Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

401–410 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#401

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

If you view that from the US, it redirects to the US site, full of Facebook crap.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#402
post #53

Earlier quoted context omitted.

And how can be a business sustainable in this way?

Everything's fine if they add generic, non-targeted ads that are completely under control of the news publisher, hosted on their servers, don't track users, don't use cookies. Just like print media and TV does since forever.

The problem is that those ads could not be pay-per-click because you need cookies, javascripts and other tricks to combat clickfraud and impression spam.

If that USA Today site sticks around and adds advertising, it will presumably be low quality inventory like the internet used to be flooded with - casinos, punch the monkey etc.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#403
post #235

Earlier quoted context omitted.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

>You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project. Where in your statement do you refute the fact that it is hard to comply with GDPR? Even if you have a legitimate use case you still need to provide users a way…

>Even if you have a legitimate use case you still need to provide users a way to access all their information and delete all their information.

Which, in the EU at least, you have had to do for decades under the Data Protection Directive.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#404
post #87

Earlier quoted context omitted.

People have tried lots of other stuff in the last 10-15 years, it was not sustainable (micro-transactions never took off, subscription-based newspapers are the exception rather than the norm etc). I'm personally fine with newspapers like the LA Times collecting and selling my personal data as long as I can read articles for "free" on their website, I think it's a pretty fair deal.

Part of the reason for the failure of those other models is their need to compete with an exploitative ad driven model. When you remove the lowest common denominator, you make it is easier for the market to accomplish something better.

I've never felt exploited by advertisers. Nor do most other people, otherwise they would keep their internet usage to a minimum when what we see is the exact opposite.

Please stop attacking services and sites that hundreds of millions or billions of people find useful because of your own over the top histrionics.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#405
The limitations of internet technology means that any computer located in the EU, whether or not the user controlling it is in the EU, can enjoy the beneficial effects of the GDPR. (Those limitations and effects being in part that companies will attempt to distinguish EU natural or legal persons based on IP address.)

The GDPR finally provides a legitimate, compelling rationale for users to employ longstanding methods of partially controlling the flow of their traffic through the internet, e.g. setting up a hosting account that uses servers located in the EU and using those computers to access www sites. An ssh account on a server located in the EU has gained new value.

Accessing the www from a computer located in the EU has new advantages, thanks to the GDPR. To users who are aligned with the goals of the GDPR, it is possible that www sites located in the EU have become more appealing than those located outside the EU.

How will EU news sites treat users from outside the EU? Is there a benefit to using EU news sites from outside the EU?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#406

Earlier quoted context omitted.

> Pass whatever law you want, just don’t expect me to care. That was exactly the position of too many companies: pass whatever law, I don't care. Well. It has gone on for too long, so, hopefully, now companies will start to care. > If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money. The EU is 500 million people. It looks to me that it's you who doesn't wa…

I treat all my users fairly and protect their data, and I am not intentionally targeting any EU users with anything I do online.

Your previous comments notwithstanding, this comment does have a legitimate point. If you truly do intend to take good care of your users’ data, then the goal should be to have you demonstrate that whilst making it as easy as possible for you to do so (without compromising the said care).

I’m hoping that over the coming weeks and months the enforcement of GDPR and various court cases will add clarity and allow the development of improved guidelines for becoming compliant. If a random SaaS company that users emails for logins and communication with active customers could look at a simple 5 point check list which they could check though in a day then things would be better for everyone.

Less burden for customers, wider services for users, and those firms that can see they could make a few small changes to become compliant would be more incentivised to do so.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#407
(Reply to a deleted comment on the burden of compliance as a US business)

If you truly do intend to take good care of your users’ data, then the goal should be to have you demonstrate that whilst making it as easy as possible for you to do so (without compromising the said care).

I’m hoping that over the coming weeks and months the enforcement of GDPR and various court cases will add clarity and allow the development of improved guidelines for becoming compliant. If a random SaaS company that users emails for logins and communication with active customers could look at a simple 5 point check list which they could check though in a day then things would be better for everyone.

Less burden for customers, wider services for users, and those firms that can see they could make a few small changes to become compliant would be more incentivised to do so.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#408

Earlier quoted context omitted.

Pass whatever law you want, just don’t expect me to care. This law has nothing to do with me. If you don’t want to do business with me because I’m not compliant, don’t send me server requests, data, or money.

Is that the professional opinion of IndieHive LLC as well?

I treat all my users fairly and protect their data, and I am not intentionally targeting any EU users with anything I do online.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#409
post #235

Earlier quoted context omitted.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

>You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project. Where in your statement do you refute the fact that it is hard to comply with GDPR? Even if you have a legitimate use case you still need to provide users a way…

So what you're saying is that it will cost money to retrospectively fix a badly designed service? Good.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#410
post #318

Earlier quoted context omitted.

Yes, I'm from Europe, and it's my opinion that the GDPR is very necessary and mostly reasonable. I say that even though it caused me a lot of work for the past months. The requirement to hire a DPO is not a new thing, by the way - many countries in the EU already required this. This is true for many provisions in the GDPR - in Germany, for example, very little changes from the way it used to be, their data protection…

>The requirement to hire a DPO is not a new thing, by the way - many countries in the EU already required this. This is true for many provisions in the GDPR - in Germany, for example, very little changes from the way it used to be, their data protection law was strict to begin with. Good for those countries? I'm not going to be happy with the idea of hiring some idiot to sit around and do nothing all day.

Jesús Christ, how disingenuous can you be? "Hiring" a DPO basically means appointing someone to the role who will take over these responsibilities. Depending on the size of your firm, the workload might be quite low and somebody can do it on the side, or, if you're talking Facebook, you might have a small department to do it.
Post reply on HN