Live data from Hacker News

It's been three years. Stop saying your European visitors are important to you

news.ycombinator.com

151–160 of 192 posts

Re: It's been three years. Stop saying your European visitors are important to you

#151
post #115

Maybe the cost of GDPR compliance just isn't worth the small amount of revenue that they might make from European visitors? US visitors are probably much more 'valuable' in terms of advertisement revenue, and also much more likely to be a subscriber. And I say this as a European myself. It sucks that I have to jump through hoops to access some sites but I can't really blame them.

Having worked on and lead 3 GDPR compliance projects, I can say that the cost of GDPR compliance is close to zero if your business is not tracking users or selling their data without consent. This assuming you are following best practises for storing users’ data (ie encryption, limited access to authorised personnel, etc…). If you store data without encryption, allow randos to access users’ personal data, you shouldn…

Don't know why you got downvoted.

As a former GDPR compliance officer for a company managing about 40 customer websites, I can confirm that GDPR compliance is not burdensome or costly, unless you are intent on violating the GDPR. You appoint someone on your tech staff as compliance officer, and as an organisation you make sure that complaints are handled.

Handling complaints is something any business should be able to do, GDPR or not; a business that can't handle complaints isn't a viable business.

Re: It's been three years. Stop saying your European visitors are important to you

#152

Maybe the cost of GDPR compliance just isn't worth the small amount of revenue that they might make from European visitors? US visitors are probably much more 'valuable' in terms of advertisement revenue, and also much more likely to be a subscriber. And I say this as a European myself. It sucks that I have to jump through hoops to access some sites but I can't really blame them.

IANAL, but can't they just word a disclaimer and checkbox? Something like: "Our European visitors are important to us... but the cost of GDPR-compliance for a US-focused site is high. For your own GDPR protection, we advise you not to access our site. However, if you choose to do so, you agree to waive any and all rights granted to you under the GDPR. [ ] Agree"

> IANAL

Maybe you are not a lawyer; but perhaps you should actually read the GDPR before suggesting that it's possible to waive all one's rights under the GDPR.

Re: It's been three years. Stop saying your European visitors are important to you

#153

I’m the opposite: I grew up in Europe but live in the States. There’s a ton of European websites and content I can’t access from here. While this may suck for you personally I don’t think American companies (especially local news companies) should have to comply with invasive and expensive European privacy laws. Especially after forcing the entire world to adopt useless and annoying cookie walls. If you really want t…

Nobody asked for cookie walls, which anyway don't bring sites into compliance. The cookie walls are erected by companies that are trying to shirk GDPR responsibilities.

They can avoid these responsibilities by refusing to serve content in the EU. That's their prerogative (although it is discriminatory, and thefore violates GDPR). And if they think they are out-of-reach for EU law, they can just ignore the GDPR; but watch out, similar regulations are coming to a jurisdiction near you.

Whether the GDPR is "reasonable" depends on your perspective; regulated parties always think that the regulations under which they trade are unreasonable.

[Edit: qualified the "their prerogative" bit]

Re: It's been three years. Stop saying your European visitors are important to you

#154

“We care about your privacy.” is also a real joker. Those boxes often provide no “opt-out all” button and force you to “object” to “legitimate interests” one-by-one even if you do “opt-out”.

Why do companies even bother writing that? They clearly don't care, if they did that box wouldn't even be there. Sites like Imgur are the absolute worst. "We care about your privacy" and presents you with a list of 1200 companies they share information with.

Maybe more in a sense like "I care about your well being, as I'll exploit you and if you die then I can't exploit you anymore." kind of way.

It's not even lying.

Re: It's been three years. Stop saying your European visitors are important to you

#155

What I don't understand is, why are these local US news sites required to comply with GDPR? I wouldn't think they'd have any obligation to follow it (or any possible recourse for not doing so) unless they have business operations in the EU. Are these local news sites in fact all owned by multinationals that do have operations in the EU? Edit: I'm getting downvoted -- just in case it helps to clarify, I'm not trying t…

GDPR applies whenever you're providing services to EU citizens, regardless of where you have operations. If you want those people to read your stuff, it applies to you. And before you say that's crazy, look at US tax laws.

> GDPR applies whenever you're providing services to EU citizens

That's a common misconception. GDPR applies to the data of people "in the Union". There is no mention of citizens at all in GDPR.

If someone is not an EU citizen but is in the Union, it applies.

