Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

121–130 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#121

Someone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

> the law does not allow automatic profiling of the user (Article 22)

GEO-IP is not a profile unless it is stored with additional data.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#122

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

Lets say your a hot upcoming startup and you dont have the funds to pay GDRP lawyers. In the early stages, blocking EU customers entirely may be tempting...

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#123
post #111
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

>After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves. That sort of thing happens all the time - except the US is usually the one coercing foreign entities. Remember the DMCA? ThePirateBay's raid in 2006? Or the Megaupload debacle? Or how…

The DMCA does not magically apply extra territorially.

It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules.

The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks.

The problem with the GDPR is that it’s extraterritorial application as expected by the EU is also extrajudiciary.

I would have no problem with the EU seeking ways to expand GDPR through new legal frameworks which the people that would be impacted by these changes can actually control through their own political system.

What I have a problem with is the EU essentially forcing compliance through extortion and sooner rather than later it will employ the companies that the GDPR was in spirit intended to protect us from to enforce it.

I don’t see the EU being able to enforce the GDPR even internally without essentially deputizing the likes of Google, Amazon and PayPal to enforce it across all of their customers in order for them themselves to be compliant.

Even with the fines possible under the GDPR the EU can not enforce compliance by targeting 100,000’s of small companies without going essentially bankrupt. It can however effectively target the big ones and worse make it impossible to operate within the EU without using their “GDPR complaint” platforms.

The GDPR might be a great thing on paper and even in spirit but the uncertainty and the inability to enforce complex regulation on a mass of small entities would likely cause it’s real world repercussions to be quite different than from what was imagined or intended.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#125
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

Imagine if China decided that Chinese citizens accessing foreign servers was a breach of national security due to the ability of these foreign servers to collect private browsing information, and imagine if China decided to make laws that fined these foreign entities in violation of their laws.

I agree with you. Fortunately, at least in the case of GDPR, we don't have to worry about it, as this article is completely off base legally. While I'm sure there are many in the EU that would love for it to be illegal for foreign entities to block EU residents, here's the reality of this. Under Recital 23 [1], you are not subject to the GDPR if you are outside of the EU and it cannot be established that you "envisage" servicing EU customers. This Recital explicitly states that the mere accessibility of a foreign website from within the EU does not by itself subject the site to the GDPR. In other words, none of the GDPR applies to foreign websites that are blocking EU residents, because they have shown that they don't intend to serve EU residents. Since the law doesn't apply, its restrictions on automated profiling don't apply either (and you can legally store their IP address and any other information gleaned from HTTP requests for eternity and not bother responding to their "nightmare letters").

I find articles written in bad faith like this odd on a number of levels. Do people in the EU really want to falsely make sites in other parts of the world believe that they must comply with this absurd legislation? It's almost like they are trying to say "HA! We have power over you and can force you to do whatever we want!". It seems like a weird and desperate power struggle.

Block the EU, and GDPR doesn't apply (as long as you don't already hold EU resident data). It's as simple as that.

[1] http://www.privacy-regulation.eu/en/recital-23-GDPR.htm

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#126
post #111

Earlier quoted context omitted.

>After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves. That sort of thing happens all the time - except the US is usually the one coercing foreign entities. Remember the DMCA? ThePirateBay's raid in 2006? Or the Megaupload debacle? Or how…

The DMCA does not magically apply extra territorially. It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks. The problem with the GDPR is that it’s extraterritorial application as expected by the EU is also extr…

>The DMCA does not magically apply extra territorially.

>It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. >The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks.

That means essentially the same, in effect. Very few countries have copyright laws that do not align with interests of US lobbies. If any country with significant partnerships with the US decided to tell "screw the MPAA, you can now download anything from the Internet" to its citizens, the said lobbies would pressure the US government to pressure that country through the trade agreements you mentioned, until it relented. This is something that actually happened, during e.g. the TPB raid. We can argue about the moral legitimacy of such things but the reality of the matter is, it's all power plays.

>What I have a problem with is the EU essentially forcing compliance through extortion and sooner rather than later it will employ the companies that the GDPR was in spirit intended to protect us from to enforce it.

