Earlier quoted context omitted.
Because bitter HN users will call you shady if you don’t fully comply with their pet law, no matter how ambiguous or onerous :)
This "pet law" is the law of 500 million people, has been in effect for two years (two years was a grace period to comply with it), and exists exactly because shady businesses didn't even comply with existing data protection laws. It's not "bitter HN users". It's bitter European citizens. No wonder that it's mostly American companies who have the most trouble complying with it.
GDPR: US news sites unavailable to EU users over data protection rules
481–490 of 680 posts
Re: GDPR: US news sites unavailable to EU users over data protection rules
#482They claim that everyone had a lot of time, but what about the 1-3 person startup that’s been around for 4-5 years who is just getting by and didn’t have the resources to re-engineer their entire application or to write up a complex privacy policy or hire an EU Representative (Yes, apparently that is required as well). If the EU does clamp down on forced consent I think the long tail of small startups and publication…
> hire an EU Representative It's called Data Protection Officer and you only need to appoint one if processing personal data is your core business, which is reasonable. https://ico.org.uk/for-organisations/guide-to-the-general-da... And yes, I expect the EU to enforce the consent rules. It's very central to the GDPR.
Article 27 stipulates that data processors outside the EU should designate a representative, a whipping boy, if you will. The representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor.
In most cases it would probably be the same person fulfilling both the representative and DPO functions but those are actually two separate roles.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#483Earlier quoted context omitted.
Hopefully what will happen is that it will be more expensive to advertise and publishers will earn more on dumber ads Obviously if ads are less targeted then they may be less effective so advertisers will make less on ads that cost more. This will hurt their bottom line, which in turn will make the products we buy more expensive. But that's exactly the end goal. I want to pay for things (information, products) with m…
>Obviously if ads are less targeted then they may be less effective so advertisers will make less on ads that cost more. This will hurt their bottom line, which in turn will make the products we buy more expensive. But that's exactly the end goal. I want to pay for things (information, products) with more money rather than with slightly less money and all my integrity. I'm sure you considered all the poor people acro…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#484Earlier quoted context omitted.
I think it's because of a deep cultural divide. EU users who are big fans of the GDPR genuinely admire the law, both its intent and implementation, and also have a very positive view of the government. They believe that regulators will try to help companies comply, and will only fine as a last resort. Whereas in the US, we tend to be fairly skeptical of government. And as a consequence, since EU users think this law…
Bear in mind GDPR seems to have become some sort of totemic issue for the small minority of people in Europe who are true-blue died in the wool ideological supporters of the EU project. They are flooding GDPR discussions with these sorts of views. A good give away is they say "speaking as a European" or use the term "EU citizen" (there is no such thing, the EU as an institution does not have citizens or issue passpor…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#485Earlier quoted context omitted.
Honest hypothetical question... my file hosting website is in New Zealand, my servers are in New Zealand. Why would I care about US laws? Asking for a friend.
Can you explain to me the point of this comment? I'm too dense.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#486Earlier quoted context omitted.
You can make fun of it, but there's a reason that Silicon Valley venture capital goes to software engineering (where regulations have generally been lower) while significant disruption in the automotive space is coming from incumbents and one company founded by a guy with a net worth of $18 billion.
That would be the self same reason the net is starting to attract regulation. Some of that significant disruption basically involves extending a middle finger to the laws and regulations of the country they want to do business in. I might call it taking the piss. Taking the piss with laws and employment rights such as Deliveroo etc, or taking the piss with user data and personal privacy. We'll be left with some of th…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#487Earlier quoted context omitted.
if you do not value my privacy False equivalence. You can do nothing untoward with user data and still not be compliant.
Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#488Earlier quoted context omitted.
if you do not value my privacy False equivalence. You can do nothing untoward with user data and still not be compliant.
Exactly. The most basic/outrageous example: anyone in the EU who installs Apache and leaves it in its default configuration which logs all page visits indefinitely is now a criminal. Spin up a DO/Linode/etc. instance and apt-get install apache2? You're now theoretically liable for a 20 million Euro fine.
Do the same, but from any country in the world, and make sure your welcome page has multiple languages, including some EU ones. Now you're specifically targeting EU users and you're liable for up to $20 million euros.
The response from GDPR fans is that: a) regulators would never levy such a fine, or b) they can't enforce it, or even c) that of course you should be fined because you're a filthy scammer who is stealing people's data and violating their human rights!
But all that misses the point: in what universe is it reasonable to even make such a claim to begin with? And why should I have to trust that the regulators will be more reasonable than the law requires, or that they won't be able to enforce what they'd like to do? And why should I have to comply because you sent me your info voluntarily??
Is there something that makes the internet different here? If someone in the EU puts some personal info in an envelope and mails it to me and I never get around to opening it and it just sits on a stack with other junk mail, am I now violating their human rights by keeping the info they voluntarily sent to me?
Re: GDPR: US news sites unavailable to EU users over data protection rules
#489Facebook, Google, Instagram and WhatsApp are accused of forcing users to consent to targeted advertising to use the services. Privacy group noyb.eu, led by activist Max Schrems, said people were not being given a "free choice". I mean, that just isn't a valid complaint IMO. You have a choice -- you can not use Facebook, or not use Google, or not use Instagram, or not use WhatsApp. If you're using a "free" service tha…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#490Earlier quoted context omitted.
Part of the reason for the failure of those other models is their need to compete with an exploitative ad driven model. When you remove the lowest common denominator, you make it is easier for the market to accomplish something better.
I've never felt exploited by advertisers. Nor do most other people, otherwise they would keep their internet usage to a minimum when what we see is the exact opposite. Please stop attacking services and sites that hundreds of millions or billions of people find useful because of your own over the top histrionics.
The parent makes an excellent point: it’s easy to argue the other models (micro transactions, subscriptions, paywalls) failed because they were in competition with an industry that has safely operated with little to no regulation for a decade or two.
The ad industry in this situation has an insane advantage because it can make money from end-users without them even being aware that they are involved in a transaction. They don’t have to see a banner ad in order for dozens or hundreds of other businesses to learn about them.
There is no explicit contract between the website and the user in the way that there is when you agree to pay the business money in exchange for the value it offers.
So GDPR levels the playing field by removing that advantage. If an advertiser or another business runs above board they don’t have a problem. More to the point, if they can convince a user to opt in, then they have a serious value proposition to the user too.
Advertising itself is an easy and almost fallacious target. People know about adverts so they use Adblock. People have no idea what a business will do with all of the data that reaches their servers without any JS required.