If someone is an EU citizen but is not in the Union, it does not apply.

Re: It's been three years. Stop saying your European visitors are important to you

#156
post #115

Maybe the cost of GDPR compliance just isn't worth the small amount of revenue that they might make from European visitors? US visitors are probably much more 'valuable' in terms of advertisement revenue, and also much more likely to be a subscriber. And I say this as a European myself. It sucks that I have to jump through hoops to access some sites but I can't really blame them.

Having worked on and lead 3 GDPR compliance projects, I can say that the cost of GDPR compliance is close to zero if your business is not tracking users or selling their data without consent. This assuming you are following best practises for storing users’ data (ie encryption, limited access to authorised personnel, etc…). If you store data without encryption, allow randos to access users’ personal data, you shouldn…

For small organizations, even if they are not tracking or doing anything with data that would need to be changed to comply with GDPR, the couple hundred or so Euros a year to comply with Article 27 [1] might be enough for them to block EU access.

[1] https://gdpr-info.eu/art-27-gdpr/

Re: It's been three years. Stop saying your European visitors are important to you

#157
Seeking the wisdom of the HN crowd:

Does RSS, with the full article content in each item's description, avoid the "problem" of GDPR compliance?

Maybe it'll become "cheaper" for global content creators to go back to old-fashioned content-targeted ads, which can be distributed through RSS [1], among other domains.

Placing the ads will be more expensive [2] (no more than it used to be), but it might be cheaper than guaranteeing GDPR compliance with the adware they've grown cozy with recently, and it opens up the EU as an available market.

[1]: for one example of this already working, podcasts are distributed via RSS, and have a rapidly growing advertising market around them: https://www.emarketer.com/content/us-podcast-ad-spending-sur....

[2]: apparently, most podcast ads are placed with a human in the loop (only 8% are placed programmatically). there might be a product idea here, in building a "static, content-targeted ad" exchange.

Re: It's been three years. Stop saying your European visitors are important to you

#158

Lawmakers and voters sometimes act as if regulations are free. They think “wouldn’t it be nice” and pass on the costs to businesses. They aren’t in fact free.

Of course regulations are not without cost to those being regulated. Lawmakers and voters would prefer not to have regulations; they would prefer if businesses just did the right thing. But they don't, so they have to be regulated. And nobody wants the cost of that regulation to fall on voters; so it falls on businesses. Hey, who makes money out of these websites? Voters? Nope. Why should anyone but businesses pay th…

To extend @bradleyjg's point, businesses often do try and "do the right thing" but don't always get the "voters" support. For instance, you could have no ads or tracking on your site, and just charge people to view the content. And of course the vast majority of people will simply not view it, go find a "free" version that has ads instead. Most companies could go 100% green today and do so by charging 2-10x more for their products -- do you think people in general would pay for it? It works on some scale, but not in general. So its not as simple as the business doing the right thing and business owners paying the costs. Its about forcing all business to adhere to some regulation, and pass the same cost on to customers in the same way, to achieve some hopefully laudable goal. And that's totally fine in my opinion, but it breaks down when people assume there are no costs passed on to customers, and (again to @bradleyjg's ponit) that you can merely make owners pay it without any knock on effect. Recognizing the costs and how policy works helps voters to push for the right ones IMHO.

Re: It's been three years. Stop saying your European visitors are important to you

#159

Jeez, what a mess. To extend the McDonald’s analogy, when McDonald’s is serving its American customers, it doesn’t heed European laws about beef and potatoes. Because those laws are irrelevant to them, they have no bearing on McDonald’s making money (again in the context of serving their American customers). McDonald’s is never going to check what Brussels says about dairy before they make a milkshake in Spokane. Sor…

Someone located in Brussels does not buy a cheeseburger from a McDonalds in Spokane. Someone located in Brussels might easily end up on the website of a Spokane newspaper.

A newspaper in Spokane is also not going to be covered by GDPR unless that actively target people in the EU. If a few people in the EU happen to wander over to your website, that's not enough to make you subject to GDPR.

Re: It's been three years. Stop saying your European visitors are important to you

#160
post #23

Earlier quoted context omitted.

Toxic positivity. It's a pervasive feature of American culture.

The concept of supermarket greeter blows my mind. As a customer this would be a reason to NOT go to that supermarket. As a potential employee I would have to be starving before I took that job.

Supermarket greeters are really for theft-prevention. It's not for the customer's benefit.
Post reply on HN