Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

431–440 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#431
post #422

Earlier quoted context omitted.

OK, so let's say that hypothetically I run a small business in the US. I just sell access to software (that lives on my server in the US) instead of burgers. An EU visitor comes to my server in my country and buys something. Why should I care about their laws any more than the burger shop owner should?

Is your argument that someone else in the business should care or is your argument that EU visitors should not have rights to their data because it is inconvenient to you? Depending on your arrangement, if you are a reseller for example, you probably are not responsible for what that software does with your customer's data. Also, burger shops that do business in EU(usually chains, McDonald's and Burger King) do care…

Burger shops IN the EU are a completely different thing.

My primary argument is that the GDPR's attempt to regulate companies in other jurisdictions because EU citizens go INTO those jurisdictions and do business is a dangerous precedent. If there was an enforcement mechanism for all such laws, it implies that any business or individual anywhere in the world with a website should therefore have to comply with any laws from any jurisdiction that are similarly constructed.

If my website says things about Islam that Saudi Arabia passes a law against, I should be fined.

If my website disrespects the king of Thailand, I should be extradited for imprisonment.

If I encourage NK citizens to revolt against their oppressive regime, I should end up in a labor camp.

After all, those governments have a right to say that if I want to "do business in their jurisdiction", I must respect their laws, right?

(To be clear, I'm not talking about enforcement of these kinds of laws, because all of those countries might do the above if given the chance. I'm talking about what I SHOULD do as a matter of morality or ethics or civic duty or whatever, or what my government should cooperate with those governments on, because it's just.)

But the problem is that they're describing "doing business in their jurisdiction" as a citizen from their country (maybe even one who is currently visiting my country) going online and sending my server requests, data, and money. And apparently explicitly telling those citizens to please NOT do that, or blocking them, is not sufficient. The only way to make the majority of the EU users on HN happy is to comply. Why would that same logic not apply to all other kinds of laws?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#432

The limitations of internet technology means that any computer located in the EU, whether or not the user controlling it is in the EU, can enjoy the beneficial effects of the GDPR. (Those limitations and effects being in part that companies will attempt to distinguish EU natural or legal persons based on IP address.) The GDPR finally provides a legitimate, compelling rationale for users to employ longstanding methods…

>GDPR only applies to EU citizens.

No, it doesn't. It applies to natural persons in the EU.

Article 3 GDPR:

---

Territorial scope

1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

---

Note that the above does not reference citizenship.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#433

Earlier quoted context omitted.

In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked, and the primary bottleneck to making software more secure is crap tools, crap platforms, poor training and inability to hire people who deeply understand security. Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".

> In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked No, it boils down to an incentive . No company wants to get hacked, but a lot those same companies aren't willing to invest in security measures and training that could mitigate the risk. > Hacking is not a problem you can solve by passing a regulation that says "don't get hacked". I don't think anyone's propo…

But companies that do invest massively still get hacked. See: Google. Yahoo. Microsoft.

It's also not even always clear what hacking actually means. A common way users get hacked is by reusing the same password on every website. One of those small sites gets hacked, the hackers try the users password at bigger sites to see if they work. Big players like Google and Facebook have heuristic systems that try to detect and block that, but sometimes they don't work.

So who's at fault then? The user for losing control of their password? The small site, probably not EU based, doesn't give a shit? Or the big guys who tried to protect the user but failed? Given the way the GDPR is being done my guess is the big guys will get taken to the cleaners even though they did nothing wrong.

Basically, you can't stop a big company from getting hacked no matter how much you spend on security.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#434

Earlier quoted context omitted.

> In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked No, it boils down to an incentive . No company wants to get hacked, but a lot those same companies aren't willing to invest in security measures and training that could mitigate the risk. > Hacking is not a problem you can solve by passing a regulation that says "don't get hacked". I don't think anyone's propo…

But companies that do invest massively still get hacked. See: Google. Yahoo. Microsoft. It's also not even always clear what hacking actually means. A common way users get hacked is by reusing the same password on every website. One of those small sites gets hacked, the hackers try the users password at bigger sites to see if they work. Big players like Google and Facebook have heuristic systems that try to detect an…

> Basically, you can't stop a big company from getting hacked no matter how much you spend on security.

