Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

191–195 of 195 posts

Re: Statement on 4 Years of GDPR

#191
What I do not understand about GDPR is analytics. If you are operating a website outside the US and EU citizens access that website, my understanding is that applicability of GDPR is limited to only uses where the site is capturing data from EU citizens. If the server statistics include standard analytics (e.g. client IP address, client browser, client screen size, etc), are not those analytics the capture of personal data from EU citizens? In this regard, don't EU visits to all non-EU non-GDPR-compliant websites involve a violation of GDPR simply through accumulation of server analytics? Is there an exclusion for this? Or can any website operator anywhere in the world be fined for non-compliance on this basis?

Re: Statement on 4 Years of GDPR

#192
post #166

Earlier quoted context omitted.

Is that really true? My understanding for example in the USA is that if you violate the laws in another country, you automatically violate the laws in the USA (under the Foreign Corrupt Practices Act - https://www.justice.gov/criminal-fraud/foreign-corrupt-pract... ) - or is that really just limited to bribery? AFAIK some other countries have similar provisions.

The FCPA is incredibly specific. What US law requires a US citizen to comply with EU law?

Yes thank you, a more detailed read of FCPA would indicate it is primarily restricted to bribery (or at least payments that could be interpreted as bribery). But could a non-EU website operator still be fined for non-compliance with GDPR if it were to collect personal data on EU citizens? Do website analytics constitute personal data?

Re: Statement on 4 Years of GDPR

#193

What I do not understand about GDPR is analytics. If you are operating a website outside the US and EU citizens access that website, my understanding is that applicability of GDPR is limited to only uses where the site is capturing data from EU citizens. If the server statistics include standard analytics (e.g. client IP address, client browser, client screen size, etc), are not those analytics the capture of persona…

I think the law is not well-defined because, as you mentioned, any visit to a country that doesn't provide that same data protection rules should be blocked based on the current law.

Also, I still find it weird that the EU (GDPR) laws apply at the client (visitor) rather than at the source (server). The question is: is the server providing a service in EU (sending a webpage) or is the client "going" to a server in the US?

Re: Statement on 4 Years of GDPR

#194
post #165

Earlier quoted context omitted.

Jurisdiction issues are complex. In this case, the jurisdiction is defined by the location of the customer, not the business. If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe. GDPR is framed as a h…

Jurisdiction is sometimes complex, but you don't have to be an attorney to see the disconnect in a court in say, Germany, claiming it has jurisdiction over the practices of a food blog run by someone in Kansas because someone in Berlin decided to sign up for their newsletter. I want to be clear I think they have a moral and ethical obligation to delete that person's information if so requested. There's just no (legit…

Reasonable people cannot disagree about the framing of GDPR as a human rights law. The second sentence is "This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data."

Reasonable people can disagree about the extent to which privacy is a fundamental, human right, or where the bounds are, but that is literally the phrasing of the law.

Reasonable people can argue about a lot of issues, and views on rights change with time. Ancient Greeks and not-so-ancient Afghans had sex with kids. Just over a century ago, women couldn't vote. It's hard to predict how views on human rights will evolve. Right now, there are huge cultural disconnect about a lot of things digital. It's not clear where they'll land.

Re: Statement on 4 Years of GDPR

#195
post #37
post #14

Earlier quoted context omitted.

In theory yes, but so far they haven't brought the hammer onto anyone of formidable size.

Amazon Europe Core S.à.r.l. Industry and Commerce LUXEMBOURG 746,000,000 euro Non-compliance with general data processing principles 16 Jul 2021 WhatsApp Ireland Ltd. Media, Telecoms and Broadcasting IRELAND 225,000,000 euro Insufficient fulfilment of information obligations 02 Sep 2021 https://www.enforcementtracker.com/?insights

     In 2021, Amazon EU S.à r.l. had a revenue of over 51 billion euros
Can't find numbers on profit, but companies such as amz are experts on creativity, as indicated by eg this quote:

    Amazon paid zero corporation tax in Luxembourg last year, despite seeing a record sales income of €44 billion.

    As first reported by The Guardian, accounts for Amazon EU Sarl published online showed that despite making billions of dollars in sales, the company's Luxembourg unit, which oversees retail in countries across Europe, made a €1.2 billion loss and therefore paid zero tax.

    Not only did the company not have to pay corporate tax, but it was also handed €56 million in tax credits to offset future tax bills in the event that it does turn a profit. That also comes on top of €2.7 billion in losses that have been carried forward and can be used to offset future tax bills.
Ie, not a sledge hammer.
Post reply on HN