Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

441–450 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#441
post #422

Earlier quoted context omitted.

Is your argument that someone else in the business should care or is your argument that EU visitors should not have rights to their data because it is inconvenient to you? Depending on your arrangement, if you are a reseller for example, you probably are not responsible for what that software does with your customer's data. Also, burger shops that do business in EU(usually chains, McDonald's and Burger King) do care…

Burger shops IN the EU are a completely different thing. My primary argument is that the GDPR's attempt to regulate companies in other jurisdictions because EU citizens go INTO those jurisdictions and do business is a dangerous precedent. If there was an enforcement mechanism for all such laws, it implies that any business or individual anywhere in the world with a website should therefore have to comply with any law…

So do you argue that businesses that do business over the internet should be subject to the laws where the business is legally based?

So, do you say that EU businesses should be able to operate in the USA but according to the EU laws and without any consideration to the US laws?

Or is your arguments something else, something selfish like all online businesses should operate according to the US laws or something like online businesses should not be bound by any laws whatsoever? Or something else?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#442

What if the US to passes a law that Americans are too fat and are no longer allowed to be sold gelato (they're allowed to buy gelato, but no longer allowed to be sold gelato), and then levy a multi-million dollar fine against every gelato shop in Italy where Americans visit on vacation. How is that different from the GDPR?

The difference is that one is an example of actual and well-thought out legislation in the EU which is generally welcomed by the people most affected by it: EU citizens. The other is a trumped up example by someone on whom the GDPR self-admittedly has hardly any bearing but who still insists on throwing a hissy fit because legislation is somehow un-american or something.

I disagree on "well thought out", but it doesn't really matter. I don't think that legislation is "un-american" or that the EU shouldn't have passed this law for its citizens. My issue is with the attempt to declare that it applies so broadly to organizations in other countries who have no connection to the EU except that EU visitors might come to their website. I'm going to assume you're intentionally not trying to understand the broader principle here, but just in case:

Reposted from another comment:

My primary argument is that the GDPR's attempt to regulate companies in other jurisdictions because EU citizens go INTO those jurisdictions and do business is a dangerous precedent. If there was an enforcement mechanism for all such laws, it implies that any business or individual anywhere in the world with a website should therefore have to comply with any laws from any jurisdiction that are similarly constructed.

If my website says things about Islam that Saudi Arabia passes a law against, I should be fined.

If my website disrespects the king of Thailand, I should be extradited for imprisonment.

If I encourage NK citizens to revolt against their oppressive regime, I should end up in a labor camp.

After all, those governments have a right to say that if I want to "do business in their jurisdiction", I must respect their laws, right?

(To be clear, I'm not talking about enforcement of these kinds of laws, because all of those countries might do the above if given the chance. I'm talking about what I SHOULD do as a matter of morality or ethics or civic duty or whatever, or what my government should cooperate with those governments on, because it's just.)

But the problem is that they're describing "doing business in their jurisdiction" as a citizen from their country (maybe even one who is currently visiting my country) going online and sending my server requests, data, and money. And apparently explicitly telling those citizens to please NOT do that, or blocking them, is not sufficient. The only way to make the majority of the EU users on HN happy is to comply. Why would that same logic not apply to all other kinds of laws?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#443

Earlier quoted context omitted.

But companies that do invest massively still get hacked. See: Google. Yahoo. Microsoft. It's also not even always clear what hacking actually means. A common way users get hacked is by reusing the same password on every website. One of those small sites gets hacked, the hackers try the users password at bigger sites to see if they work. Big players like Google and Facebook have heuristic systems that try to detect an…

> Basically, you can't stop a big company from getting hacked no matter how much you spend on security. I never said anything to the contrary, but the observation is irrelevant. You can't stop all pollution, but that doesn't mean you shouldn't pass regulations that ether ban it or impose liability for it.

That's an invalid metaphor. The point behind regulating specific types of pollution and fining companies that emit it is in fact to completely eliminate it. When total elimination isn't possible regulators have taken alternative approaches, like phase outs and carbon trading schemes.

The GDPR authors appear to believe that not being hacked is merely a matter of choice, despite all evidence to the contrary. They are clearly dangerously delusional. If even Google, with its pick of the crop, unlimited budget and massive security team, cannot avoid being hacked, then nobody else has a chance.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#444
post #297

Earlier quoted context omitted.

Well, as it turns out, it's your problem. Like, literally :) Only if the EU can enforce it, which they can’t. I don’t pay attention to laws from other countries that don’t apply to me and have no teeth, and I’ll ignore this one as well, until there’s some enforcement mechanism. At that point I’ll evaluate. I’d probably just block the EU though; not worth the hassle.

>not worth the hassle There you get it. If your business is not profitable when you respect the privacy preferences of your users you simply don't do business. It's not your god given right to violate user's privacy so that you can turn a profit. In other words, if you can't make a profit by selling 1$ burgers when you meet hygiene requirements just get out of the 1$ burger business. No need for hard feelings.