>I don’t see the EU being able to enforce the GDPR even internally without essentially deputizing the likes of Google, Amazon and PayPal to enforce it across all of their customers in order for them themselves to be compliant.

>Even with the fines possible under the GDPR the EU can not enforce compliance by targeting 100,000’s of small companies without going essentially bankrupt. It can however effectively target the big ones and worse make it impossible to operate within the EU without using their “GDPR complaint” platforms.

Three objections:

-The use of 'extortion' is rather harsh - the EU isn't out there to suck money out of the poor American startups, they simply want them to treat user data in a sensible manner. Now you may object to what is considered 'sensible' just like someone in Sweden (e.g. anakata) may object to what is considered a 'copyright breach' but the point here is that they are not looking to make money from fines. If you are found to be noncompliant you wouldn't get sued by troll lawyers, you'd get a couple warnings along with guidance on how to be compliant again. Fines are simply there to say they mean business so people stop ignoring the regulations like they've done with existing country-specific ones for the last decades. Again, power play.

-I really doubt Google, Amazon and Paypal would cut off the entire EU market just to avoid going through the hassle of setting up an updated privacy policy. The EU population is 500 million, way more than the US. More likely, they'll do a cost-benefit analysis that will tell them it's worth paying their lawyers to do the compliance work. It's not actually a big deal. Also, these tech giants do have offices in the EU, usually in Ireland, so it hardly counts as extraterritorial extortion.

-As for the poor hundreds of thousands of companies - well, see the above. They don't want your money, they want compliance. A fine is the absolute worst case if you are repeatedly and outrageously negligent on a very large scale. The most likely case, however, is that the GDPR isn't going to care about these startups because the European public doesn't care about them either. I don't mean to be harsh or condescending, but while lurking HNs and reading headlines about such and such service shutting its doors to European user, I couldn't recognize any of the names. No one is going to sue your ten-man startup that develops a niche/superficial app whose use cases only fit twice that many people to a EU court. It is far more likely that it will fail by itself, because that's what startups do. Should it grow, however, and be in a position to deal with enough customers data that negligence or nefarious intent when handling it would cause significant harm - that's where actual GDPR enforcement would step in.

You may say: 'but there is no guarantee', 'it's all very vague', 'this much vagueness only opens the way to corruption and preferential treatment', but that's mostly how most of the law is written here in the EU - clarity of intent and concision over clarity of wording and exhaustiveness. Against all odds I'd say it's working out pretty well for us and the vast majority of people here do not feel any defiance toward their institutions (at least when compared to other countries), so I feel confident in the GDPR's enforcement, jurisprudence cases and their future effects on the handling of my data. You may feel slighted that a foreign entity, its views and its legal culture are being imposed on you, though, and I understand. Again, power play.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#127
post #108
post #78

Earlier quoted context omitted.

Not just IPs, The regulation knows about all of them (including RFID): Preamble paragraph 30: > Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers a…

That's not what I meant, I'm curious why people want to store IPs apart from the security applications, which usually only need it temporarily.

You need IP addresses for forensic investigation. As the statute of limitations for most forms of fraud is 10 years or more, shouldn’t everyone be storing logs with full IPs and source ports for at least that long?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#128
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves.

I might be reading this wrong but you are saying that as a privacy valuing individual GDPR your issue is that because it is a single entity - EU has come up with the law. And the solution is not that every country in the world should pass privacy laws rather European countries should build a China-like firewall?

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#129
post #41

As somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of do…

If you want to sell your wine-picker in the EU you have to adhere to the local regulations. If you want to offer your services in the EU you have to adhere to local regulations.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#130
This is a clear mis-reading of the law. Look at the examples that you can't use profiling (including geo-IP) for:

> which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention.

Blocking someone from reading a news website is clearly not a decision along these lines. Obviously this would need to be tested in court, but I would bet on it being allowed.

Also, the GDPR only applies at all if the business operates in the EU. If they clearly don't (e.g. by blocking European visitors) then the GDPR does not apply and you obviously can't use text in the GDPR itself to prove that you can't do that.

This article is nonsense.

Post reply on HN