Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

291–300 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#291
post #253

Earlier quoted context omitted.

Promoting VPN usage could be construed by the UK courts as an attempt to commit subterfuge or dodge jurisdiction. They will not take kindly to this. You really want to make it perfectly clear that you want nothing to do with Britain as long as they have crazy laws on the books. Related point: if you're intending to get out of GDPR, blocking the EU doesn't really help, because the law applies on the basis of citizensh…

>Related point: if you're intending to get out of GDPR, blocking the EU doesn't really help, because the law applies on the basis of citizenship, not territory. Argh, why won't this misinformation die? You are completely, utterly, 100% wrong. The GDPR applies if either the data controller is established in the EU or the data subject is physically in the EU. Article 3 (territorial scope) is incredibly short, read it:…

Yes and this may be a UK citizen on a trip to Paris

Re: Your compliance obligations under the UK’s Online Safety Bill

#292
post #266
post #217

Earlier quoted context omitted.

> If an EU citizen accesses your website in America, that's still within GDPR scope. No, that's not correct. You have to be clearly intending to (not just incidentally happening to) offer goods or services to an EU data subject. > ship things to the EU This wouldn't be enough to make the GDPR applicable. You'd have to be specifically targeting EU customers in some way, such as allowing users to pay in euros - not jus…

Targeting EU data subjects with goods and services is just one of two ways GDPR asserts extraterritorial jurisdiction. The other is when you are processing personal data of EU data subjects that is related to "the monitoring of their behaviour as far as their behaviour takes place within the Union". There's a recital that adds: > In order to determine whether a processing activity can be considered to monitor the beh…

> That's pretty broad as written. From what the recital says it even applies if you are gathering data the could be used for profiling even if you are not actually currently profiling.

I'm not aware of legal cases that have specifically hinged on this issue, but Soriano v Forensic News LLC (from 2021) touched on this clause, and seemed to doubt that merely collecting information (e.g., using cookies) without further processing it with the intent to profile would make you subject to the GDPR.

I didn't specifically mention Article 3(2)(b) - the clause you're citing - because the post I was responding to didn't really mention profiling in any way. Still, it's good to note that the legal landscape on this particular point isn't totally clear as far as I'm aware.

Re: Your compliance obligations under the UK’s Online Safety Bill

#293

Can someone explain why this won't result in a renaissance for peer to peer and e2e encrypted chat/forums/social media etc.? When government or industry makes it nearly impossible for consumer needs to be met we inevitably see a grey and black market spring up to meet those needs. My prediction is that if legislation like this becomes widespread we'll see a freely distributed application rise to prominence among a ga…

Peer to peer needs a business model. E2EE social media involves storing tons of large binary blobs (images and video) for people, and they need to cover that cost somehow. Since it's already been established that social media is supposed to be free, a lot of people aren't going to want you to charge for it, no matter what advantages you have over other market participants.

Re: Your compliance obligations under the UK’s Online Safety Bill

#294
post #269

Earlier quoted context omitted.

Regarding GDPR, citation needed - do you have actual links you can share to those claimed "recent interpretations", and whose in particular they are? I'd be quite interested to see them, if true ,which I seriously doubt - for the time being, as an EU citizen, my understanding is, and continues to be, that it's totally possible for US corpos to adhere to GDPR; it would just require some money and effort to be spent by…

They're decisions by the governments of Germany, France, and Italy: * https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/ * https://www.cnil.fr/en/use-google-analytics-and-data-transfe... * https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/d... So far they've just been enforced against companies that use Google Analytics, but the reasoning behind it has been that having users connect to a US server e…

Doesn't seem so clear cut to me yet, but I see what you're hinting at. The first one seems about Google Fonts specifically, together with IPs indeed, but not mentioning US govt subpoenas at all (at least in the English translation of the abstract). Personally, I long believed Google Fonts are a risk from privacy standpoint and not really necessary, just easy - this seems to basically be reflected in the abstract and makes me quite happy. Interestingly, it seems to mention severity of the privacy abuse potential vs. benefit, which again sounds great to me. Now, the 2nd one mentions GA and subpoenas, so this becomes more tricky and I wonder what will come of it. Though for the time being, GA is exactly a target I hoped would be regulated, so again rather happy for now, though I see how this seems indeed a concern dealing with any US company. And how connecting the two (i.e. IPs as PII + US govt subpoenas) becomes a concern as well. IANAL, obviously, though. But interesting, thanks!

Re: Your compliance obligations under the UK’s Online Safety Bill

#295

Earlier quoted context omitted.

It's not really weird. We have rights guaranteed to us in the United States that no other country has, so it makes sense we would not extradite.