Well they ARE doing business. They are just blocking the EU.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#445
post #441

Earlier quoted context omitted.

Burger shops IN the EU are a completely different thing. My primary argument is that the GDPR's attempt to regulate companies in other jurisdictions because EU citizens go INTO those jurisdictions and do business is a dangerous precedent. If there was an enforcement mechanism for all such laws, it implies that any business or individual anywhere in the world with a website should therefore have to comply with any law…

So do you argue that businesses that do business over the internet should be subject to the laws where the business is legally based? So, do you say that EU businesses should be able to operate in the USA but according to the EU laws and without any consideration to the US laws? Or is your arguments something else, something selfish like all online businesses should operate according to the US laws or something like…

So, do you say that EU businesses should be able to operate in the USA but according to the EU laws and without any consideration to the US laws?

If by "operate in the US" you mean that they are based in the EU and allow US residents to visit their website and purchase from them, then yes, absolutely. Why would it be any other way?

I just don't see how the alternative works at all. Why couldn't some city in France pass a law that if a citizen of their city buys something from your site based in Hong Kong, you owe that city a tax of $50k. That's obviously ridiculous and not enforceable, but why is it not based on the same underlying legal theory that a business is bound by the laws of jurisdiction where visitors or customers to their site originate from?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#446

Earlier quoted context omitted.

> Basically, you can't stop a big company from getting hacked no matter how much you spend on security. I never said anything to the contrary, but the observation is irrelevant. You can't stop all pollution, but that doesn't mean you shouldn't pass regulations that ether ban it or impose liability for it.

That's an invalid metaphor. The point behind regulating specific types of pollution and fining companies that emit it is in fact to completely eliminate it. When total elimination isn't possible regulators have taken alternative approaches, like phase outs and carbon trading schemes. The GDPR authors appear to believe that not being hacked is merely a matter of choice, despite all evidence to the contrary. They are c…

Regulators don't care if you're hacked.

What they care about is how much data you had (and did you need all of it), did you tell the users, have you put things right, had you done anything to protect the data?

If you have a lump of data that you don't need, that you store with no attempt at encryption, and it's held behind software that you haven't bothered to update even though security patches have been released then yes, you're going to be regulated.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#447
post #332

Earlier quoted context omitted.

Ones related to safety. The other ones related to a nebulous concept of data privacy

If my car crashes or I am extorted due to my sexuality or killed for my religion. All the same. It is deadly. Data Privacy is not a nebulous concept. It is a human right. It is for that reason in the German constitution.

If you have to keep your religion secret to avoid being killed, you have MUCH bigger problems in your society that I don't think "nobody knowing who is secretly Jewish" is actually going to fix.

It's not like a future hypothetical fascist dictatorship isn't going to have access to the necessary records to piece it together or would follow its own GDPR constraints, nor would the GDPR stop it from arbitrarily deciding some people are Jewish without detailed evidence.

I'd like to think the GDPR is underpinned by better philosophy than a false hope it could prevent a future Holocaust.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#448

Earlier quoted context omitted.

Cool dude. You don't plan to take care of my data I certainly don't want to be entrusting you with it.

False equivalence. I don't misuse any user data, never have or will. But I'm still not compliant, nor will I be for the foreseeable future, unless someone can tell me why I should care about a law from some other country that has no mechanism of enforcement?

You may handle my data appropriatly, but how the hell do I know? Take some guy on the Internet's word for it?

What I do know is that massive numbers of services like yours are missusing, mishandling, or lossing my data every year. I'm not OK with that.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#449
post #320

Earlier quoted context omitted.

"This site does not collect personally identifiable information or persistent identifiers from, deliver a personalized experience to, or otherwise track or monitor persons reasonably identified as visiting our Site from the European Union. We do identify EU internet protocol (IP) addresses for the purpose of determining whether to direct you to USA TODAY NETWORK’s EU Experience. This site provides news and informatio…

I was surprised when my adblocker didn't bleep once. This is like looking what the internet could be. It could've been great.

Of course, that vision of what the internet could be never really answered the question of where the money was coming from to pay for the servers that are delivering that content.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#450

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

Relations, the regulators that make them, and the incumbents that support those regulators are under a sort of survival of the fittest to optimize for regulations that protect the incumbents but do so without being obvious and with some benefit to the consumer. Regulations that clearly support the incumbent and which clearly have no benefit to consumers will be the easiest to attack and remove. So if you want to cherry pick regulations, you can make them seem like perfect things that no sane person would ever have an issue with.

Look at how fines work, say with the GDPR. The maximum fine is 20 million or 4% of revenue, which ever is larger, which means that small businesses see a much larger risk as a percent of revenue from these regulations. This is independent of the chance of the max fine being applied. This inherently creates a pro-incumbent bias even if nothing else about the law created pro-incumbent bias.

Post reply on HN