Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

1–10 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#5
I predict secretive offshore entities which exploit activities banned under GDPR which have sufficient economic value. Entities which are essentially judgment proof in EU. Maybe directly affiliated with a foreign government.

Being able to do certain kinds of background checks or financial risk calculations is the first use case which comes to mind.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#6
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

If the company does not have a data protection officer (or if the DPO doesn't comply with users' requests), users can go to their national government's data protection regulator. No need to go to court.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#7
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Extradition?

Extradition treaties usually limit extradition to things that are punishable in both countries.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#8
No. (Usual caveats, not a lawyer, not an expert).

If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't.

Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant.

I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#10
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

> how would a user effectively get courts to enforce the GDPR?

Most Americans would prefer not to have European court judgments against them. That said, I agree this is absurd. If I choose to do business in your country, that is one thing. But extending that to blocking my right not to do business in your jurisdiction is silly.

Post reply on HN