Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

51–60 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#51
post #3

The E.U. has no legal authority or enforcement mechanism to stop foreign, online companies from not doing business in the E.U.

It's NOT about stopping them from doing business, it's about businesses taking personal data more serious.

E.g. the right to be forgotten, EU has it US doesn't. sanctions when you forget to disclose a massive data-leak on your private escort website? $0 in the US, hopefully very expensive in the EU. Your nemesis publishes lies on the net? EU helps you have that deleted. Your supermarket tracks your shopping and knows you are pregnant before you do (this happened in the UK!), won't happen anymore in the EU. Shady Sunshine Ltd bought your email address and purchase data to spam you, bad and expensive for them. facebook won't allow you to continue unless you agree to face-recognition? This might be the first case in courts.

Wait and see for the good sides once the panic has quieted down.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#53
post #38

Earlier quoted context omitted.

IP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there. Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these lo…

> IP address is PII, though. Your premise appears to be flawed in the context of established case law. IP addresses alone are not considered 'personal data' unless you have the capacity to readily add other information to add color. See below: https://www.whitecase.com/publications/alert/court-confirms-... > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. t…

Fair point. Pretty much all of my data protection work recently has been with sites that can identify the person, sorry, I let thay context affect what I said.

That said, doesn't this assume the user has a dynamic IP address? You can't easily tell a dynamic from a static, so wouldn't you have to plan for the worst?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#54
post #51
post #3

The E.U. has no legal authority or enforcement mechanism to stop foreign, online companies from not doing business in the E.U.

It's NOT about stopping them from doing business, it's about businesses taking personal data more serious. E.g. the right to be forgotten, EU has it US doesn't. sanctions when you forget to disclose a massive data-leak on your private escort website? $0 in the US, hopefully very expensive in the EU. Your nemesis publishes lies on the net? EU helps you have that deleted. Your supermarket tracks your shopping and knows…

Thats all well and good. However, if a company chooses not to do bussiness in the EU, then it does not matter what the GDPR says; even if the mechanism they use to block the EU violates the GDPR.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#55
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

As an EU citizen I agree. Also, GDPR is problematic because it confuses privacy with invisibility. I hope this problematic law is amended soon.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#56

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol.

Maybe, maybe not. It all depends on your business and your market.

We're in the UK. If we'd understood how much trouble the EU VAT rules were going to cause when they came in three years ago, we would have excluded customers from the remaining EU member states rather than adapting our systems and processes to comply -- and it would have been one of the clearest and easiest business decisions we'd ever made.

Given the amount of uncertainty and liability involved with the GDPR, it seems entirely possible that some non-EU services will take a similarly conservative approach.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#57

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

> No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies.

That's true for big companies.

The calculation changes for small companies, and really changes for hobby projects.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#58

I'm a traveler, just because I'm not coming from EU IP address range, doesn't mean I'm not EU citizen with rights established by EU.

thats in general false, you cant claim legal protections in every territory on earth and beyond.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#59
post #31
post #11

Earlier quoted context omitted.

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

Is anything in GDPR an arrestable offence?

Not paying, and getting a bench warrant for an overdue fine?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#60

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

IP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there. Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these lo…

By the way, why is IP so important to this many? The only reason I can think of is browser fingerprinting, but for that, IP is actually secondary. Why even bother storing IP apart from temporary/ephemeral security, say, fail2ban?
Post reply on HN