Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

261–270 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#261

If this applies to every site that hosts user generated content then that's nuts. When the internet first started, part of the appeal is that you could just make stuff without people looking over your shoulder, asking for forms, etc. Seems that the internet we created today is technically the same as the one from before, but now with governments throwing up red tape at every corner. Makes me wonder what a site like H…

We're also going to get the big companies triggering investigations of smaller up-and-comers to stamp out competition. Better Reddit? Think of the children. Better Twitter? Think of the children. Facebook without the algorithm? Think of the children. Just like what we see with the DMCA. Cheaper toner cartridges? Think of the creatives!

Honestly this impact can't be overstated. If the bill passes I'm leaving the UK

Re: Your compliance obligations under the UK’s Online Safety Bill

#262
I found the comparisons to the EU privacy regulations a bit annoying. I think the article would be stronger without them. I think they give too rosy an impression of the EU regulations (which can also be bad or burdensome) and that makes me think the U.K. regulations are less bad (rather than that they are so bad they make the EU regulations look good, I suppose).

Re: Your compliance obligations under the UK’s Online Safety Bill

#264

Earlier quoted context omitted.

Don't worry, blocking p2p is the next step and is extremely easy to do. China has done it already and it's very effective: * Force every service provider to register their IPs and domains (for CDN use) * Force every ISP to do stateful firewalling and block every attempt to establish a new connection unless the destination IP is on a whilelist maintained by the government. Problem solved.

Autonomous pirate satellite internet

Men with guns.

Yeah, they can't 100% win. They don't need to. In fact, even if they did 100% win, they'd still find reasons to need to crush some people just to keep people reminded of who has the guns.

Re: Your compliance obligations under the UK’s Online Safety Bill

#265
If UK government really cared about children, and not about surveillance and censorship, they would solve the problem another way.

The only way protect children online is to ban them from Internet. Children should not have access to normal laptops and smartphones, instead they should use "kid phones". Such phones would allow children to communicate only with people approved by parents or teachers and visit only approved sites. This way they will enjoy perfect safety which this Bill fails to provide.

Every site which wants to become approved, must fulfill all the requirements from the Bill and indicate this with a HTTP header. Kid phones and laptops should allow only to visit such compliant sites.

Kid-oriented phones and laptops must be visually distinctive: for example, have a shape of a cute animal. In this case teachers, parents or police will be able to instantly spot and confiscate illegal devices.

This is a win-win plan: kids would be safe and adults would be safe from government overreach. Obviously no government will agree to such plan.

Re: Your compliance obligations under the UK’s Online Safety Bill

#266
post #217

Earlier quoted context omitted.

Promoting VPN usage could be construed by the UK courts as an attempt to commit subterfuge or dodge jurisdiction. They will not take kindly to this. You really want to make it perfectly clear that you want nothing to do with Britain as long as they have crazy laws on the books. Related point: if you're intending to get out of GDPR, blocking the EU doesn't really help, because the law applies on the basis of citizensh…

> If an EU citizen accesses your website in America, that's still within GDPR scope. No, that's not correct. You have to be clearly intending to (not just incidentally happening to) offer goods or services to an EU data subject. > ship things to the EU This wouldn't be enough to make the GDPR applicable. You'd have to be specifically targeting EU customers in some way, such as allowing users to pay in euros - not jus…

Targeting EU data subjects with goods and services is just one of two ways GDPR asserts extraterritorial jurisdiction.

The other is when you are processing personal data of EU data subjects that is related to "the monitoring of their behaviour as far as their behaviour takes place within the Union".

There's a recital that adds:

> In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.

Unlike the recital that explains the goods and services case, which talks about it only applying if you envisage offering goods and services in the Union as opposed to your site merely being accessible from the Union, the monitoring case doesn't seem to have any requirement that you are intending to monitor EU data subjects.

That's pretty broad as written. From what the recital says it even applies if you are gathering data the could be used for profiling even if you are not actually currently profiling.

As noted in the article at gdpr.eu that a parallel commenter cited:

> If your organization uses web tools that allow you to track cookies or the IP addresses of people who visit your website from EU countries, then you fall under the scope of the GDPR. Practically speaking, it’s unclear how strictly this provision will be interpreted or how brazenly it will be enforced. Suppose you run a golf course in Manitoba focused exclusively on your local area, but sometimes people in France stumble across your site. Would you find yourself in the crosshairs of European regulators? It’s not likely. But technically you could be held accountable for tracking these data.

Re: Your compliance obligations under the UK’s Online Safety Bill

#267
post #169

If I, a US citizen, started an online service that attracted Ofcom attention, what binds me to following UK regulations? The article mentions "extraterritorial enforcement", but what does that mean? Will the US extradite me to the UK if I don't put monitoring in place? Will I get arrested if I visit the UK? Will they try to sue me in US court? I mean realistically if it became a problem I'd just IP-block all of the U…

In theory yes, in practice the US basically never extradites people to the UK and if they tried you would probably have a good defence (against extradition) under various parts of the constitution.

"From January 2004 to the end of December 2011, seven known US citizens were extradited from the US to the UK. No US citizen was extradited for an alleged crime while the person was based in the US."

https://www.whatdotheyknow.com/request/100739/response/25520...

https://www.telegraph.co.uk/news/politics/9237663/No-America...

Re: Your compliance obligations under the UK’s Online Safety Bill

#269

Earlier quoted context omitted.

This has been said about the EU, but the market has proven to just be too big to ignore. It could also be the reverse (see authoritarian countries), with international players leaving the market and local ones filling the space.

Very few websites comply with GDPR. Based on recent interpretations, it's essentially impossible for any US-owned or US-hosted site to comply with GDPR. The EU is just being extremely selective about its enforcement. If they ever decided to follow the law to the letter, most of the Internet would have to disconnect the EU. Theoretically the EU could make clones of all international sites like China has with Baidu and…

Regarding GDPR, citation needed - do you have actual links you can share to those claimed "recent interpretations", and whose in particular they are? I'd be quite interested to see them, if true ,which I seriously doubt - for the time being, as an EU citizen, my understanding is, and continues to be, that it's totally possible for US corpos to adhere to GDPR; it would just require some money and effort to be spent by companies that blatantly hoover and hoard personally identifying data in hopes of squeezing some monies from it. And having to spend some money on anything that is not an investment into more money in the future seems to always trigger over-the-top allergic reaction in corporations. Until they feel the teeth of real law in painful fines, when suddenly "impossible" things will magically become possible.

Re: Your compliance obligations under the UK’s Online Safety Bill

#270

Can someone explain why this won't result in a renaissance for peer to peer and e2e encrypted chat/forums/social media etc.? When government or industry makes it nearly impossible for consumer needs to be met we inevitably see a grey and black market spring up to meet those needs. My prediction is that if legislation like this becomes widespread we'll see a freely distributed application rise to prominence among a ga…

More likely it will result in crippling the domestic UK tech industry while everyone else in the world ignores it. I really don't see most countries extraditing someone for the high crime of "let british users access a website without verifying their age".

After my ears bleeding from trying to understand the legislation, I know I'll be ignoring it.
Post reply on HN