Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

151–158 of 158 posts

Re: GDPR compliance as a service

#151

Disclaimer: This is not legal advice. Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source). If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU…

> If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence).

What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment against an American company that accidentally violated the GDPR because an EU resident lied to it?--and (b) inconsistent with the statements of Facebook et al. that they will comply with the GDPR only for those subject to it.

Re: GDPR compliance as a service

#152

Disclaimer: This is not legal advice. Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source). If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU…

> If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence). What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment agains…

Disclaimer: This is not legal advice.

Good question. An American court won’t enforce it, but any decent-sized entity is, for all practical purposes, subject to decisions by ECJ (and potentially by individual EU countries).

If an EU resident case is brought to ECJ, they’ll almost certainly have jurisdiction, so the question is what ECJ would rule. I wouldn’t bet my compliance strategy on the ECJ deciding that an EU resident opted out of GDPR by misstating their residency (intentionally or not). One can reasonably assume that ECJ would see requiring users to explicitly state their location as a mitigating factor, but not that it would eliminate the need to comply, nor the opportunity for EU litigation claiming the same.

Again, this is not legal advice, but I’ve actually read the GDPR and and been part of a large company working through how to comply with it.

Re: GDPR compliance as a service

#153

Earlier quoted context omitted.

> If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence). What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment agains…

Disclaimer: This is not legal advice. Good question. An American court won’t enforce it, but any decent-sized entity is, for all practical purposes, subject to decisions by ECJ (and potentially by individual EU countries). If an EU resident case is brought to ECJ, they’ll almost certainly have jurisdiction, so the question is what ECJ would rule. I wouldn’t bet my compliance strategy on the ECJ deciding that an EU re…

How do you expect that the ECJ or individual EU countries would enforce their ruling against our hypothetical American company without the use of the American courts? I presume that if they're blocking the EU, then they have no revenue or assets there.

And how do you reconcile this with Facebook's public statement that they won't comply for those not covered? They obviously make money doing stuff that the GDPR prohibits; but they're target #1 and they even have EU presence, much more exposed than our hypothetical.

Re: GDPR compliance as a service

#154

Earlier quoted context omitted.

Disclaimer: This is not legal advice. Good question. An American court won’t enforce it, but any decent-sized entity is, for all practical purposes, subject to decisions by ECJ (and potentially by individual EU countries). If an EU resident case is brought to ECJ, they’ll almost certainly have jurisdiction, so the question is what ECJ would rule. I wouldn’t bet my compliance strategy on the ECJ deciding that an EU re…

How do you expect that the ECJ or individual EU countries would enforce their ruling against our hypothetical American company without the use of the American courts? I presume that if they're blocking the EU, then they have no revenue or assets there. And how do you reconcile this with Facebook's public statement that they won't comply for those not covered? They obviously make money doing stuff that the GDPR prohib…

Disclaimer: This is not legal advice.

Yes, the lack of assets and revenue would make it difficult to collect. Exposure could include a staff member wanting to visit an EU country, the company trying to hire an EU-based remote contractor, or trying to get credit in the US.

That said, the reasoning is simpler: even if there's literally zero interaction with or exposure to the EU, by the time a complaint gets to litigation, the company's approach to GDPR has already failed. erely being party to a case in any court (let alone losing one) isn't a trivial matter -- it means at least consulting an attorney and thinking through the implications (like perhaps not being able to obtain an EU visa). A GDPR strategy which gets to that point, and relies on the inability to collect a judgment, has failed.

Facebook - really, FANG and a handful of other name-brand, global, consumer-facing companies - differ from most businesses in 2 ways:

1. They expect litigation, complaints, and article 17 erasure requests. There's no way to avoid it, just plan around it and minimize the impact. Their goal isn't no impact, it's no catastrophic impact.

2. They have teams of attorneys analyzing the risk and benefit of every decision. If they've decided (not) to do something, it's because they've accepted that the risks are worth the benefits, not necessarily because they think it's risk-free. Even most mid-market businesses don't have that luxury.

Note also that my original comment said that experts debate whether user-submitted location is sufficient. I explicitly didn't and don't claim that there's any certainty. There's no case law at all right now, so anyone who claims certainty about edge cases is making stuff up.

What is close to certain is that IP-based geocoding (ie, what this vendor provides) doesn't eliminate anywhere near all visitors from the EU, and thus doesn't eliminate the need to consider GDPR. Perhaps they decide to also add a user-submitted location dropdown to their signup form and accept the risks I just described, or decide to do nothing else and accept the risk of litigation from EU visitors who the geocoding doesn't identify. My core point is that the geocoding service pitches "Just block EU IPs and you're done," and that's not the case at all.

I think we're past the point where HN comments are adding value, so this will be my last comment in this thread.

Re: GDPR compliance as a service

#155

Earlier quoted context omitted.

