Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

611–620 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#611

Earlier quoted context omitted.

What it means for me personally is that The Washinton Post as well as the NPR can't be relied upon for reporting news, since they are apparently unable to even marginally interpret a legal document aiming for clarity and instead channel their incompetence into snarky behaviour that still isn't compliant with the GDPR. To wit (washpo): "You consent to the use of cookies and tracking by us and third parties to provide…

What's NPR doing wrong? Are they redirecting to the text-only version for EU IPs or something?

I looked at it with an EU proxy, it gives you the choice to either consent or go to the text-only version.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#612

Earlier quoted context omitted.

Apparently, WashPo prefers a more coercive method: https://www.washingtonpost.com/gdpr-consent/ Either pay or sell yourself. A gamble they might lose if people just stop sharing and click Washpo articles, but a possible route if others follow suit. Meanwhile, NPR goes more hardcore than even USA Today: https://text.npr.org I wonder, does that mean EU users are just a nuisance costing traffic, or that all graphics are…

What it means for me personally is that The Washinton Post as well as the NPR can't be relied upon for reporting news, since they are apparently unable to even marginally interpret a legal document aiming for clarity and instead channel their incompetence into snarky behaviour that still isn't compliant with the GDPR. To wit (washpo): "You consent to the use of cookies and tracking by us and third parties to provide…

for what it's worth text-only npr has been around for a while now

Re: GDPR: US news sites unavailable to EU users over data protection rules

#613

Earlier quoted context omitted.

The incidence rate for salmonella is pretty low either way, but you should definitely wash eggs before cracking them open, for the same reasons you wash your tomatoes. As for potatoes, no, we don't all cook them by boiling them in water -- many of us bake them, fry them, or use them for making hash browns. This might just be cultural, but I would actually be more inclined to wash them before boiling them, since the r…

Nope. In fact when I was in cookery school here in the EU, I was told that it is perfectly safe to eat raw egg here, but that in the US this is never advisable.

You can eat raw egg (yolks and whites) in the EU because chickens are inoculated against salmonella. This has absolutely nothing to do with whether or not salmonella is allowed to accumulate and/or incubate on the outside of the shell.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#614

Earlier quoted context omitted.

The problem is that those ads could not be pay-per-click because you need cookies, javascripts and other tricks to combat clickfraud and impression spam. If that USA Today site sticks around and adds advertising, it will presumably be low quality inventory like the internet used to be flooded with - casinos, punch the monkey etc.

Ohh I didn't know the EU just outlawed internet ads, TIL I guess. /s I can't stop laughing at the stupidity among americans

Is it reasonable to attribute ignorance of laws on another continent with stupidity?

Is nobody outside of America ignorant of these laws?

Also, how much of the internet technology and content you use and consume was created by Americans? Probably quite a lot.

Why so rude?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#615

Earlier quoted context omitted.

What's NPR doing wrong? Are they redirecting to the text-only version for EU IPs or something?

I looked at it with an EU proxy, it gives you the choice to either consent or go to the text-only version.

They may have just done that as a cheap and easy way to comply with the new regulations while they wait for the dust to settle. Especially since the text-only version already existed.

Also, I wonder how much of Washington Post and NPR's revenue comes from Europeans. It might not even make sense for them to spend resources to be more precise in their compliance.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#616

Earlier quoted context omitted.

Apparently, WashPo prefers a more coercive method: https://www.washingtonpost.com/gdpr-consent/ Either pay or sell yourself. A gamble they might lose if people just stop sharing and click Washpo articles, but a possible route if others follow suit. Meanwhile, NPR goes more hardcore than even USA Today: https://text.npr.org I wonder, does that mean EU users are just a nuisance costing traffic, or that all graphics are…

> Either pay or sell yourself. What is your preferred third option for content that costs money to make?

I did not judge what method they need to employ. I merely dubbed what they chose as coercion.

That said, ads in general do not require personal information, only targeted ads do. But trackers also trade in such data, collect it, build profiles as a service, etc.

We will see whether their choice pays off or whether the competition like the NYT will gain some new regulars.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#617
post #576

Earlier quoted context omitted.

USA Today originally distributed their advertisements on paper without any user tracking. I don't see why advertising without tracking is so unthinkable today.

I'm of the opinion that at some point USA Today had demographic data on it's users. Maybe polled directly, or based on a list of names in their subscriber database cross referenced with some other database. The idea that "user tracking" is now happening on the internet and not in print isn't true. Yes, internet tracking can follow you specifically, but that's because the systems have gotten faster and more connected.

This was true for a huge number of newspapers - user data was an enormous part of the ad business in the print days as well, and has some striking similarities to what happens today online.

Back then it took the form of the subscriber database as you suggest, and was used to help target and sell ads in the paper. The print industry often "sold" the subscriber list in detail to prospective advertisers to demonstrate the potential reach.

Losing detailed subscriber data was one of the primary objections many papers expressed to Apple's app store distribution model which can effectively render readers anonymous, as this was apparently one of the most valuable things they had.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#618

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

Same with npr! https://text.npr.org/ It's brilliant

Re: GDPR: US news sites unavailable to EU users over data protection rules

#619
post #53

Earlier quoted context omitted.

And how can be a business sustainable in this way?

By hosting non-tracking ads. Like they used to be before Google started this whole profiling menace.

I keep seeing this argument. But the reason I don't see this happening is the giant amount of fraud out there. Sure ad fraud is an arms race, but if you can't do js fingerprinting, cookies, etc it would be impossible to verify ad impressions are real humans, not bots. And actual clicks from real humans would be impossible to differentiate - not coming from the same bot clicking over and over again (can't store ip, cookie, etc I'm not sure how you'd distinguish).

Re: GDPR: US news sites unavailable to EU users over data protection rules

#620

Earlier quoted context omitted.

Recital 43 is a fair objection -- I should rephrase what I said in light of it. I should have said: > "The GDPR requires many things, but there's nothing in there that says you can't reject the customer if they don't opt-in to the things you need them to opt-in to in order to provide the service. " The last sentence of recital 43 says that consent can only be given to those personal data processing operations that ar…

Your business model's success is not "providing the service". EDIT: Quoth the British agency responsible for implementation: "The processing must be necessary to deliver your side of the contract with this particular person. If the processing is only necessary to maintain your business model more generally, this lawful basis will not apply and you should consider another lawful basis, such as legitimate interests." h…

Thank you for the citation; this is an interesting and useful discussion.

The contract that Facebook has with its users is not merely to serve as their social media platform. The contract includes personalized advertising.

Facebook, in the terms of their contract with you, give you X in exchange for Y. X is the social media platform. Y is personalized advertising. This is the contract. AFAICT from the GDPR, they don't specify boundaries for the terms of the contract itself, do they?

The ICO talks at length about what it means for processing to be "necessary" for the purpose of fulfilling a contract. But it doesn't state what the boundaries are as far as what constitute legitimate contracts.

For example, this would be a valid contract under the GDPR, AFAICT:

I offer to make you free sandwiches in exchange for you telling me some personal information about you and targeting you with advertisements while you're my sandwich shop or elsewhere; and I provide you an ability to revoke this contract at any time (and whereupon I will delete the data I've collected). Of course, this means you don't get free sandwiches anymore. This would not be an illegal contract under the GDPR, AFAICT.

Now, if my contract were just "I'm going to give you free sandwiches." Then yes, collecting data and advertising would not be necessary for that contract. But that isn't the contract.

Post reply on HN