Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

61–70 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#61
post #7

Earlier quoted context omitted.

Extradition?

Extradition treaties usually limit extradition to things that are punishable in both countries.

But not being able to step foot on European soil due to an outstanding bench warrant is at least severely inconvenient.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#62

I'm a traveler, just because I'm not coming from EU IP address range, doesn't mean I'm not EU citizen with rights established by EU.

The GDPR's scope is based on geography, not citizenship. If you're an EU citizen currently in the US, you do not necessarily enjoy whatever rights and protections the GDPR might offer you if you were within the EU. If you're a US citizen currently in the EU, you do enjoy those protections.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#63

What happens when an EU citizen travels to the US and accesses a website?

U.S. law applies, just like normal, unless the website is located in the EU. The EU claiming jurisdiction over transactions entirely in another country would be a major breach of sovereignty, which is why the law uses the phrase "data subjects in the Union".

Note that EU law does apply for visitors, so look forward to data tourism!

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#64
I have ~600 small business customers from the EU who are using my SaaS product and until now I received zero requests regarding GDPR. It seems it was the right decision to ignore this law, because no one cares about it. The same thing was with the cookie banner. Never built it into the product and in 6 years not even a single person asked about it...

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#65
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

Imagine your country claiming taxes from you even though you are an ex-patriate and not living in that country. Oh, that does happen.

You can't just build a firewall for data, especially as users will actually willingly export data. You look at the GDPR from a business side only and miss that it is about personal data and how that data has become a commodity that is being traded, mishandled and often abused.

So far none of the US-based services that I use has shut down or blocked me just because I'm under the protection of the GDPR. Those websites we see blocking users have either no interest in the European market (fair enough) or are indeed using shady practices.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#66
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

There is no enforcement because if GDPR claims that it has jurisdiction over entities not having physical presence in the EU, then the law isn't lawful to begin with.

And if the EU started going after companies/individuals who don't have presence in the EU because they claim "we say so", well, then the rest of the world can play that game to.

Maybe the rest of the world will put sanctions on EU bureaucrats if EU bureaucrats start trying to shake down companies that have no presence in the EU.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#67
post #11
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

Arrest for EU bureaucrats for when they go outside the EU for trying to enforce unlawful laws?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#68
post #50

Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

"Article 4 (4): ‘profiling’ means any form of automated processing of personal data " CJEU case law has determined that IP addresses are not considered "personal data" except in certain cases ( https://www.whitecase.com/publications/alert/court-confirms-... ) > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. there is another party (such as an ISP) that can…

I hope that IPs will stop being considered PII for the same reason. It's much easier to anonymize them at the ISP level rather than doing all these acrobatics.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#69
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Extradition?

Yes, extradition for EU officials who try to enforce illegal lawss against the citizens of sovereign nations.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#70
post #65
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

Imagine your country claiming taxes from you even though you are an ex-patriate and not living in that country. Oh, that does happen. You can't just build a firewall for data, especially as users will actually willingly export data. You look at the GDPR from a business side only and miss that it is about personal data and how that data has become a commodity that is being traded, mishandled and often abused. So far n…

> Oh, that does happen.

That's based on international law, while there is no such thing about privacy

Post reply on HN