Live data from Hacker News

It's been three years. Stop saying your European visitors are important to you

news.ycombinator.com

171–180 of 192 posts

Re: It's been three years. Stop saying your European visitors are important to you

#171
post #117

Earlier quoted context omitted.

Which is like saying “this building doesn’t follow engineering best practices, it may fall on your head at any moment” and expect to get away with that.

Isn't it more like a website in one country rightly stating it's not bound by the laws in another country?

You asked:

> IANAL, but can't they just word a disclaimer and checkbox?

The answer is no, as far as GDPR is concerned, if they want to process and/or sell data of EU citizens or residents they have to follow some rules. I’ve no idea how the EU plans to enforce this regulation outside of the EEA, but it’s beside the point (as in it’s not what you asked)

Re: It's been three years. Stop saying your European visitors are important to you

#172

Earlier quoted context omitted.

Europeans would rather have the GDPR than be able to read American news sites. American news sites would rather block European readers than comply with the GDPR. Everything is working as intended, no?

No. The GDPR requires sites not to discriminate. It is a violation to refuse to serve users because they are in Europe.

Laws in Europe apply to European subjects only, not the entire world. Europe has no authority to force a non-European company to serve it's subjects.

Re: It's been three years. Stop saying your European visitors are important to you

#173

Earlier quoted context omitted.

Several times I've said that HN should block European IP addresses. Nothing they have to say is relevant in the US. And pay your own damn defense budgets.

I'm a U.S. citizen and veteran working for a company with many customers the U.S. and friends working in every reach of the country. I didn't realize I'm not part of the tech scene because of my location. Alas, I have paid and do still pay my country's defense budget---financially, physically, emotionally.

You broke the site guidelines with this. They ask:

"Don't feed egregious comments by replying; flag them instead."

a.k.a. please don't feed the trolls

https://news.ycombinator.com/newsguidelines.html

If you wouldn't mind reviewing and sticking to the rules when posting here, we'd be grateful.

Re: It's been three years. Stop saying your European visitors are important to you

#174
post #161

Earlier quoted context omitted.

I simply thought jurisdiction would be relevant here. The EU can make whatever rules it wants to cover its own citizens, and beyond that - they can't enforce them.

Apologies by the way, re-reading my post it comes across overly dismissive. I didn't intend it that way.

Thank you. This made my day. I didn't feel put-out (well, no more than I'm used to!), but it's refreshing and affirming to see empathy and self-accountability here on HN.

I will try to do better myself. I'm sure I am sometimes guilty of same.

Re: It's been three years. Stop saying your European visitors are important to you

#175
post #171

Earlier quoted context omitted.

Isn't it more like a website in one country rightly stating it's not bound by the laws in another country?

You asked: > IANAL, but can't they just word a disclaimer and checkbox? The answer is no, as far as GDPR is concerned, if they want to process and/or sell data of EU citizens or residents they have to follow some rules. I’ve no idea how the EU plans to enforce this regulation outside of the EEA, but it’s beside the point (as in it’s not what you asked)

Would this mean all a non-EU website needs to do to safely serve GDPR-bound persons is trash any data collected from them?

Re: It's been three years. Stop saying your European visitors are important to you

#176

Earlier quoted context omitted.

Any company that serves EU residents has to comply. If they block users from the EU, they don't have to comply. Fines can be massive (up to 2% global revenue). Nexstar might not have any European assets, but non-compliance might not be a smart move if they get fined and business executives travel to Europe...

A company in the US has no legal obligation to pay fines in the EU. There is no ability to enforce these rules on US companies. Also, individuals traveling to the EU will never be liable for the fines of their company. Our company just completely ignores GDPR - and I suspect no one will ever care.

It sounds like you do some tracking, but don't do business in Europe. Okay, fine.

Do you do only your own tracking? Or do you directly or indirectly sell Europeans' personal data to other companies, who in turn may be doing business in Europe?

You can probably see where I'm going with this: those other companies may then potentially be liable in Europe for improperly handling Europeans' personal data. If I was buying personal data from US company as a European, I would make it part of the contract that the seller must comply with GDPR at least for Europeans, to avoid this potential liability.

Re: It's been three years. Stop saying your European visitors are important to you

#178

Earlier quoted context omitted.

A company in the US has no legal obligation to pay fines in the EU. There is no ability to enforce these rules on US companies. Also, individuals traveling to the EU will never be liable for the fines of their company. Our company just completely ignores GDPR - and I suspect no one will ever care.

It sounds like you do some tracking, but don't do business in Europe. Okay, fine. Do you do only your own tracking? Or do you directly or indirectly sell Europeans' personal data to other companies, who in turn may be doing business in Europe? You can probably see where I'm going with this: those other companies may then potentially be liable in Europe for improperly handling Europeans' personal data. If I was buying…

You are speaking very speculatively about facts that cannot ever be demonstrated to any EU court. ...so the point from our perspective is moot. There is no legal risk, because there is no method of detection of a violation, and no method of enforcement.

Re: It's been three years. Stop saying your European visitors are important to you

#179
post #173

Earlier quoted context omitted.

I'm a U.S. citizen and veteran working for a company with many customers the U.S. and friends working in every reach of the country. I didn't realize I'm not part of the tech scene because of my location. Alas, I have paid and do still pay my country's defense budget---financially, physically, emotionally.

You broke the site guidelines with this. They ask: " Don't feed egregious comments by replying; flag them instead. " a.k.a. please don't feed the trolls https://news.ycombinator.com/newsguidelines.html If you wouldn't mind reviewing and sticking to the rules when posting here, we'd be grateful.

Understood. Thanks. :)

Re: It's been three years. Stop saying your European visitors are important to you

#180

Earlier quoted context omitted.

Exactly this. Every time I read about GDPR compliance, it feels like a very well-designed set of guidelines that are easy to follow ... IF you aren't stalking users. The complaints about it have the same tone as the Guild of Assassins complaining that laws against murder are really hard to comply with in their industry. Of course they are, and that's the point. -------------- Hypothetical conversation with a Maliciou…

>Every time I read about GDPR compliance, it feels like a very well-designed set of guidelines that are easy to follow ... IF you aren't stalking users. There's a difference between being compliant and being _in compliance_. There's a real cost to the latter. Why should sites that primarily serve non-European readers bother with it? The assumption that they don't because they're all greedily stalking users is a misgu…

I'm not sure what the distinction is between the two. Is one of those having a verified system to ensure that you are compliant, while the other is merely being compliant but unprovably so?
Post reply on HN