Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

311–320 of 349 posts

Re: Shopify Is Illegal in Germany

#311
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

Short answer: Don't be based in the US until the US respects fundamental human rights, like the right to sue before a proper court. Simple, isn't it?

The more pragmatic answer is: You can just ignore human rights. The other US companies operating in the EU also don't have issues with that.

The EU isn't going to enforce its own laws in this regard anyway as more or less all EU governments are violating this laws themself. They currently all just waiting for the next round of the "safe harbor" smoke grenade.

On the other side, the EU companies that use US cloud services (so more or less all EU companies) do by the way exactly the same. Nobody cares.

Re: Shopify Is Illegal in Germany

#312
post #245

Earlier quoted context omitted.

How would BunnyCDN and KeyCDN be able to have endpoints in the US that are beyond the reach of the US government? The recent rulings say that no packets are allowed to travel to the US because that would enable the US government to access them if it wants to. I don't see how this can be avoided. As soon as a tcp packet enters the US, it is on infrastructure the US government can access if it wants to.

Again, you route people differently depending on the location. The problem is not that the US government can access data for US persons when on US soil, the problem is US government being able to access EU persons data when on EU soil.

Did you read the GDPR? I did not see any reference in there to location or "soil" being relevant to how it applies.

Re: Shopify Is Illegal in Germany

#313
post #268
post #257

Earlier quoted context omitted.

We've actually never been asked. Some unelected bureaucrats decided "for our own good".

They're elected representative. You were asked in the most official way possible, with elections. Both in your national election which then decided the government which chose your country EU representative for the council and commission, which then created the law and decided to put it to a vote and where your government had a direct veto right, and in the European election where you elected the parliament that voted…

None of the representatives I voted for got elected.

No candidate had on her proposal list "hunt and close cookie consent dialogs on the web forever".

I recommend you go out on the street and find out how real governing in the EU works, you seem to be deeply idealistic about it. It’s important, it could be why the next brexit happens.

Re: Shopify Is Illegal in Germany

#314

Earlier quoted context omitted.

> We can all see the results of it. It made the web experience worse for everyone This bullshit again. It wasn't the GDPT that made the web worse. This is is entirely on the companies who took a look at GDPR and said: no, we're going to ignore it, continue siphoning user data, and trick users into "consent" through dark patterns (actually illegal under GDPR). > Thought experiment: why didn’t any major ad tech company…

It’s amazing that the excuse for the web being worse is always “the web being worse is not caused by the law being bad. It’s caused by it being badly enforced”. The fact is that the cookie pop ups would never be necessary if the GDPR hadn’t been passed.

> the web being worse is not caused by the law being bad. It’s caused by it being badly enforced

Because that's the truth

> The fact is that the cookie pop ups would never be necessary if the GDPR hadn’t been passed.

Show me exactly where GDPR mandates the use of cookie pop ups.

(Hint: GDPR mandates: "ask the user for consent if you collect more data than is strictly necessary, and the opt-out must be as simple as opt-in". Guess who decided they should continue siphoning all possible user data and trick users into giving this data with dark patterns)

(Another hint: AppStore rule on tracking was more effective precisely because Apple has the possibility to enforce it immediately. And still the greedy leeches like Facebook complained about the rule, not about their own practices)

Re: Shopify Is Illegal in Germany

#315

Earlier quoted context omitted.

IANAL. Although I imagine you could, presumably they'd argue that (while your parking tickets are unpaid) they have a legal basis other than consent for processing your personal data. In that case, you'd probably have to find grounds for erasure other than withdrawal of consent. 1d or 1e of Article 17 look most relevant (but maybe not very promising): https://gdpr-info.eu/art-17-gdpr/

So Italy issued the ticket, gets my contact info from the rental company, then hands it over to the collection agency. Is it reasonable that all of that is something I agreed to beforehand? I have no idea. If you rent a car in the EU should you immediately send them a GDPR request after you are done to get them to remove your data so you can't be found? Or is there a legal requirement for them to hold on to the data?…

Come on, GDPR does bot supersede other laws.

E.g. if some law requires a company to retain certain data for longer periods than stated in GDPR, that law still applies.

