Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

551–560 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#551
post #102

Earlier quoted context omitted.

That looks fantastic, I would actually read USA Today if this lean site sticks around. If they want to monetize, publishers should control their own generic ad inventory (like they used to in old pre internet days) and ask for opt-in if you want customization. Easy on paper but hard in reality.

Apparently, WashPo prefers a more coercive method: https://www.washingtonpost.com/gdpr-consent/ Either pay or sell yourself. A gamble they might lose if people just stop sharing and click Washpo articles, but a possible route if others follow suit. Meanwhile, NPR goes more hardcore than even USA Today: https://text.npr.org I wonder, does that mean EU users are just a nuisance costing traffic, or that all graphics are…

What it means for me personally is that The Washinton Post as well as the NPR can't be relied upon for reporting news, since they are apparently unable to even marginally interpret a legal document aiming for clarity and instead channel their incompetence into snarky behaviour that still isn't compliant with the GDPR.

To wit (washpo):

"You consent to the use of cookies and tracking by us and third parties to provide you with personalized ads"

Where is the "No I don't. Just give me regular/random ads" button?

and,

"Premium EU subscription" "No on-site advertising or third-party ad tracking"

There's nothing specifically EU about that, in fact, it sounds like a good service to offer to all your readers. But still, there's a big difference between on-site advertising and third-party ad tracking, and that difference is at the heart of the GDPR. A half decent journalist could have figured that out. Maybe that's their real problem.

But most importantly, and frighteningly, instead of these two stunts being knee-jerk backlash reactions, maybe they're serious and most data-peddlers aren't shady figures in smoke-filled backrooms, but simply the fourth estate en large.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#552
post #355

Earlier quoted context omitted.

I am writing replies on GDPR topics the other way around ("I see you are from the US"). GDPR is a regulation for a topic which is important in the European societies. Not so much in the US (free capitalism) or China (social score).

I mean, fine. I'm not an EU citizen, I think GDPR is a pain in ass but ultimately is not my decision no matter how much I judge you all. But it does frustrate me that you all believe that GDPR will somehow be good for you. I've seen it said multiple times that when a massive American media company decides to pull out of the EU that a European alternative will emerge that is GDPR compliant and replace it. Do you actua…

The economist of GDPR compliance are a drop in the bucket for companies that already have compliance burdens that are actually not trivial.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#553
post #235

Earlier quoted context omitted.

You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.

>You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project. Where in your statement do you refute the fact that it is hard to comply with GDPR? Even if you have a legitimate use case you still need to provide users a way…

If you know what you're doing you know how store data in a GDPR-compliant way anyway.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#554
post #471

Earlier quoted context omitted.

> Which specific EU country would have jurisdiction over an interaction which took place in the US? OP’s country. The "place" that interaction took place in is irrelevant here, unless the company "doesn’t specifically target its services at individuals in the EU"; OP is citizen of an EU country so the GDPR rules apply. (edit: rephrasing)

That's not how jurisdiction normally works. A French citizen working within the US for a US company can't demand that they follow French employment regulations.

That depends entirely on how the lawmakers in question decide to act. Many countries claim jurisdiction over certain types of events occurring outside their own borders. E.g Belgium claims jurisdiction over human rights violations. Norway and many others claim worldwide jurisdiction over sexual abuse of children. The US claims jurisdictions to tax US citizens worldwide. The question tends to rather be whether or not they are able to enforce them, and so normally in such cases the practice is to only prosecute if the people involved are within your own borders.

Your example is flawed in that most countries that use these kind of mechanisms will tend to either require a extraterritorial jurisdiction to be written into the law, or will assume that only certain classes of crimes transcend jurisdictions. E.g. in the case of Norway, Norway has traditionally claimed extraterritorial jurisdiction over Norwegian citizens, but with the practice that things that are legal in the country you are in are generally not possible to prosecute in Norway unless there is a law that specifically claims extraterritorial jurisdiction (sexual abuse of children being one such example, where Norway may prosecute people who return from countries with weak or non-existent protection of children younger than the Norwegian age of consent).

In other words: It's how jurisdiction works if your courts wants it to work that way.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#555

Earlier quoted context omitted.

You should definitely wash the eggs before you cook with them. As you mention, that is de rigueur for Europeans, as it is in America for things like lettuce and potatoes.

What ? Is this legitimate or are you being funny ? I'm European and have never washed an egg before cooking it in my life. what is this ? I crack it open and cook it and am still here. I do wash my tomatoes when I make a salad with raw tomatoes though. And that's mostly to get stuff off since I'd argue my vinegrette would kill all the bacteria. And washing your potato ? I'm so confused. Don't we all cook potatoes in…

The incidence rate for salmonella is pretty low either way, but you should definitely wash eggs before cracking them open, for the same reasons you wash your tomatoes.

As for potatoes, no, we don't all cook them by boiling them in water -- many of us bake them, fry them, or use them for making hash browns. This might just be cultural, but I would actually be more inclined to wash them before boiling them, since the reason you wash potatoes is because they have dirt on them, and just as I wouldn't want to toss dirt into my boiling water, I would prefer to clean (or peel) my potatoes before boiling them.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#556
post #19

Earlier quoted context omitted.

You can still run a free website and be compliant with the GDPR. The EU/EEA is the largest market in the world, closing yourself for an market that size will hurt more than changing a few thing to be compliant.

* The EU/EEA is the largest market in the world* Define "largest" in this context.

Nevermind. I looked it up.

The European Union is 7% of the world's population.

So by "largest" he means "not largest," as in there's still 93% of the world left to do business with.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#557
post #534

Earlier quoted context omitted.

Not an ad-free version but you have to provide one without personalized ads being used. Non-personalized ads make far less money than personalized.

I see no reading of the GDPR that would lead you to that conclusion... The GDPR requires many things, but there's nothing in there that says you can't reject the customer if they don't opt-in to the things you want them to opt-in to. Do you have a citation from the GDPR that leads you to believe that I am wrong on that point?

https://gdpr-info.eu/recitals/no-43/

"Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance"

This is one of the core provisions.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#558
post #246

Earlier quoted context omitted.

The relevant part of GDPR is Recital 23. https://gdpr-info.eu/recitals/no-23/ Short version: GDPR does not apply if you happen to collect data on a few EU residents by accident (assuming you're not otherwise based in the EU).

This is only your opinion. It doesn't say that on the page you pasted. To be complaint you probably must clearly state that the service is not for EU resident and ask them to leave. Even that could be too little.

"...the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union [...] is insufficient to ascertain such intention"

Re: GDPR: US news sites unavailable to EU users over data protection rules

#559

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

The most interesting part of that website is its certificate. It includes 342 different news websites domains. There are many duplicates for the wildcards, but even 171 is a big number.

This just shows us how big and influential the media giants are becoming.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#560
post #530
post #527

Earlier quoted context omitted.

> https://eu.usatoday.com/ is fantastic, loads instantly, no clutter, smooth experience, I love it. I am willing to believe it to be someones idea of sarcasm, lets strip our website of all the "goodies", give viewers poorer experience and watch the cries!!1 Except its actually better, and I wouldnt be surprised if it vanishes really quickly once they realize it backfired by reminding users how fast and clean web once…

It force redirects me to www. on mobile for me :(

Same. But with adblock the USA version is a light page anyway.
Post reply on HN