There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?
Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...
Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
31–40 of 140 posts
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#32No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.
Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…
Did they? Isn't Facebook's GDPR flow "agree or fuck off forever"? https://techcrunch.com/2018/05/25/facebook-google-face-first...
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#33Assuming the article is correct in its interperatation of the law, it is still missing the point. If you do neot operate out of, or do business in, the EU, then the EU has no claim for jurisdiction. The only simmilar case I can think of is the Isreali law which prohibits entry into the country by anyone supporting BDS. Notably, in this case they are not even claiming that everyone on the planet is required to not sup…
Then why block the EU to begin with? The argument is clear, blocking users is not a panacea.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#34Juristiction. By this same logic you have to comply by the rules of the Great Firewall of China.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#35So the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies…
That's seriously optimistic. From what I can tell, most companies realized about a week and a half ago that this was going to be an issue and freaked the hell out.
I'm still getting a stready stream of better-late-than-never GDPR emails.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#36So the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies…
> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.
Litigating on this particular issue would be an incredible stretch though. Offends basic sense of fair play imo.
If Turkey gets EU membership, it would be a hoot to see how Erdogan uses this law.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#37Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#38No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.
IP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there. Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these lo…
Your premise appears to be flawed in the context of established case law. IP addresses alone are not considered 'personal data' unless you have the capacity to readily add other information to add color. See below:
https://www.whitecase.com/publications/alert/court-confirms-...
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and
> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.
> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.
The vast majority of entities do not meet the requirements for #2.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#39No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.
Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…
Probably not. It would make sense to roll out services on a country-by-country basis, limiting exposure to those where the national data regulator is known. EU lobbyists and lawyers were just granted a massive break.
Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
#40Earlier quoted context omitted.
Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…
> Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. Did they? Isn't Facebook's GDPR flow "agree or fuck off forever"? https://techcrunch.com/2018/05/25/facebook-google-face-first...
Two things: they are still operating in EU, and it didn't go well for Microsoft itself when they tried to disobey EU.
So, we'll see how it ends.