Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

471–480 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#471

Earlier quoted context omitted.

Cutting access in Europe does not solve anything. I'm living in US but I am European. Thus I can visit any of the above listed website they are processing my data, and GDPR applies to me. So they are not complying and I could file a complaint.

File a complaint with who ? There's no EU-wide data privacy regulator. Which specific EU country would have jurisdiction over an interaction which took place in the US?

> Which specific EU country would have jurisdiction over an interaction which took place in the US?

OP’s country. The "place" that interaction took place in is irrelevant here, unless the company "doesn’t specifically target its services at individuals in the EU"; OP is citizen of an EU country so the GDPR rules apply.

(edit: rephrasing)

Re: GDPR: US news sites unavailable to EU users over data protection rules

#472

Earlier quoted context omitted.

There are benefits to washing the eggs, isn't there? I have read that in Europe as a consumer it's a lot more important to wash the eggs before using them.

You should definitely wash the eggs before you cook with them. As you mention, that is de rigueur for Europeans, as it is in America for things like lettuce and potatoes.

You should wash the eggs before opening them. If you cook them in boiling water without opening them (except for the prick at the bottom), I don't see how washing them beforehand would make a difference.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#473
post #221

Earlier quoted context omitted.

Good. if you do not value my privacy, I dont want you to do business here. another product will replace your own. And in all likeness an EU one, meaning less euros leaving the eurozone. I'm all for it.

if you do not value my privacy False equivalence. You can do nothing untoward with user data and still not be compliant.

Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal.

Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#474

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

Wouldn't it be sufficient to regulate outcome? I.e. mortality rate per passenger mile? Then, hypothetically, an AI company might be able to dispense with a lot of physical safety devices by taking advantage of the lower reaction times of a non-human driver.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#475

Earlier quoted context omitted.

Everything's fine if they add generic, non-targeted ads that are completely under control of the news publisher, hosted on their servers, don't track users, don't use cookies. Just like print media and TV does since forever.

The problem is that those ads could not be pay-per-click because you need cookies, javascripts and other tricks to combat clickfraud and impression spam. If that USA Today site sticks around and adds advertising, it will presumably be low quality inventory like the internet used to be flooded with - casinos, punch the monkey etc.

Ohh I didn't know the EU just outlawed internet ads, TIL I guess. /s

I can't stop laughing at the stupidity among americans

Re: GDPR: US news sites unavailable to EU users over data protection rules

#476

Earlier quoted context omitted.

So, you're saying if someone from Saudi Arabia sees a German website that shows a woman's bare knees, that the German site will have to pay Saudi fines?

The fans of this law seem incapable of separating its intent from the practical realities of the underlying principle it introduces. Namely, that every website on the internet is now subject to any laws by any jurisdiction in the world (down to the city level) because some subject of that jurisdiction might visit their site. It’s insane.

Fast Forward 10 years: "and that's how decentralized internet was born"

Re: GDPR: US news sites unavailable to EU users over data protection rules

#477

Earlier quoted context omitted.

Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.

I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.

What if - hypothetically - you came up with something safer then airbag & seatbelt? Even if all your customers found it to be self-evidently true that it was safer the only thing that would matter would be if the regulator thought it was safer. A regulator who is likely controlled by the incumbents.

Now with something like car safety it's easy to say - no one will come up with something like this or if they do then the regulator will immediately allow it. But what about something like Internet privacy? I think it's more likely in that case for the rules like the GPDR to be used to protect incumbents by keeping out competition.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#478

Earlier quoted context omitted.

I disagree on "well thought out", but it doesn't really matter. I don't think that legislation is "un-american" or that the EU shouldn't have passed this law for its citizens. My issue is with the attempt to declare that it applies so broadly to organizations in other countries who have no connection to the EU except that EU visitors might come to their website. I'm going to assume you're intentionally not trying to…

There is no conspiracy here. If you don't do business with the EU, the EU has nothing on you. They have no other mechanism for enforcing compliance. If you would disrespect the king of Thailand, and you would go to Thailand, they might act on their laws and lock you up. If you would break Eu privacy laws, and you would try and do business with the EU, they might act on their laws and enforce their fines. There is no…

You're focusing on the enforcement issue, and I agree with all the points you've listed here.

My concern is that they're even trying to make this claim, and that so many fans of the GDPR think it's a reasonable one.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#479

Earlier quoted context omitted.

I think the phrase "You're oversimplifying a complex situation to the point of no longer adding anything to the discussion" applies to your comment. No one here is saying that ALL regulations are bad or should be removed, just that all regulations have unintended consequences.

The grand parent did the exactly the same thing.

Not really, all regulation will favor incumbents - its just that some may with worth it. And it's worth noting that not all regulation is universally seen as useful.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#480
post #352

Earlier quoted context omitted.

If the 1-3 person startup's application is geared around personal information and it needs a complex privacy policy to describe what it does with data, then yes, it will have to work very hard to comply with GDPR, but that will also result in meaningful improvements in privacy and data control for its customers. Do you have examples of startups where data is not a core business concern, who still find it very onerous…

Here's an example: I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication. I've been talking to a very well known…

>It's a trivial application that stores mostly already public data

So wtf are you worrying about then? Only shady companies are afraid of GDRP, the fact that you look at GDPR as a problem is a huge let down in trust for your company

Post reply on HN