies on GDPR topics the other way around ("I see you are from the US"). GDPR is a regulation for a topic which is important in the European societies. Not so much in the US (free capitalism) or China (social score).

I mean, fine. I'm not an EU citizen, I think GDPR is a pain in ass but ultimately is not my decision no matter how much I judge you all.

But it does frustrate me that you all believe that GDPR will somehow be good for you. I've seen it said multiple times that when a massive American media company decides to pull out of the EU that a European alternative will emerge that is GDPR compliant and replace it.

Do you actually believe that if the economics of GDPR compliance did not work for a large American business that it will somehow work out for a small EU startup? The only way I can see it work out is if GDPR is selectively enforced against American business which it seems obvious to me that will be the case.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#368

Well we still have HN, even if non-compliant.

Why is HN non-compliant? They use Cloudflare which has gone out of their way to be compliant (to the point of offering US citizens and the rest of the world the same protections as EU citizens), and nothing else is included on the page that could track you (check it if you don't believe me). You can anonymize your profile, you can edit it and you can use one of several services to get your data out. On the whole it i…

they have a public api/funnel to random services, can't edit data / can't download / delete my archive. their privacy policy is not updated, no cookie notice. i was fairly sure they used google analytics but it seems they removed them

Some people say that their use of s and inline styles is a punishable offence, i beg to differ.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#369

Earlier quoted context omitted.

Is that a bigger offence than „losing over 1400 migrant children” under an official governmental US programme, „some returned to child traffickers”? https://eu.azcentral.com/story/opinion/op-ed/ej-montini/2018...

And how is this related?

I guess it isn’t. There are laws which US considers to be broken by external entities, yet US introduces a comletely inhumane programme worth of DPRK. Where’s the logic.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#370
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Cutting access in Europe does not solve anything. I'm living in US but I am European. Thus I can visit any of the above listed website they are processing my data, and GDPR applies to me. So they are not complying and I could file a complaint.
Post reply on HN