All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…
Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.
Shopify Is Illegal in Germany
141–150 of 349 posts
Re: Shopify Is Illegal in Germany
#142Earlier quoted context omitted.
> You're just incorrect here. I was expecting you to show where I'm incorrect. And yet, it's the same emotionally-charged "omg moat, large companies, impossible to run a business". Which doesn't disprove what I say, but further supports my case: the bullshit narrative around GDPR persists even if it has literally no basis in reality. > A small online shop using a CDN is who is actually hurt with GDPR. Most CDNs have…
Oddly this argument feels familiar - like we've sparred in the past over GDPR on another hacker news article. I won't continue this as it seems like it's more a flame war where no side can convince the other. I'll say this, though: please imagine who I am who feels so passionately about this. Likely, I am a small business that has been affected personally by the GDPR though I am not in advertising or tracking. Maybe…
It's possible. Because every GDPR discussion is this: emotionally charged "gdpr is the devil" sold to gullible devs by advertisement industry vs. attempt to disprove at least the obvious lies.
> please imagine who I am who feels so passionately about this.
The less we imagine and the more we deal with facts, the better we, and the world we build, will be.
So let's reiterate facts vs imagination in my original reply:
- "GDPR is ugly."
It's an emotionally charged subjective statement. However, GDPR is no uglyt. As far as laws surrounding complex topics go, it's absolutely definitely emphatically not ugly.
- "The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior."
This is 100% unadulterated lie.
The problem though, people keep mixing emotionally charged statements with lies and half-truths, and you get "GDPR is the devil" in the majority of HN comments.
Re: Shopify Is Illegal in Germany
#143Earlier quoted context omitted.
GDPR applies to everyone, including individuals.
Does that mean I can send people requests to delete my contact info from their phone and they're legally required to comply?
> 2. This Regulation does not apply to the processing of personal data:
> (c) by a natural person in the course of a purely personal or household activity
My sense (I am neither a lawyer nor European so this is certainly not European legal advice) is that you cannot use GDPR to compel someone to delete your contact info if they're solely a social acquaintance, but you can use it to compel them to delete it if they're a one-person business of some sort (contractor, Etsy seller, lawyer, etc.).
Re: Shopify Is Illegal in Germany
#144Earlier quoted context omitted.
Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.
Don't spread FUD please. > anyone in the EU is not even allowed to connect to any website owned by a US company This is blatantly false, of course you are allowed to connect to non-EU websites even if the IP address could be PII in some circumstances. It's the service providers problem to manage the data they collect in legal way.
Re: Shopify Is Illegal in Germany
#145Earlier quoted context omitted.
GDPR applies to everyone, including individuals.
Does that mean I can send people requests to delete my contact info from their phone and they're legally required to comply?
For instance the baby sitter you hire now and then probably keeps track of the contacts of their potential clients, and you could request deletion of your data if you don’t intend to work with them for a few years.
Re: Shopify Is Illegal in Germany
#146Earlier quoted context omitted.
To add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?
GDPR applies to individuals as well as companies if they provide services to customers within the EU/EEA[0], as long as they are either a data controller or data processor, which are explained better than I can in the source below[1]. If the business is based in the US, things get a bit more complicated due to the CLOUD Act[2]. [0]: https://ec.europa.eu/info/law/law-topic/data-protection/refo... [1]: https://ec.europ…
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
Re: Shopify Is Illegal in Germany
#147Earlier quoted context omitted.
I think it's good that the EU is forcing the US to get their privacy laws in order.
who for goodness sake needs privacy to buy some coffee online? This is just bullshit and slows down innovation. Moreover It is a big hassle just like these cookie consent banners. Nothing shows better that European leaders are powerless than this sort of nitpicking over things of little importance.
Re: Shopify Is Illegal in Germany
#148Earlier quoted context omitted.
I thought it was the storage of such data that is illegal not the connection? Obviously logs and analytics are an issue in some cases for this law, but I slightly agree with it; should we not all want our digital footprint to be as small as possible?
How long does your TCP connection need to be open for until it becomes "logs"? The law doesn't care what format that this information is stored in.
Re: Shopify Is Illegal in Germany
#149Earlier quoted context omitted.
GDPR applies to everyone, including individuals.
Does that mean I can send people requests to delete my contact info from their phone and they're legally required to comply?
Re: Shopify Is Illegal in Germany
#150Earlier quoted context omitted.
At least if you're US-based and not accepting money, I have one bit of advice: just don't care. Even if they complain, don't care. The Internet is global; if they really have an issue, they can block your site, or they can just put up with it. If you're gonna sell a product or service, then worry about figuring stuff out.
In theory you could individually be sanctioned, prevented from entering EU countries (or face the courts upon doing so), etc. Gotta cross a bunch of countries off of your vacation list. But in practice that's never going to happen.