How do you expect that the ECJ or individual EU countries would enforce their ruling against our hypothetical American company without the use of the American courts? I presume that if they're blocking the EU, then they have no revenue or assets there. And how do you reconcile this with Facebook's public statement that they won't comply for those not covered? They obviously make money doing stuff that the GDPR prohib…

Disclaimer: This is not legal advice. Yes, the lack of assets and revenue would make it difficult to collect. Exposure could include a staff member wanting to visit an EU country, the company trying to hire an EU-based remote contractor, or trying to get credit in the US. That said, the reasoning is simpler: even if there's literally zero interaction with or exposure to the EU, by the time a complaint gets to litigat…

I don't mean to endorse any strategy of blocking the EU, and I certainly don't mean to endorse the advertised service. I do think you overestimate the importance of the EU to many Americans' views and lives.

The Americans that you interact with--here or otherwise--are a disproportionately cosmopolitan sample, simply by the fact that they're talking to you. A lot of people in this country have no desire to do business in the EU. They have no desire to visit. Any regulatory action against them would reconfirm all their worst thoughts about "foreigners", and otherwise not change their lives. If they read what you wrote above, then they'd take away nothing, beyond maybe that your legal system is so terrible that no one knows what the laws are.

And really, does this kind of extraterritoriality feel like a good idea to you? Roughly two hundred countries exist. Can you imagine a world where each of them tried to enforce rules of similar complexity to the GDPR against every human alive (because remember, I might be a lying North Korean)? Would you comply with every country's rules? Or would you decide what set of countries mattered to you, and write the rest off as enemy territory? I'm pretty sure the answer is the latter. I expect that many Americans will do the same here, and that their set will not include the EU.

I agree with the high-level goals of the GDPR, and with increased privacy regulation in general. I'm disturbed to see how quickly people will take the position that "every website is subject to the laws of every country" when it serves an end goal they agree with. Do you think the UK could export its super-injunctions (court orders enforcing censorship) by the same mechanism? If not, on what legal basis?

I understand that you don't intend to comment further. I'm interested to discuss with anyone who thinks this kind of extraterritoriality is a good idea, and to understand what countries and what laws you think this should extend to.

Re: GDPR compliance as a service

#156

Disclaimer: This is not legal advice. Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source). If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU…

> If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence). What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment agains…

> What's your basis for this statement?

Lying does not necessarily waive rights. E.g. purgery does not waive 5th amendment rights. Hence "may well still". If you know this _not_ to be case here, do share.

> If it's true, then literally everyone in the world is covered by the GDPR

You mean GDPR is a massive overreach where one organization is trying to regulate effectively the entire internet? Yeah, that about sums it up.

Re: GDPR compliance as a service

#157

Earlier quoted context omitted.

At the moment there is no way the EU can enforce you to comply with that law, unless you have a subsidiary in the EU. Only if USA sign a special agreement with the EU this may change, but I don't think this will ever happen (very unlikely). Otherwise every country on planet can create their own draconian laws and expect that every single company in the world comply with it...

this is true, but kinda pointless, you are not gonna fight the EU over this... Several countries in the EU (UK, Ireland, ...) can assign personal liability for intentionally ignoring privacy law, in which case someone in your company is basically going to end up a wanted man in Europe

> Several countries in the EU (UK, Ireland, ...)

UK is not part of the EU.

> assign personal liability

Citation needed? If CEO decides to ignore privacy law, everyone else is accountable?

Re: GDPR compliance as a service

#158

Earlier quoted context omitted.

> If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence). What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment agains…

> What's your basis for this statement? Lying does not necessarily waive rights. E.g. purgery does not waive 5th amendment rights. Hence "may well still". If you know this _not_ to be case here, do share. > If it's true, then literally everyone in the world is covered by the GDPR You mean GDPR is a massive overreach where one organization is trying to regulate effectively the entire internet? Yeah, that about sums it…

In a certain sense, no one can know any law until the judge rules; but it seems there are people who believe:

1. To within some threshold of certainty, it is not yet possible to determine whether blocking EU visitors by IP, asking the remainder if they are subject to the GDPR, and blocking them if they say yes complies.

2. To within that same threshold, I can determine that some other plan (e.g., whatever troydavis is implementing) complies.

For anyone who thinks both of these can be true: Are you sure that you're basing those statements on the law? Or do you mean that the regulators will view (1) unfavorably and go after you, but they'll treat (2) as a good-faith effort and be nice?

The latter is probably true, but it's not the rule of law. Are you okay with that? How sure are you that all those regulators (and courts) will always behave in the way that you predict, or a way that you personally consider right?

I am disturbed by how willing most commenters are here to abandon the rule of law when it gets them something they want. Selective enforcement of regulations on business is a routine tactic of unfree states--remember the guy with the leopard-print fabric in Russia? I don't think it's a good idea to create powerful new tools for that, just because Europe--a continent that within living memory harbored some of the worst dictators of modern history--is well-governed right now.

Post reply on HN