Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

71–80 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#71
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

As an EU citizen I agree. Also, GDPR is problematic because it confuses privacy with invisibility. I hope this problematic law is amended soon.

I'm sorry, but what part of the GDPR do you think demands invisibility? It doesn't even mention privacy because the GDPR stands of General Data PROTECTION Regulation.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#72

You can’t force people to operate in your country. The EU does not have sovereignty over the whole world. This is nonsense and is certainly not what is contemplated by the law. Making it undesirable for some businesses to operate in your country is part of the cost-benefit analysis you have to do when passing laws.

The EU is overplaying its hand by claiming global sovereignty. If the EU really wants to play hard ball, the rest of the world can impose sanctions against the EU and bureaucrats who try to enforce illegal laws

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#73
post #71

Earlier quoted context omitted.

As an EU citizen I agree. Also, GDPR is problematic because it confuses privacy with invisibility. I hope this problematic law is amended soon.

I'm sorry, but what part of the GDPR do you think demands invisibility? It doesn't even mention privacy because the GDPR stands of General Data PROTECTION Regulation.

the part where you are not allowed to profile the user based on a piece of information for which it is impossible to obtain consent (IP address).

The law does not mention privacy, correct, but its entire rationale is based on the idea of privacy rights.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#74

I have ~600 small business customers from the EU who are using my SaaS product and until now I received zero requests regarding GDPR. It seems it was the right decision to ignore this law, because no one cares about it. The same thing was with the cookie banner. Never built it into the product and in 6 years not even a single person asked about it...

if you 're likely to receive requests, you re most likely to receive them now that gdpr is in the news.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#75

I have ~600 small business customers from the EU who are using my SaaS product and until now I received zero requests regarding GDPR. It seems it was the right decision to ignore this law, because no one cares about it. The same thing was with the cookie banner. Never built it into the product and in 6 years not even a single person asked about it...

Simple advise: If ever anyone asks: Be active and responsive.

But remember: The GDPR protects people's data. Companies aren't people (at least in the EU).

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#76

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

>No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol.

Considering how many US-only startups I see on HN every day, this is patently false.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#77
post #38

Earlier quoted context omitted.

> IP address is PII, though. Your premise appears to be flawed in the context of established case law. IP addresses alone are not considered 'personal data' unless you have the capacity to readily add other information to add color. See below: https://www.whitecase.com/publications/alert/court-confirms-... > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. t…

Fair point. Pretty much all of my data protection work recently has been with sites that can identify the person, sorry, I let thay context affect what I said. That said, doesn't this assume the user has a dynamic IP address? You can't easily tell a dynamic from a static, so wouldn't you have to plan for the worst?

Maybe, but firewalling an IP range doesn't actually require logging the specific ips. I don't think gdpr has any teeth for information that isn't actually stored.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#78
post #60

Earlier quoted context omitted.

IP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there. Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these lo…

By the way, why is IP so important to this many? The only reason I can think of is browser fingerprinting, but for that, IP is actually secondary. Why even bother storing IP apart from temporary/ephemeral security, say, fail2ban?

Not just IPs, The regulation knows about all of them (including RFID):

Preamble paragraph 30: > Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#79
post #67
post #11

Earlier quoted context omitted.

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

Arrest for EU bureaucrats for when they go outside the EU for trying to enforce unlawful laws?

It's not the EU but the member states that are enforcing the regulation. They are also free to make minor changes to the regulation (e.g. Austria won't allow NGOs to make complaints and releases state-run companies from the regulation's duties).

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#80
There is a lot of discussion about GDPR from an American perspective. I'm curious about the Chinese one. Does the EU really expect Baidu, WeChat and Tencent to comply with these rules? Or is this just a roundabout way of extracting bureaucratic benefits from American technology companies?
Post reply on HN