Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

151–160 of 349 posts

Re: Shopify Is Illegal in Germany

#151

This is getting ridiculous. The EU is waging a protectionist war on US tech companies. The US should ban all EU produced cars from the US until the EU figures out a solution.

While I am by no means a fan of GDPR and this behavior by, especially in Germany, tiny federal data protection agencies spouting toxic, perfectionist legal interpretations onto entrepreneurs for mostly making a name for themselves...

You do realize that there is a fair share of protectionism alive and well in the US as well, right?

Probably not the most productive way to argue to start a tit for tat comparison, let's just be honest withourselves that everyone kinda does it in areas where they lag behind (digital in EU, some engineering, cars in the US).

Re: Shopify Is Illegal in Germany

#152

This is getting ridiculous. The EU is waging a protectionist war on US tech companies. The US should ban all EU produced cars from the US until the EU figures out a solution.

It's a war on casual privacy invasion by US companies that can't be bothered to pay attention to what's happening in a legal sense in key markets that are important to them (from a revenue point of view). There are plenty of US companies that get a lot of revenue from the EU market. Including some big names like Azure, Amazon, etc. And they aren't being banned but they are being forced to comply with locally applicable law. As they should.

As for cars, the US has already forced many EU based car manufacturers to produce in the US. So, when it comes to protectionism, the US is way ahead of you.

Re: Shopify Is Illegal in Germany

#153
post #72

Earlier quoted context omitted.

I think it's good that the EU is forcing the US to get their privacy laws in order.

Wait, do you think law enforcement agencies in Europe can't force companies to reveal ip addresses and/or other customer information?

They can do whatever the local laws allow. If the local laws forbid it, then they can't.

Re: Shopify Is Illegal in Germany

#154
post #128

Earlier quoted context omitted.

> A German CDN can setup their own infrastructure Ok, but what if you just want to run a website and not build a billion doller global CDN. > GeoDNS According to the GDPR you have to protect the data of your visitors no matter where they are.

> Ok, but what if you just want to run a website. Not build a billion doller global CDN. Ah, from the perspective of website owners, not the CDN owner... Well, use a European CDN, they tend to follow European regulation, just like US companies follow US regulation. The two companies that comes first to mind is BunnyCDN and KeyCDN, but I'm sure there are many others. Both of them have global networks. > According to t…

I was addressing your point "US visitors to domain.com gets a different IP". How does that relate to GDPR?

Re: Shopify Is Illegal in Germany

#155
post #116

Earlier quoted context omitted.

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

I thought it was the storage of such data that is illegal not the connection? Obviously logs and analytics are an issue in some cases for this law, but I slightly agree with it; should we not all want our digital footprint to be as small as possible?

No, courts have made it clear that sending EU IP addresses to the US is illegal unless you can prove that the US government can't intercept it or someday force you to log them. No one the US is immune to subpeona, so no one can comply with that requirement.

https://www.cnil.fr/sites/default/files/atoms/files/decision...

Re: Shopify Is Illegal in Germany

#156

Earlier quoted context omitted.

I can’t see EU’s balkanization in positive light either. Seems good ol protectionism instead of actually innovating. Privacy is a trope, they give away data at US’s whim.

The EU isn't "the" EU. The GDPR was created by the elected representatives of the EU citizens. The EU commission consisting of representatives of the EU member state's governments are giving away the data.

Elections have consequences.

Re: Shopify Is Illegal in Germany

#157

Earlier quoted context omitted.

Don't spread FUD please. > anyone in the EU is not even allowed to connect to any website owned by a US company This is blatantly false, of course you are allowed to connect to non-EU websites even if the IP address could be PII in some circumstances. It's the service providers problem to manage the data they collect in legal way.

There _is_ no legal way to manage that data if the service provider is subject to the CLOUD act.

There is an option for a service provider not to store the IP address anywhere.

For users with accounts the standard ToS can handle it.

Re: Shopify Is Illegal in Germany

#158

Earlier quoted context omitted.

I thought it was the storage of such data that is illegal not the connection? Obviously logs and analytics are an issue in some cases for this law, but I slightly agree with it; should we not all want our digital footprint to be as small as possible?

How long does your TCP connection need to be open for until it becomes "logs"? The law doesn't care what format that this information is stored in.

Maybe I’m getting confused with GDPR, anyway I think interpretation of these laws that the stop the internet from working completely is usually incorrect in my experience.

Re: Shopify Is Illegal in Germany

#159
post #129
post #116

Earlier quoted context omitted.

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

People are free to give away their PII

How do you collect consent from people before you receive their IP addresses?

Re: Shopify Is Illegal in Germany

#160
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

Honestly, I think if the GDPR had been around before HTTP, we would have seen HTTP as the unreasonable part in this system.

You don't have to make a direct TCP/IP connection for two people to communicate. We had systems like Usenet and UUCP that replicated data through a series of servers. Even today, when you use email, you talk to your email provider who talks to the recipient's email provider, and they have no need to share your personal IP addresses in the process. Some providers used to include this in Received: headers, but many today do not, rightly seeing it as a privacy concern. And even on HTTP we had (and still have, in some cases) mirrors, where legally-unrelated entities host copies of each others' data. Someone in the EU can visit http://ftp.icm.edu.pl/pub/linux/Documentation/ and never have their connection known to the US-juridiction host of TLDP.

It is both socially sensible for these providers to consent to sharing their own infrastructure IP addresses with other providers (but not share their customers' IP addresses) and legally practical for them to make that consent under the GDPR.

Why should it be the case that when you visit my personal website, which I happen to self-host, I have access to your IP address? I don't want that information. I don't even get that information when using higher-level services like Hacker News or Twitter or GitHub, even though those services operate over HTTP. It's weird that I get it, honestly.

I understand there's a huge planetary investment in HTTP, and so the collision of abstractly-reasonable privacy rights with that reality is an extremely hard engineering and policy problem. But that doesn't make the privacy rights unreasonable.

Post reply on HN