Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

21–30 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#21
Site got hugged. Google cache: http://webcache.googleusercontent.com/search?q=cache:www.get...

In short: the opinion expressed by that link appears to be plainly wrong as the organization using IP addresses to restrict EU traffic for the sake of GDPR would need the ability to actually identify people from that information, a power arising from access to other information. The vast majority of entities lack that additional, so for them, IP addresses are not 'personal data' under existing case law.

In long: I'm not providing legal advice, only forwarding details (again, non-representative) conversations I've had or been party to with various lawyers on this topic. Notably: the consensus opinion is that determining a potential IP range is specific to the EU is not the same as geolocating them as that location information is not specific enough to determine who the person is, and partly as a result of a lack of this capability and others, IP addresses cannot alone be determined to be personal data.

Related: https://www.whitecase.com/publications/alert/court-confirms-...

> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:

> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and

> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.

> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.

By precedent (unless I'm missing more recent case law), for the vast majority of entities possessing IP addresses e.g. through request logs, an IP address is not "personal data," and determining the continental whereabouts of an IP would therefore not be considered "profiling."

I'm not a lawyer; I'm only relaying what's come up in conversation between attorneys covering the topic. I'm open to seeing the position I'm relaying above proven wrong.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#22
Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22)

> The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#23
post #11
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

I find it pretty problematic that the US does that to gambling site operators. People who do things that are legal where they live should not have to fear that they'll get arrested when they visit a foreign country just because those things are not legal in that country.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#25
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Does your bank need to maintain a good relationship with European governments? If not, does it need to remain connected to banks that do?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#26

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

IP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there.

Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these logs indefinitely as if they weren't sensitive.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#27

Assuming the article is correct in its interperatation of the law, it is still missing the point. If you do neot operate out of, or do business in, the EU, then the EU has no claim for jurisdiction. The only simmilar case I can think of is the Isreali law which prohibits entry into the country by anyone supporting BDS. Notably, in this case they are not even claiming that everyone on the planet is required to not sup…

Then why block the EU to begin with? The argument is clear, blocking users is not a panacea.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#28
post #15

So the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies…

> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.

How will they do that to a company that has no presence in that country and is actively blocking any access from that country?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#29

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming.

No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law.

But: GDRP will filter out businesses that existed in the legaly grey area because technology was faster than the law in this type of busines competitive advantage features.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#30
post #15

So the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies…

I only have basic knowledge of the law (I'm in the US) and I'm curious. If you're not operating at all in the EU and outright block EU IP ranges, can the EU take any action against you if an EU citizen manages to access the site and you do not comply with GDPR? Surely that is out of their jurisdiction, right?

I have US-only clients currently freaking out because they think they are going to be sued into oblivion, but I can't imagine they have anything to worry about (we've been giving them the whole "we can't provide legal advice, talk to your lawyer about what you need to do and we'll work with you to make it happen" line)

Post reply on HN