Re: Shopify Is Illegal in Germany

#316
post #227

Earlier quoted context omitted.

It is neither impossible to follow or very hard. It just happens to be incompatible with US laws that grant local law enforcement access to stuff that is stored outside their jurisdiction, for customers also outside any jurisdiction.

Yeah, all countries should just fix their legislation to be compatible with the EU one. Is it so hard?

If they want to provide services to EU yes they should. Or at least limit governmental powers to their own citizens.

Re: Shopify Is Illegal in Germany

#317

It is ridiculous that data protection officials focus on CDNs, third party resources and cookies. And at the same time it is totally legal for Google to collect advertizing data from some random websites so they can create a profile that follows you around. All that sites have to do is to put up obnoxious cookie banners that nobody reads. If they were really concerned about my privacy, they would ban creating cross-p…

According to the Danish Data Protection Agency Denmark has outlawed the use of Google Analytics[0]. Austria, France, and Italy have also done so. [0]: https://www.datatilsynet.dk/english/google-analytics/use-of-...

But as a user in Europe, I still see plenty of personalized Google Ads. That's not Google Analytics, that is Doubleclick.

My point is that Google Analytics (or Matomo or whatever visitor statistics you are using) is outlawed, while it is apparently completely legal for Google Ads to include dozens of "fourth-party" javascript files and everybody keeps records of what pages you visit.

It's totally backwards. Embedding content (using a basic HTML feature, sending basically only the IP address) can get you in legal trouble. But if I visit a website about say, lawnmowers, then ads for lawnmowers follow me around for weeks, because the site owners sold every mouse movement on that site for a fraction of a cent to advertizers.

Re: Shopify Is Illegal in Germany

#318
post #62

Earlier quoted context omitted.

Or you know, right click page -> Translate to English. I'll miss that the most when manifest v3 rolls out and chrome becomes unusable.

https://www.mozilla.org/en-US/firefox/features/translate/ never tried, but seems promising

Seems like it just takes the text and pastes it into google translator? Not even close to the same functionality of translating the entire page in situ with 2 clicks.

Re: Shopify Is Illegal in Germany

#319

Earlier quoted context omitted.

If you dont handle/store PII then there is no problem. Or, you can just do it anyways. Its not like GDPR and Schrems II have stopped Microsoft, Amazon, Google, etc etc.

I can't get away from storing PII for signed in users. For non-signed-in users, I think it would be useful to avoid all PII.

Fair enough. Just wanted to make sure the take away wasnt that US companies cannot deliver services _at all_ to EU.

Just curious whats your product/service? And how is PII used (high level)? As a dev and sw architect, and strong supporter of GDPR, I think its interesting to (attempt to) find engineering solutions for the challenges posed by GDPR (and Schrems)

Re: Shopify Is Illegal in Germany

#320

Earlier quoted context omitted.

I can't get away from storing PII for signed in users. For non-signed-in users, I think it would be useful to avoid all PII.

Fair enough. Just wanted to make sure the take away wasnt that US companies cannot deliver services _at all_ to EU. Just curious whats your product/service? And how is PII used (high level)? As a dev and sw architect, and strong supporter of GDPR, I think its interesting to (attempt to) find engineering solutions for the challenges posed by GDPR (and Schrems)

> Fair enough. Just wanted to make sure the take away wasnt that US companies cannot deliver services _at all_ to EU.

With the CLOUD Act, I'm wondering if it is illegal.

> Just curious whats your product/service? And how is PII used (high level)? As a dev and sw architect, and strong supporter of GDPR, I think its interesting to (attempt to) find engineering solutions for the challenges posed by GDPR (and Schrems)

It's a code forge.

For users with accounts, I have to store at least email addresses, which I believe are PII. I also need to store public keys (for commit signing), which could be considered "identification numbers" covered by the GDPR.

Even if I got away with not using email addresses, I can't get away with not storing public keys, unfortunately.

I believe that once I store any PII, it's game over, right?

By the way, I'm all for strong consumer privacy protection too. I would want the US to implement something like the GDPR as well. So I'm a supporter on some level. I'm just mad at the US government for the CLOUD Act.

Post reply on HN