Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

101–110 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#101

I'm a traveler, just because I'm not coming from EU IP address range, doesn't mean I'm not EU citizen with rights established by EU.

The GDPR's scope is based on geography, not citizenship. If you're an EU citizen currently in the US, you do not necessarily enjoy whatever rights and protections the GDPR might offer you if you were within the EU. If you're a US citizen currently in the EU, you do enjoy those protections.

Hmm, that's interesting, I was convinced it's based on citizenship.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#103

I have ~600 small business customers from the EU who are using my SaaS product and until now I received zero requests regarding GDPR. It seems it was the right decision to ignore this law, because no one cares about it. The same thing was with the cookie banner. Never built it into the product and in 6 years not even a single person asked about it...

The GDPR has been in effect for less than three days, two of which have been weekend. A bit premature to say, "nobody's enforcing this law", isn't it?

The cookie banner is different because everyone knew it was completely meaningless. Whether GDPR is or not remains to be seen; it's certainly not an "everybody knows" situation yet.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#104
post #95

Earlier quoted context omitted.

That's not how most regulations work. If you are a chemical company selling something that is legal in the US but illegal in the EU, the EU doesn't use your bank to enforce their regulations on your business in the US. Using the banks to cut off commerce across borders is an enforcement action for what countries agree are crimes - terrorism, money laundering, fraud, etc. It takes a lot of political willpower and nego…

The US used this against Rossmann GmbH, which was a German company, in Germany, selling cuban cigars to a German. And they got cut off from PayPal, and the credit card networks for quite a while. If the US can use it for selling a product in a store that’s entirely legal to sell under EU law, then the EU can also use the same rules for GDPR.

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#105
post #23
post #11

Earlier quoted context omitted.

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

I find it pretty problematic that the US does that to gambling site operators. People who do things that are legal where they live should not have to fear that they'll get arrested when they visit a foreign country just because those things are not legal in that country.

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#106

There is a lot of discussion about GDPR from an American perspective. I'm curious about the Chinese one. Does the EU really expect Baidu, WeChat and Tencent to comply with these rules? Or is this just a roundabout way of extracting bureaucratic benefits from American technology companies?

Yes, of course. If they do business in the eu, they will need to comply. If they don’t do business in EU, then they dont have to follow eu rules.

If Facebook certifies deletion of certain data, and somebody doesn't believe them, they can sue in an American court. If WeChat certifies deletion of certain data, and somebody doesn't believe them, they're SOL.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#107

This is a ridiculous interpretation of the law. Brought to you by some «experts» in Colorado. If you had followed EU policy discussions over the last 10 years, you would realize this is about creating a single, unified online market. Meaning a citizen living in Poland should have access to the same online services as a German, unless there are valid reasons for denying him.

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#108
post #78
post #60

Earlier quoted context omitted.

By the way, why is IP so important to this many? The only reason I can think of is browser fingerprinting, but for that, IP is actually secondary. Why even bother storing IP apart from temporary/ephemeral security, say, fail2ban?

Not just IPs, The regulation knows about all of them (including RFID): Preamble paragraph 30: > Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers a…

That's not what I meant, I'm curious why people want to store IPs apart from the security applications, which usually only need it temporarily.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#109

Earlier quoted context omitted.

The GDPR's scope is based on geography, not citizenship. If you're an EU citizen currently in the US, you do not necessarily enjoy whatever rights and protections the GDPR might offer you if you were within the EU. If you're a US citizen currently in the EU, you do enjoy those protections.

Hmm, that's interesting, I was convinced it's based on citizenship.

It's a common misconception, and has been widely reported even in the mainstream media. FYI it's Article 3 of the GDPR that specifies the territorial scope authoritatively.

Fun fact: The word "citizen" doesn't actually appear in the GDPR at all.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#110

Earlier quoted context omitted.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

> No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. That's true for big companies. The calculation changes for small companies, and really changes for hobby projects.

Exactly this. The big companies can afford to pay people to deal with the issue.

For small companies one mistake and they could be out of business. So its easier to avoid the problem to begin with.

Post reply on HN