Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

391–400 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#391
post #142

Earlier quoted context omitted.

That's the takeaway I'm arriving at as well. We (as an industry) had about two decades to be responsible and hold others to account with user data online. Instead we opted to pretend like a weasely Terms of Service replaced a sense of morality. Now we face regulation because, as it turns out, people care about how we use their data and how we influence them. Not exactly shocking that we ended up here.

Do people care that much about we use their data? I mean they care a little bit, but I still think given the choice between where we're at technologically and where we'd be if no one had access to users data -- I think the vast majority would take where we're at today. The funny thing is that I generally wish companies did more with my user data. Why don't events sites do a better job just showing me events it thinks…

That's great and your choice it shouldn't be the default for everyone. If someone sees the benefit in an algorithm learning what they like then let them pick that option. It's not up to engineers to assume what someone cares about.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#392
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Cutting access in Europe does not solve anything. I'm living in US but I am European. Thus I can visit any of the above listed website they are processing my data, and GDPR applies to me. So they are not complying and I could file a complaint.

File a complaint with who? There's no EU-wide data privacy regulator. Which specific EU country would have jurisdiction over an interaction which took place in the US?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#393

Earlier quoted context omitted.

Cutting access in Europe does not solve anything. I'm living in US but I am European. Thus I can visit any of the above listed website they are processing my data, and GDPR applies to me. So they are not complying and I could file a complaint.

Personally, this is the fun part of GDPR for me. The days of weasling out of regulations for private data with cute workarounds are coming to an end.

How in the heck is "blocking all European users" a cute work around?

The laws apply to European people. What if a site just doesn't want any of these people to be customers?

The EU can't force you to accept it's users.

If anything, the business should sue the EU customers who accessed their website without permission. You are breaking the rules as a EU citzens by doing so.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#394

Earlier quoted context omitted.

> Only if I make significant money from that market. If most of my revenue/profit comes from the US and it's problematic to "do business" in the EU or China, why wouldn't I want to just cut access off rather than dealing with potential hassles? Because you would rather grow your market?

There are 6.5 billion non-Europeans, there's plenty of market outside of Europe.

> There are 6.5 billion non-Europeans, there's plenty of market outside of Europe.

The world doesn't have uniform GDP per capita. Potential European customers have more money to spend than most of those other potential customers. If you're looking for a new market, Europe is a juicy one.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#395
post #386

Earlier quoted context omitted.

If your business is not profitable when you respect the privacy preferences of your users you simply don't do business. This is a false dichotomy: 1. Fully comply with the GDPR, no matter the cost, even if that's just legal and administrative because you're not actually doing anything in terms of data practices that would violate the law. 2. Go out of business, because you clearly are intending to do shady things tha…

See, that's not what GDPR does. Maybe In your alternative-facts GDPR, your case may have a point. I don't see why I should argue over a hypothetical GDPR, let's focus on the reality. About the burger thing, we do not need to assume things here, we can examine the reality and the reality is that McDonald's complies with the EU regulations when doing business in the EU, local American burger shops that don't do busines…

OK, so let's say that hypothetically I run a small business in the US. I just sell access to software (that lives on my server in the US) instead of burgers. An EU visitor comes to my server in my country and buys something. Why should I care about their laws any more than the burger shop owner should?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#396
post #261

Earlier quoted context omitted.

Such TOS would most likely be 'unduely onerous' or whatever the local term for this concept is in other EU jurisdictions. I've said this many times here already, but law is not a closed rule based decision tree. Intent matters, and laws are written in a way that they can be interpreted so that their meaning can be adapted to new circumstances or different times. Now, I'm not going to argue about whether that's how it…

Unduly onerous to say you're not allowed to access the site if you're in the EU? So the EU regulators can say my TOS have to allow EU citizens to access my site and my site must follow the GDPR. That seems unlikely, and the fact that there's so much ambiguity around this is why so many websites are opting to block the EU rather than dealing with it.

In many civil law systems, there are limits to contracts. Sometimes these limits are codified, sometimes they're not. Let's take Dutch law here as an example, because well that's what my degree is in. The Dutch civil code has a list of so-called 'black' and 'gray' clauses in terms and conditions; the black ones are always void, the grey ones sometimes (obviously grossly simplifying here, I'm not going to type a paper on a phone). Many catch-all statements are either black or grey, especially when they are designed to absolve one party from their legal obligations. Nobody is saying anything about requiring you to allow EU citizens. What I'm saying is the GP's plan is an obvious scheme to avoid one's legal obligations, and will be treated as such - and hence won't be a defense or obstacle when an authority goes after a non-compliant processor.

Hence my comment up thread - the law is not a closed system you can program like a code wars game, where if you're clever enough a judge will say 'oh you outsmarted me here because your logic is internally perfectly consistent, have a good day sir'.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#397

Earlier quoted context omitted.

>I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents. I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as…

My comparison is simply to show the standard laissez faire talking point of "oh, regulation exists just to protect incumbent market players" as bullshit: regulations exist to protect consumers from negligence and misbehaviour on the part of the companies. The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR. Equifax…

In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked, and the primary bottleneck to making software more secure is crap tools, crap platforms, poor training and inability to hire people who deeply understand security.

Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".

Re: GDPR: US news sites unavailable to EU users over data protection rules

#398

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

What is this, 1995? You're gonna need more than airbags and seat-belts and fuel efficiency.

Modern cars need ABS, TPMS, electronic stability control, passenger airbags, a backup camera and crash test standards all but demand side curtain airbags.

Don't get me started on emissions. Fuel economy really isn't a big deal or hard to meet. It's the half million other little things that need to be in a specific range that really waste the R&D time and money.

For something like a low end subcompact compliance is a huge chunk of the price.

Given the choice between a 1999 Toyota Solara (or whatever) which has one or two airbags for $5k or a new subcompact hatch with none of the listed safety features for $6k or $7k I'd probably take the subcompact. There's been huge improvements in all sorts of non-safety aspects of vehicle design in the past ~20yr that the subcompact has that the old sedan doesn't.

There's rapidly diminishing returns for regulating cars because by driving up the price of new cars you extend the time that the old ones stick around and the people who choose less safe alternatives (see mopeds in Asia)

Saying "regulation that mandates $goodthing is good" as a blanket statement is approximately of the same dumbness as saying "regulation is bad" as a blanket statement.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#399

Earlier quoted context omitted.

And how is this related?

I guess it isn’t. There are laws which US considers to be broken by external entities, yet US introduces a comletely inhumane programme worth of DPRK. Where’s the logic.

[flagged]

Re: GDPR: US news sites unavailable to EU users over data protection rules

#400

Earlier quoted context omitted.

Glad you can tell how regulation affects a market after less than one day of being active law, and zero enforcement actions or cases suggesting how courts/regulators are going to interpret the rules.

You do know that GDPR is not the first regulation that has ever been written correct? There is a huge body of economic literature already dedicated to the subject.

And you do know that not all regulations are the same? You are making it sound like some kind of universal consensus on the validity of regulations exists, but such a consensus does not exist because it's a way too complex, and wide, topic to be making blanket statements about.
Post reply on HN