I never said anything to the contrary, but the observation is irrelevant. You can't stop all pollution, but that doesn't mean you shouldn't pass regulations that ether ban it or impose liability for it.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#435

Earlier quoted context omitted.

> All VW execs should be in prison for the rest of their lives for what they have done. You must point to the laws violated. E.g. Schmidt made a false statement to the California Air Resources Board under the Clean Air Act. Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law.

>You must point to the laws violated. E.g. Schmidt made a false statement to the California Air Resources Board under the Clean Air Act. >Trial in the court of opinion and mob lynching is not compatible with the Western tenements of law. Stop trying to shift goalposts, my point is that if any company deserved to be fined 4% of global turnover it's VW and they have currently received a total of $0 in fines even though…

I thought we established they received a non-zero dollar fine.

Their annual profit is about $13BN, they were fined $2.8BN which is about 22%. I think that along with imprisoning an exec that was complicit in the lie is a significant and reasonable deterrent/punishment.

As for VW significantly increasing the likelihood of any given arbitrary citizen getting cancer I'd love to see the numbers on that. Sounds like hyperbole to me[0]

[0] http://scienceblog.cancerresearchuk.org/2012/06/14/diesel-fu...

Re: GDPR: US news sites unavailable to EU users over data protection rules

#436
post #140

Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…

Cutting access in Europe does not solve anything. I'm living in US but I am European. Thus I can visit any of the above listed website they are processing my data, and GDPR applies to me. So they are not complying and I could file a complaint.

No that's not correct. GDPR applies if you are in Europe. So a US citizen in Poland is protected but a Polish citizen living in the US is not.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#437

Earlier quoted context omitted.

>I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents. I think by going to cars to prove your point proves how ridiculous regulation for websites are. For some reason there exists a group of people that believe that websites like facebook need regulations that are as…

My comparison is simply to show the standard laissez faire talking point of "oh, regulation exists just to protect incumbent market players" as bullshit: regulations exist to protect consumers from negligence and misbehaviour on the part of the companies. The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR. Equifax…

So now we get a new status quo: "These measures are onerous and bake in internationally-controversial concepts like 'right to be forgotten,' so now companies may actually decide to punt on doing business with 500 million customers because the risk outweighs the rewards.' "

Good work everyone.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#438

What if the US to passes a law that Americans are too fat and are no longer allowed to be sold gelato (they're allowed to buy gelato, but no longer allowed to be sold gelato), and then levy a multi-million dollar fine against every gelato shop in Italy where Americans visit on vacation. How is that different from the GDPR?

The difference is that one is an example of actual and well-thought out legislation in the EU which is generally welcomed by the people most affected by it: EU citizens.

The other is a trumped up example by someone on whom the GDPR self-admittedly has hardly any bearing but who still insists on throwing a hissy fit because legislation is somehow un-american or something.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#439
post #428

Earlier quoted context omitted.

To me it's overreach because smaller measures could have been a better first step, this won't help the problem much, and it hurts the non-targets. I understand it's why you asked your government to work on the problem. We just need to stop pretending that any way they work on the problem is a good one.

Smaller measures were taken. The Data Protection Directive was adopted in 1995 and hasn't worked at preventing EU citizens' human rights from being abused.

So using the law didn't work. What is a rational reaction? To try one of many other approaches? Of course not...draft and pass more laws, but bigger this time. If someone has a hammer and everything looks like a nail, all they are going to do when the hammer doesn't work is tweak the hammer. Instead of stepping back and saying that a provision in the law can be fixed here and there (e.g. requiring regulators to do something as if words are enough to usurp apathy), why not question whether the method in the first place is the problem?

Re: GDPR: US news sites unavailable to EU users over data protection rules

#440

Earlier quoted context omitted.

I guess it isn’t. There are laws which US considers to be broken by external entities, yet US introduces a comletely inhumane programme worth of DPRK. Where’s the logic.

[flagged]

Sure. But please remind me, how did we end up with VW case on a GDPR topic in the first place?
Post reply on HN