The US extradites people, including US citizens. That is required from the federal government by extradition treaties that are signed voluntarily by the US (in exchange for extradition _to_ the US). It is uncommon because they require escalations through the Department of State and not many crimes are serious enough to justify extradition.

The US does not extradite for crimes committed in the US to other countries at least I'm not aware of any cases.

Re: Your compliance obligations under the UK’s Online Safety Bill

#296
post #220

The article says: "Is it possible for your site, service, or app, which allows content to be shared and/or people to communicate with each other, to be accessed by any adult or any child within the UK? Then you’re in scope. NB “accessed” doesn’t necessarily mean that a user can set up an active account on your service. If a British adult can merely download your app on the app store, the app is in scope." However, th…

The "has links with the UK" portion of the "regulated service" definition says if UK users are a "target market", or if the "service is capable of being used in the United Kingdom" and there's user generated content with a "material risk of significant harm" then it "has links".

If an app is available in an app store are the users who can access it not a target market?

I'm not really sure what "material risk of significant harm" means for the second qualifier but if it means "users can potentially post bad things" then that seems very broad too.

I feel it's telling that they had a need to make exceptions explicitly for email/voip/sms texting.

Re: Your compliance obligations under the UK’s Online Safety Bill

#297

Can someone explain why this won't result in a renaissance for peer to peer and e2e encrypted chat/forums/social media etc.? When government or industry makes it nearly impossible for consumer needs to be met we inevitably see a grey and black market spring up to meet those needs. My prediction is that if legislation like this becomes widespread we'll see a freely distributed application rise to prominence among a ga…

It could mean choosing a life of crime if the regulations are too draconian. Now that your legit business enterprise can’t succeed because of Stasi tactics by the UK government, you are forced to go underground and build something to sidestep the measures.

Re: Your compliance obligations under the UK’s Online Safety Bill

#298

Earlier quoted context omitted.

Conservatives are, by definition, people who want to conserve the status quo. They believe society is good as it is (or as it was in sine possibly imagined past) and seek to use the power of the state to prevent changes, and to revert any changes that are pushing society away from what they believe is the status quo. Conservatism has absolutely nothing whatsoever to do with "being conservative in application of gover…

Quoted post unavailable.

Clarence Thomas believes these things should be prohibited. He has stated some of these things before, especially about gay marriage - he doesn't believe it should be permitted in the United States, regardless of how that permission is achieved. He doesn't necessarily believe that the Supreme Court should or can ban it, but he certainly believes it should be banned, in an ideal world.

He doesn't believe that the Supreme Court has power to prohibit them, so he's trying to do the next best thing: make sure that the Supreme Court doesn't prevent the federal or state governments from prohibiting them.

Also note that Roe v Wade has nothing whatsoever to do with the federal government. It has everything to do with individual rights, which don't come from the government, they are natural rights. The government can only recognize or fail to recognize them.

His predecessors recognized that these wildly popular natural rights exist and are compatible with the Constitution, so they made sure all states are compelled to recognize them.

The current highly partizan court has decided to ignore these natural rights in favor of their political agenda. That they couch this in the language of overreach is just an obvious rhetorical ploy.

If the federal government makes a law prohibiting abortion in any state, this same Supreme Court will argue that is obviously in the power of the federal government to regulate. If the federal government possess a law guaranteeing abortion, they will find that it is unconstitutional, tidying done other legal reasoning.

You may choose to fall for the rhetoric of demagogues like Thomas, but most people who think critically quickly see past it.

Re: Your compliance obligations under the UK’s Online Safety Bill

#299

Earlier quoted context omitted.

The US extradites people, including US citizens. That is required from the federal government by extradition treaties that are signed voluntarily by the US (in exchange for extradition _to_ the US). It is uncommon because they require escalations through the Department of State and not many crimes are serious enough to justify extradition.

The US does not extradite for crimes committed in the US to other countries at least I'm not aware of any cases.

No, there is not a precedent for that AFAIK. But the US does extradite, as we don't have "rights guaranteed to us in the United States that no other country has".

Re: Your compliance obligations under the UK’s Online Safety Bill

#300
post #171

Earlier quoted context omitted.

If the article is to be believed, then simply ignoring this law would open your company's leadership up to criminal liability in the UK. This probably doesn't matter too much, assuming they never fly through Heathrow or something.

I mean you can just ban all UK IPs and be done with it. Its clearly not a sensible law, and blocking users will send a clear message to them that they should complains about it.

Realistically, are they going to complain? I don’t ever remember a mass revolt over US websites blocking EU users because of GDPR.
Post reply on HN