Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

591–600 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#591
Can someone explain to me how the EU is planning on enforcing GDPR on US-based companies?

And even with EU companies, without some kind of third party auditing, how can you actually believe anyone's privacy policies which claim to conform?

What's actually preventing everyone from just claiming that they are following it, and then secretly breaking the rules?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#592
post #270

Earlier quoted context omitted.

If it’s your right to use an adblocker under the theory that you should control what requests your browser makes from your device, then which requests it makes are also your responsibility. Regardless, whether you intended to send my server a request is your problem. The fact is that you did, and that hardly gives full control of my business to whatever legal jurisdictions claim you as their subject.

Well, as it turns out, it's your problem. Like, literally :) Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers. I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that…

Not when a US site uses a "copy protection" mechanism to ban all EU users, and grants a copyright license giving full access to US users and no access to EU users. Then your EU-based choice to use a proxy becomes a copy protection circumvention under the ECD, and the user is subject to a lawsuit.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#593

Earlier quoted context omitted.

Apparently, WashPo prefers a more coercive method: https://www.washingtonpost.com/gdpr-consent/ Either pay or sell yourself. A gamble they might lose if people just stop sharing and click Washpo articles, but a possible route if others follow suit. Meanwhile, NPR goes more hardcore than even USA Today: https://text.npr.org I wonder, does that mean EU users are just a nuisance costing traffic, or that all graphics are…

> Either pay or sell yourself. What is your preferred third option for content that costs money to make?

[deleted]

Re: GDPR: US news sites unavailable to EU users over data protection rules

#594
post #365

Earlier quoted context omitted.

"Business" means website visit from a US/EU citizen travelling Europe. And even blocking them by IP and logging it is a violation. User can file a complaint against you, resulting in a ruling. Whether you ever see an "invoice" or see police officers is another topic. But you violate the regulation/law in another country.

Blocking by IP is okay, logging it is the only violation. And why on earth would you have to log those blocks?

That's right!

Re: GDPR: US news sites unavailable to EU users over data protection rules

#595

Earlier quoted context omitted.

>Obviously from what? Are you a GDPR compliance expert? You don't need to be a GDPR compliance expert to know that the costs of implementing GDPR are huge and I doubt any GDPR experts actually even exist today.

> You don't need to be a GDPR compliance expert to know that the costs of implementing GDPR are huge So you don't actually know anything, but you are going to pretend to know that it's "huge". > I doubt any GDPR experts actually even exist today Then why be so condescending and pretend that you are actually one?

You only have had to gone through the implementation challenges personally to know that it’s hard and the costs (to do it by the letter) are high. In fact to do it by the letter you’re going to have to hire a law firm to ensure you’re compliant and they’re going to err on the side of caution and take you down a rabbit hole of implementation changes.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#596

Earlier quoted context omitted.

My comparison is simply to show the standard laissez faire talking point of "oh, regulation exists just to protect incumbent market players" as bullshit: regulations exist to protect consumers from negligence and misbehaviour on the part of the companies. The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR. Equifax…

In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked, and the primary bottleneck to making software more secure is crap tools, crap platforms, poor training and inability to hire people who deeply understand security. Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".

> Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".

It doesn't say "don't get hacked", it says "if (when?) you get hacked, minimize the the cost to people who trusted you with their data". And the easy way to conform is: 1. do not collect more than you need to provide the service, and 2. do not keep the data you don't need any more just in case. Which should be the default, but in the world of cheap storage and data mining seems to be forgotten, or an afterthought. E.g. when a user unsubscribes we tend to set the flag "subscribed" to false next to the rest of their data, instead of removing the e-mail address we don't need.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#597

Earlier quoted context omitted.

https://gdpr-info.eu/recitals/no-43/ "Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance" This is one of the co…

Recital 43 is a fair objection -- I should rephrase what I said in light of it. I should have said: > "The GDPR requires many things, but there's nothing in there that says you can't reject the customer if they don't opt-in to the things you need them to opt-in to in order to provide the service. " The last sentence of recital 43 says that consent can only be given to those personal data processing operations that ar…

This is not the interpretation I've seen everywhere.

GDPR says 'accordingly, consent will not be considered to be free if the data subject is unable to refuse or withdraw his or her consent without detriment.'

The user needs to be able to use the service in the way they expect to, without needing to give their personal data for targeted advertising. Another way of putting it is personal data can no longer be used to pay for a service.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#598
post #355

Earlier quoted context omitted.

I am writing replies on GDPR topics the other way around ("I see you are from the US"). GDPR is a regulation for a topic which is important in the European societies. Not so much in the US (free capitalism) or China (social score).

I mean, fine. I'm not an EU citizen, I think GDPR is a pain in ass but ultimately is not my decision no matter how much I judge you all. But it does frustrate me that you all believe that GDPR will somehow be good for you. I've seen it said multiple times that when a massive American media company decides to pull out of the EU that a European alternative will emerge that is GDPR compliant and replace it. Do you actua…

I never believed that the GDPR is a protective regulation. It is a focused on huge players which coincidentally are all US based.

The winners of GDPR continue to be the big five. Hopefully, they will adjust their behaviors (after paying some painful fines) in spirit of this regulation. Despite he GDPR, these companies will stay the technology and innovation leaders they are today. This will not change by that. This regulation will hopefully just enforce them to consider data privacy as something a lot of people really value.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#599
post #320

Earlier quoted context omitted.

I was surprised when my adblocker didn't bleep once. This is like looking what the internet could be. It could've been great.

Of course, that vision of what the internet could be never really answered the question of where the money was coming from to pay for the servers that are delivering that content.

It takes many more servers to deliver a 200mb page than it does a 600kb page

Re: GDPR: US news sites unavailable to EU users over data protection rules

#600
post #221

Earlier quoted context omitted.

False. The marginal cost of an EU customer is no longer zero. Why should I put in a bunch of work for GDPR compliance if the cost to implement it exceeds the initial marginal cost of an EU user. There is still the rest of the world.

Good. if you do not value my privacy, I dont want you to do business here. another product will replace your own. And in all likeness an EU one, meaning less euros leaving the eurozone. I'm all for it.

> another product will replace your own

That's optimistic ... but there is no reason to believe in many niche areas that another equally good product will do that. It is very plausible that in fact what will happen is that EU customers will be significantly delayed in accessing valuable services and products. And in many cases the web sites provide those would be making no meaningful intrusion on privacy in the first place.

Post reply on HN