Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

41–50 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#41
As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it.

After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves.

Imagine if China decided that Chinese citizens accessing foreign servers was a breach of national security due to the ability of these foreign servers to collect private browsing information, and imagine if China decided to make laws that fined these foreign entities in violation of their laws. It would be a fucking joke and it would be ridiculed internationally for good reason. China obviously knows this and they are prepared to get their hands dirty and implement the Great Firewall of China because they have no problem appearing as a controlling and authoritarian state.

So why doesn't Europe just do what China does and build their own firewall? If they really wanted to restrict collection by foreign servers which exist in non-EU jurisdictions and apply the regulation internally in the EU then they have the technical capacity to do so with a firewall.

Europe just can't bare the consequences of building such a firewall because it would destroy them in the court of public opinion. If EU citizens suddenly lost access to American services all hell would break loose. On a more political level the EU is a place which is generally known as being liberal and open and the construction of a mechanism designed to enforce their regulations by closing them off from the outside internet would be the construction of an authoritarian tool of censorship and restriction of freedom.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#42
post #36

Earlier quoted context omitted.

> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.

Allowing 28 separate, politically diverse and motivated data regulators to litigate a vague law against publicly unpopular multinationals is a recipe for capricious and arbitrary action, but I believe that was rather the intent. Litigating on this particular issue would be an incredible stretch though. Offends basic sense of fair play imo. If Turkey gets EU membership, it would be a hoot to see how Erdogan uses this…

> Litigating on this particular issue would be an incredible stretch

At least litigation has a clear end. The problem is more endless requests for information, each requiring research and drafting by expensive EU lawyers. A burden irrespective of whether you did anything wrong.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#44
post #36

Earlier quoted context omitted.

> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.

Allowing 28 separate, politically diverse and motivated data regulators to litigate a vague law against publicly unpopular multinationals is a recipe for capricious and arbitrary action, but I believe that was rather the intent. Litigating on this particular issue would be an incredible stretch though. Offends basic sense of fair play imo. If Turkey gets EU membership, it would be a hoot to see how Erdogan uses this…

I mean, each EU member already had the right to litigate vague data privacy laws if they wanted to.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#45

Earlier quoted context omitted.

> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.

How will they do that to a company that has no presence in that country and is actively blocking any access from that country?

> How will they do that to a company that has no presence in that country and is actively blocking any access from that country?

One of the EU's twenty-eight members will try to extradite an American executive. That will be shot down by U.S. courts. We'll throw tariffs at each other for a few months until whatever administration that happens under negotiates a compromise.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#46
post #15

So the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies…

> 2 years of legal arguments and debates happening in companies because of GDPR. That's seriously optimistic. From what I can tell, most companies realized about a week and a half ago that this was going to be an issue and freaked the hell out. I'm still getting a stready stream of better-late-than-never GDPR emails.

Large ones certainly, small ones kicked the can out of ignorance or just waiting for consensus to develop. That articles like this are so popular show how muddled the consensus still is.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#47

Earlier quoted context omitted.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

> No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol Probably not. It would make sense to roll out services on a country-by-country basis, limiting exposure to those where the national data regulator is known. EU lobbyists and lawyers were just granted a massive break.

If anything, this is good for tech jobs overall as we all have a lot more to do now.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#48

Earlier quoted context omitted.

> No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol Probably not. It would make sense to roll out services on a country-by-country basis, limiting exposure to those where the national data regulator is known. EU lobbyists and lawyers were just granted a massive break.

If anything, this is good for tech jobs overall as we all have a lot more to do now.

The vast majority of the work this creates will flow to lawyers and lobbyists.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#49

Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

That quote is incoherent. Your quote -- clause 1 from A22 -- indeed points out that profiling is permitted under circumstances enumerated at the end.

Further, the GDPR has rules around two things you mention, but they are different: (1) profiling; (2) automated decision making.

Profiling has three elements, as described by the A29 WG:

   * An automated form of processing.
   * Carried out on personal data.
   * For the objective of evaluating personal aspects about a natural person.
As for IP addresses, mapping them to an ASN is fully anonymized. Since an anonymized IP address is not personal data, using it is not profiling.

Blocking users from using your site is highly unlikely to have the "legal effects" enumerated in the above clause.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#50

Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

"Article 4 (4): ‘profiling’ means any form of automated processing of personal data"

CJEU case law has determined that IP addresses are not considered "personal data" except in certain cases (https://www.whitecase.com/publications/alert/court-confirms-...)

> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:

> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and

> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.

> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.

The vast majority of entities do not meet the requirements for #2. Therefore, automatic profiling rules could not apply since the automatic analysis being performed is not against personal data.

Post reply on HN