Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

131–140 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#131
post #126

Earlier quoted context omitted.

The DMCA does not magically apply extra territorially. It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks. The problem with the GDPR is that it’s extraterritorial application as expected by the EU is also extr…

>The DMCA does not magically apply extra territorially. >It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. >The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks. That means essentially the same, in effect. Very few countries have copyright laws that do not alig…

I’m European, EU legislation is getting out of hand I never understood Brexit until I’ve read the IP framework proposal.

I also suggest you read my post again since you seem to have missed every point.

P.S. if you have such strong convictions why the throwaway?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#132
post #129
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

If you want to sell your wine-picker in the EU you have to adhere to the local regulations. If you want to offer your services in the EU you have to adhere to local regulations.

That’s not technically correct.

I can sell a wine picker to an EU customer without worrying about any regulation as they are the responsible entity.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#133
post #126

Earlier quoted context omitted.

>The DMCA does not magically apply extra territorially. >It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. >The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks. That means essentially the same, in effect. Very few countries have copyright laws that do not alig…

I’m European, EU legislation is getting out of hand I never understood Brexit until I’ve read the IP framework proposal. I also suggest you read my post again since you seem to have missed every point. P.S. if you have such strong convictions why the throwaway?

Maybe I did miss your point, I'm sorry. Also this is not a throwaway, I'm simply a long-time lurker.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#134
post #133

Earlier quoted context omitted.

I’m European, EU legislation is getting out of hand I never understood Brexit until I’ve read the IP framework proposal. I also suggest you read my post again since you seem to have missed every point. P.S. if you have such strong convictions why the throwaway?

Maybe I did miss your point, I'm sorry. Also this is not a throwaway, I'm simply a long-time lurker.

The point wasn’t if the laws are compatible with DMCA or not but that we had the ability to influence them.

If you as a Swedish person are blaming the US for Pirate Bay then you are wrong you have had full control over your copyright laws and enforcement and some of it is actually stricter than in the US.

I’ve also that the EU will deputize the giants not that they’ll block services to the EU resulting in even more consolidation and less freedom for EU residents.

In fact that is the expectation of many MEPs.

Combined with a government run one stop shop for data accesss like those that already exist in some EU countries the actual prospects of GDPR can be quite dystopian.

People would say that it would be better than it’s now and that companies would stop abusing your information but I have no doubt that the existing business models will not differ even in the slightest the only thing that would differ is your ability to compete and operate within a free market.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#135
post #72

Earlier quoted context omitted.

The EU is overplaying its hand by claiming global sovereignty. If the EU really wants to play hard ball, the rest of the world can impose sanctions against the EU and bureaucrats who try to enforce illegal laws

Nobody is claiming global anything, the rest of the world is not the US, and illegal law is an oximoron.

The supreme court and the constitution would beg to differ.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#136
post #108

Earlier quoted context omitted.

That's not what I meant, I'm curious why people want to store IPs apart from the security applications, which usually only need it temporarily.

You need IP addresses for forensic investigation. As the statute of limitations for most forms of fraud is 10 years or more, shouldn’t everyone be storing logs with full IPs and source ports for at least that long?

No, it wouldn't make any sense, and an IP address is a very bad measurement as well. Think of airports, public hotspots, etc - even if you do keep the data, nothing else will be kept that log (or at lease I believe at this point in time), so what would storing the IP get you? An approximate location of a now potentially already recycled device and nothing else, really.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#137
post #136

Earlier quoted context omitted.

You need IP addresses for forensic investigation. As the statute of limitations for most forms of fraud is 10 years or more, shouldn’t everyone be storing logs with full IPs and source ports for at least that long?

No, it wouldn't make any sense, and an IP address is a very bad measurement as well. Think of airports, public hotspots, etc - even if you do keep the data, nothing else will be kept that log (or at lease I believe at this point in time), so what would storing the IP get you? An approximate location of a now potentially already recycled device and nothing else, really.

If you have a log time stamp, IP and source port of a compromise, you at least have a chance at attribution by working with the source network operator who can potentially correlate to a MAC or subscriber. The police can even pull video of a coffee shop to see who was there during an attack.

Without the time stamp and IP information you have zero chance at attribution during a security event.

PCI and a bunch of other regs require log retention for 1 year or even more for this reason.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#138
post #129

Earlier quoted context omitted.

If you want to sell your wine-picker in the EU you have to adhere to the local regulations. If you want to offer your services in the EU you have to adhere to local regulations.

That’s not technically correct. I can sell a wine picker to an EU customer without worrying about any regulation as they are the responsible entity.

I think you misunderstood me. Local = EU. This was written from the perspective of a non-EU company (but obviously equally applies to EU companies).

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#140

ignore the gettingmaildelivered blog... one certainly can take active measures to exclude EU visitors as a way of avoiding scope of GDPR. Get real legal advice if curious rather than relying on a blog.

rest assured you would not see major newspapers doing exactly that without them having checked the legality. The analysis in the blog is wrong because the first question to be asked is "is the business within the scope of the GDPR", and _if you are a business in scope_, then you can't process personal data or track/monitor EU residents. However, you are not a business in scope of GDPR if you don't have a business presence in the EU and don't hold out your services to EU residents. Blocking that region demonstrates clear intent _not_ to offer services to EU residents and thus puts your business out of GDPR scope.
Post reply on HN