Live data from Hacker News

GDPR and Google Analytics

adactio.com

31–40 of 130 posts

Re: GDPR and Google Analytics

#31
post #24
post #20

Earlier quoted context omitted.

Well, the point of the GDPR is to make you aware that collecting personal data of EU citizens requires their explicit consent. Just ask me for it, that's not a big deal, is it? If you don't, you're effectively stealing from me and I shall expect my government to go after you to the full extent of the law.

What makes you imagine your government has any jurisdiction over me? EU citizens can choose to use services offered under other countries' laws, or not. The EU can choose to implement their own Great Firewall to block such services, or not. Frankly I don't care either way.

Uh? This is already how the world works. It does not matter where you are located as long are you are transacting with EU citizens.

In extreme cases of non-compliance, avenues for enforcement that have been discussed reuse existing Anti Money Laundering mechanisms: once flagged in the system, banks will simply freeze your business assets connected to EU countries and you might be arrested upon crossing any EU border.

Re: GDPR and Google Analytics

#32
post #23
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

> It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. If you don't process PII about people from EU then GDRP does not apply. Merely accessing the page from EU does not trigger GDRP.

PII is an American concept, not a GDPR concept. The GDPR has a notion of personal data and it is much more expansive than PII. While merely accessing the page from the EU doesn't trigger GDPR, logging and analytics may.

I do think DPAs attempting to regulate EU external sites will be something to behold.

Re: GDPR and Google Analytics

#33
post #29

Can the US please just pass this too? The EU's current stance on privacy and individual rights makes me want to pack up my life and move there. I'd much rather the law just come here though.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

I think it makes sense when your activities infringe on the rights of citizens inside their borders.

It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

Re: GDPR and Google Analytics

#34
post #21

Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen o…

> I'm going to block access to my services to anyone based in Europe... I'm tired of governments that I don't care about expect me to follow some nonsense I have no part of under the guise of compliance.

Ever been on a plane? ... Used a cellphone outside your own borders? ... Eaten a beautifully ripened imported cheese along with a stunning imported wine?

Put your money where your mouth is: boycott all benefits of transnational cooperation and international legislation. NGOs are how a lot of the capitalism on this planet gets done. 'Compliance' is how we protect our businesses and consumers against fraud and mislabeled products.

Functionally "compliance" is a judicial equivalent of an API... All I'm reading is "Why do I gotta use Googles APIs? I wanna make my own APIs! No more API use, no matter the costs to my customers, because I'm sick of giant oligarchies demanding I comply to their demands! What are you gonna do?"

They'll stop doing business with you, that's what. And shrug about it. Your website will be replaced with one from Romania, and you'll probably develop a deep sense of irony if you feel they've infringed on your IP in any way and want to sue them... because all that stuff is based on 'compliance' too.

Re: GDPR and Google Analytics

#36
post #21

Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen o…

Imagine you’re living in a country which allows you to sell drugs freely, then it’s clear that you can sell them in a country where they are banned. I don’t really think this is different regarding privacy. You have to obey to the law where you run your business. It’s up to you wether you change your business or leave the market.

Your argument that it’s weird that you have to “adhere to their laws” is a fallacy. Your decision to leave the market is up to you.

Re: GDPR and Google Analytics

#37
post #29

Earlier quoted context omitted.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

Indeed. The idea that a country would zealously protect it's citizens' rights is practically unheard of these days, but that's what's starting to happen. GDPR is a great example, another one was Canada pushing a Right To Be Forgotten ruling worldwide as well.

It's a statement that someone's private data and intellectual property is theirs. You aren't free to steal it just because you're in another country. Google and Facebook have no divine right to people's personal data, and I am thrilled to see countries protecting their people.

Re: GDPR and Google Analytics

#38
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

>. You can get reasonably good statistics by just using a local log analyzer that does not upload your visitor's data to an analytics/ad company.

1) Has your user consented to your webserver's access logging?

2) Has your user consented to the use of access log entries about them for analytical purposes?

3) How will you delete the access log entries corresponding to a user upon request?

4) How will you provide a user with the access log entries about them upon request?

(I am not a lawyer, this is not legal advice).

Re: GDPR and Google Analytics

#39
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

It is remarkable how many websites use Google fonts. I wasn't really aware until I used uBlock to disable third party fonts, and icons started disappearing on many fonts. Web designers are inadvertently enabling mass corporate surveillance by simply trying to save bandwidth on font icons.

Re: GDPR and Google Analytics

#40
post #20
post #16

Earlier quoted context omitted.

It isn't my responsibility to block them, or to take any action whatsoever to comply with another country's laws.

Well, the point of the GDPR is to make you aware that collecting personal data of EU citizens requires their explicit consent. Just ask me for it, that's not a big deal, is it? If you don't, you're effectively stealing from me and I shall expect my government to go after you to the full extent of the law.

That is actually not correct, consent is one of several options (and usually not the best option because there are strict requirements for a valid consent).
Post reply on HN