Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

31–40 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#31
post #19
post #10

Things like this will test how much EU citizens value their privacy. Of course there will be some sites they will not be able to visit but time will show if they are okay with that. These rules are very similar to rules limiting loans. No matter how desperate a person is and how low credit they have, in the US you can't give them a loan for above a certain amount of interest. That could be terrible for a poor person…

You can still run a free website and be compliant with the GDPR. The EU/EEA is the largest market in the world, closing yourself for an market that size will hurt more than changing a few thing to be compliant.

>closing yourself for an market that size will hurt more than changing a few thing to be compliant

Only if I make significant money from that market. If most of my revenue/profit comes from the US and it's problematic to "do business" in the EU or China, why wouldn't I want to just cut access off rather than dealing with potential hassles? The fact that it's potentially a large market is irrelevant to me. In this case, any moderately tech-savvy consumers can get to my site anyway using a VPN. But I've sent a clear message that I'm not marketing to European consumers.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#32
post #23

Earlier quoted context omitted.

"Click here to agree to everything we do" schemes are explicitly forbidden by the GDPR. You need to individually opt-in to every single use case, and you need to consent to every transfer to each individual third party as well.

IANAL No, coupling is forbidden. A 20 page, non-legalese EULA is allowed if you don't couple acceptance to using your site. "You need to individually opt-in to every single use case" No. But I would be happy for your source on that. You can't change the usage purpose after collecting, but if you declare what you do before (20 pages EULA) data collection, you're fine. "and you need to consent to every transfer to each…

http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...

> Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

> Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. In accordance with Council Directive 93/13/EEC (1) a declaration of consent preformulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

> In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#33

Earlier quoted context omitted.

I wished everyone who says "GDPR hysteria" would cover legal costs for those who are hysteric.

For a site that shows text and images you have a simple solution change the code if(isUserInEU()) showBlobkingPopup();) else loadAllTrackingScripts(); into if(isUserInEU()) loadNonTrackingScripts(); else loadAllTrackingScripts();

Why not directly?

    solveAllGDPRIssues();

Re: GDPR: US news sites unavailable to EU users over data protection rules

#34

Earlier quoted context omitted.

Except that won’t help them with the GDPR one bit. They will worsen their experience and not be in compliance because they are unwilling to actually do the simple things needed.

IANAL but after working on GDPR topics for months with a lot of reading I'd say they would work. Selling data is still hard to argue, I'd not do that for EU citizens ("tag EU citizens to opt out from selling data"). Everything else should be possible. Using Art 6/1(a) and Art. 7 GDPR you can store most of the data from your visitor. You need to make sure they can inform them about your usage, revoke their aggreement…

"Clever UI" (read: deceptive) tricks are obviously explicitely forbidden by the GDPR.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#35
post #4

I won't miss them. Why would I need to know about local news from places over 5000 km away? Luckily there is still archive.is and the Internet Archive for exceptional articles that pop up on HN.

For many of us the meaning of the internet itself is being able to access things at 5000 km away.

No one needs that kind of access, crazy thoughts.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#36
post #21

What else can they do when they have this laundry list of tracking scripts on a front page: https://i.imgur.com/hKEItPS.png They obviously have NO idea what's being collected on every user and how it is being used.

That’s the whole point of GDPR, selectively kill the web businesses they want. BBC will never be concerned.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#38

Earlier quoted context omitted.

For a site that shows text and images you have a simple solution change the code if(isUserInEU()) showBlobkingPopup();) else loadAllTrackingScripts(); into if(isUserInEU()) loadNonTrackingScripts(); else loadAllTrackingScripts();

Why not directly? solveAllGDPRIssues();

If you have a webpage with text and iamges, no user accounts and subscriptions then why you prefer to block the users then load the page without tracking, and show some static ads,better then nothing.

Showing a popup with things like -we have Google analytics that track you in this way -we have FB scripts that do this -we have ad company X script that tracks this -we have Y product that tracks your focus .... would also be good,then I know what "I lost" not getting access to that page

Re: GDPR: US news sites unavailable to EU users over data protection rules

#39
post #21

What else can they do when they have this laundry list of tracking scripts on a front page: https://i.imgur.com/hKEItPS.png They obviously have NO idea what's being collected on every user and how it is being used.

That’s the whole point of GDPR, selectively kill the web businesses they want. BBC will never be concerned.

If those businesses are heavy shadow tracking/ads companies which don't even know which user data are they collecting, to who are they sending them and for which final use, man, I am so damn happy.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#40
post #23

Earlier quoted context omitted.

"Click here to agree to everything we do" schemes are explicitly forbidden by the GDPR. You need to individually opt-in to every single use case, and you need to consent to every transfer to each individual third party as well.

IANAL No, coupling is forbidden. A 20 page, non-legalese EULA is allowed if you don't couple acceptance to using your site. "You need to individually opt-in to every single use case" No. But I would be happy for your source on that. You can't change the usage purpose after collecting, but if you declare what you do before (20 pages EULA) data collection, you're fine. "and you need to consent to every transfer to each…

I would be happy for your source on that.

It's in the "Guidelines for Consent" document, in "3.1.3 Granularity":

"A service may involve multiple processing operations for more than one purpose. In such cases, the data subjects should be free to choose which purpose they accept, rather than having to consent to a bundle of processing purposes."

And they give an example:

"Within the same consent request a retailer asks its customers for consent to use their data to send them marketing by email and also to share their details with other companies within their group. This consent is not granular as there is no separate consents for these two separate purposes, therefore the consent will not be valid."

http://ec.europa.eu/newsroom/article29/document.cfm?action=d...

Post reply on HN