Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

111–120 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#111
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

>After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves.

That sort of thing happens all the time - except the US is usually the one coercing foreign entities. Remember the DMCA? ThePirateBay's raid in 2006? Or the Megaupload debacle? Or how Japan was pressured by the US to adopt stricter child pornography laws?

Note, I'm not saying the people behind these were supporting moral and noble causes that the US was wrong to clamp down on. I'm certainly not saying people should comply to China's expectations on free speech and flow of information. Simply, if you feel infuriated that a foreign power is enforcing its worldview and related regulations onto you, an American citizen, know that that's what literally everyone else has been experiencing for the last decades from the people you've put in power.

But then, what the EU is trying to enforce here - more power to Internet users, essentially - is fairly benign when compared to what other foreign powers would like to enforce. If there were matters of infuriation to be had on that account, I'd start with the Mariott debacle [1].

[1] https://boingboing.net/2018/01/15/willfull-liking.html

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#112

There is a lot of discussion about GDPR from an American perspective. I'm curious about the Chinese one. Does the EU really expect Baidu, WeChat and Tencent to comply with these rules? Or is this just a roundabout way of extracting bureaucratic benefits from American technology companies?

Yes, of course. If they do business in the eu, they will need to comply. If they don’t do business in EU, then they dont have to follow eu rules.

Ha! Good luck getting a single euro out of China! We've already seen the EU roll over when Russia's energy giant Gazprom applied a little pressure.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#113
post #95

Earlier quoted context omitted.

That's not how most regulations work. If you are a chemical company selling something that is legal in the US but illegal in the EU, the EU doesn't use your bank to enforce their regulations on your business in the US. Using the banks to cut off commerce across borders is an enforcement action for what countries agree are crimes - terrorism, money laundering, fraud, etc. It takes a lot of political willpower and nego…

The US used this against Rossmann GmbH, which was a German company, in Germany, selling cuban cigars to a German. And they got cut off from PayPal, and the credit card networks for quite a while. If the US can use it for selling a product in a store that’s entirely legal to sell under EU law, then the EU can also use the same rules for GDPR.

That's a perfect illustration of my point. The US went to pretty great lengths to have specific bans on import / export from Cuba. German train companies build plenty of things that would not meet FRA standards in the US, the US does nothing about it. But Cuba is seen as a special case. So do you think GDPR and PII are more like Cuba and terrorism, or more like chemicals and transportation standards? I think the latter.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#114
post #95

Earlier quoted context omitted.

The US used this against Rossmann GmbH, which was a German company, in Germany, selling cuban cigars to a German. And they got cut off from PayPal, and the credit card networks for quite a while. If the US can use it for selling a product in a store that’s entirely legal to sell under EU law, then the EU can also use the same rules for GDPR.

That's a perfect illustration of my point. The US went to pretty great lengths to have specific bans on import / export from Cuba. German train companies build plenty of things that would not meet FRA standards in the US, the US does nothing about it. But Cuba is seen as a special case. So do you think GDPR and PII are more like Cuba and terrorism, or more like chemicals and transportation standards? I think the latt…

Definitely the former: the way Europeans are talking about GDPR, insufficient respect for privacy is a human rights violation. We don't sanction Cuba because it makes trains the wrong way, we sanction it because we feel it violates its citizens' human rights.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#115
post #82

Earlier quoted context omitted.

the part where you are not allowed to profile the user based on a piece of information for which it is impossible to obtain consent (IP address). The law does not mention privacy, correct, but its entire rationale is based on the idea of privacy rights.

The IP itself isn't much use in the context of personal identifiable information with more data say from the person's internet provider. Also, having http logs with IP addresses (stored for a reasonable short amount of time) is still allowed as it is a necessity to provide any service at all. The regulation isn't about fucking IP addresses, it's about big data collection information about, what you buy, where you go,…

> it's about big data collection information

This can be achieved with more sane, pragmatic regulation.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#116

Earlier quoted context omitted.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

FWIW the first serious startup I worked at chose not to do CE compliance (the EU governing body for electronic devices that may interfere with RF). Thus we did not sell our product to Europe. Every single blog post had a set of people raging that we were assholes for doing this, but the reality was the cost of compliance just didn't make sense for the MVP. It was high 5 figures in cost which was just too much at the…

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#117
post #72

Earlier quoted context omitted.

The EU is overplaying its hand by claiming global sovereignty. If the EU really wants to play hard ball, the rest of the world can impose sanctions against the EU and bureaucrats who try to enforce illegal laws

Nobody is claiming global anything, the rest of the world is not the US, and illegal law is an oximoron.

and illegal law is an oximoron.

Wrong. Just because a few guys vote on something and then write it down on a piece of paper doesn't make it lawful.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#118
post #111
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

>After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves. That sort of thing happens all the time - except the US is usually the one coercing foreign entities. Remember the DMCA? ThePirateBay's raid in 2006? Or the Megaupload debacle? Or how…

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#120

There is a lot of discussion about GDPR from an American perspective. I'm curious about the Chinese one. Does the EU really expect Baidu, WeChat and Tencent to comply with these rules? Or is this just a roundabout way of extracting bureaucratic benefits from American technology companies?

Yes, of course. If they do business in the eu, they will need to comply. If they don’t do business in EU, then they dont have to follow eu rules.

Why are most companies (i.e. USAToday complying) when they have no market, interest, or presence in the EU?
Post reply on HN