Live data from Hacker News

GDPR: US news sites unavailable to EU users over data protection rules

bbc.com

621–630 of 680 posts

Re: GDPR: US news sites unavailable to EU users over data protection rules

#621

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

Same with npr! https://text.npr.org/ It's brilliant

That's more of a fallback in disasters to get important information out to the public. Here is CNN's in english and Spanish.

http://lite.cnn.io http://lite.cnn.io/es

If anyone knows of more let us know.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#622

Alternatively there's this: https://eu.usatoday.com/ No ads, no tracking, no cookies, not even Javascript. Just plain HTML+CSS and JPEG images. The whole front page is around 650 KByte, and by far most of this is in the image files. As a result the page looks very clean and loads very fast. This is what all news web sites should look like, not just for EU readers (although I fear that this is just a temporary solutio…

US users who want the same, lovely, experience can route via Europe (for now).

I just did and it's such a fantastic user experience.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#623

Earlier quoted context omitted.

Your business model's success is not "providing the service". EDIT: Quoth the British agency responsible for implementation: "The processing must be necessary to deliver your side of the contract with this particular person. If the processing is only necessary to maintain your business model more generally, this lawful basis will not apply and you should consider another lawful basis, such as legitimate interests." h…

Thank you for the citation; this is an interesting and useful discussion. The contract that Facebook has with its users is not merely to serve as their social media platform. The contract includes personalized advertising. Facebook, in the terms of their contract with you, give you X in exchange for Y. X is the social media platform. Y is personalized advertising. This is the contract. AFAICT from the GDPR, they don'…

From same source: "The processing must be necessary to deliver your side of the contract with this particular person."

That is - these regulations refer to the performance of a contract by the service provider. If the data isn't necessary for creating the sandwich, you're not allowed to deny use of the service based on the user not giving you the data.

GDPR was specifically written by smart lawyers and regulators to prohibit the specific kind of contract you're describing. The whole point of regulations like this (also minimum wage, regulation of arbitration agreements, etc.) is to limit the kinds of contracts people can enter into.

Specifically, they're allowed to consent to give you that data, but that's not allowed to be a condition for the use of the service.

EDIT: More specific sourcing on the way that GDPR regulates contracts, in Article 7(2): "Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding."

EDIT 2: And in fact, we've gone in a circle. Again, as Recital 43 states: "Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance."

This is all super crystal clear, by design.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#624

Earlier quoted context omitted.

Well then these EU users are illegally accessing a computer and have broken the computer fraud and abuse act. These users should be prosecuted to the fullest extent in the US for their illegal computer usage.

Eh, I'm not sure we want to go down that road either, but it's an interesting thought experiment. If you declare that EU visitors are unwelcome and unauthorized, are they violating the law by working around that? I find the idea both horrifying and interesting. So many GDPR fans here seem outraged at sites blocking access to them, which seems an acknowledgement that they want to have their cake and eat it too. What i…

Yeah, I was mostly making my comment in jest, and I find the idea ridiculous.

But I ALSO find it just as ridiculous to prosecute companies for not providing protections to users that they have banned.

It should be fully within everyone's rights to not do business with countries that make silly laws.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#625
post #502

Earlier quoted context omitted.

Your point is that apache default config is horrendous regarding log keeping policy ? I agree.

I know! Just imagine...your (likely dynamic) IP address exists in forgotten log files all over the web. The horror! One of the most annoying things about the GDPR fandom is the black and white nature it seems to inevitably take. If your log files store IP addresses, you're clearly evil and shady and are violating human rights, just as bad as if you're recording people's conversations at home with the intent to depriv…

you can log ip adresses. keeping them forever is bad.

It means that any future government, no matter how evil it is, could query your log and know precisely what I am doing on the internet right now. I might not want that.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#626

Earlier quoted context omitted.

Yes, and this is the decision that Facebook and Google have made. They will only operate for users that have given their consent, and have chosen not to do business with those who do not. Isn't this what you want? They are fully complying with the law and only doing business with people who have consented.

What decision have they made? I'm fairly sure they both will be compliant. > They will only operate for users that have given their consent Well, they can't. It's not their choice to make anymore: users in the EU can no longer sign their online privacy away. If that is not something a company can live with, they should be looking for darker pastures elsewhere.

> they should look for darker pastures elsewhere

I honestly hope they do this. Every EU citizens should have their FB accounts, Gmail accounts, and all other internet services deleted, and then blocked from the majority of internet services.

Then those citizens can decide if it was all worth it.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#627

Facebook, Google, Instagram and WhatsApp are accused of forcing users to consent to targeted advertising to use the services. Privacy group noyb.eu, led by activist Max Schrems, said people were not being given a "free choice". I mean, that just isn't a valid complaint IMO. You have a choice -- you can not use Facebook, or not use Google, or not use Instagram, or not use WhatsApp. If you're using a "free" service tha…

Then you don't understand the most fundamental thing about the GDPR: "Kopplungsverbot" (german privacy law had that for ages before GDPR). You can't force someone to consent to marketing because he wants to use your service. Everything that is not part of the core service needs consent that can be withdrawn at every time. The core service of facebook is access to the network, not that my data is processed to show me…

That is insane. As a private company they have the right to do business with whom they please. If a company refuses service because a potiential customer doesn't agree to their term, it is the companies right. No one is entitled to a good or service of some one else.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#628

Earlier quoted context omitted.

By hosting non-tracking ads. Like they used to be before Google started this whole profiling menace.

I keep seeing this argument. But the reason I don't see this happening is the giant amount of fraud out there. Sure ad fraud is an arms race, but if you can't do js fingerprinting, cookies, etc it would be impossible to verify ad impressions are real humans, not bots. And actual clicks from real humans would be impossible to differentiate - not coming from the same bot clicking over and over again (can't store ip, co…

Sure you could store IPs, as you can also use cookies. I think there's a hysteria regarding GDPR. It won't break the web. Perhaps we need to give it some time to settle in and then draw our conclusions.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#629

Earlier quoted context omitted.

They can also be quite smart. What was your referrer, what's your user flow through the site, what do similar users do when arriving from the same pages and searches? What time of day is it for the visitor? ie: figure out why they are doing what they're doing and direct them to ads that capture that intent.

I'm not certain but much of that sounds like the kind of information GDPR doesn't let you use like that.

Why? None of it requires saving info on an individual server-side. As long as you don't do that the GDPR doesn't even apply to you.

Re: GDPR: US news sites unavailable to EU users over data protection rules

#630

Earlier quoted context omitted.

> You don't need to be a GDPR compliance expert to know that the costs of implementing GDPR are huge So you don't actually know anything, but you are going to pretend to know that it's "huge". > I doubt any GDPR experts actually even exist today Then why be so condescending and pretend that you are actually one?

You only have had to gone through the implementation challenges personally to know that it’s hard and the costs (to do it by the letter) are high. In fact to do it by the letter you’re going to have to hire a law firm to ensure you’re compliant and they’re going to err on the side of caution and take you down a rabbit hole of implementation changes.

Can you give me a concrete example where the GDPR forces you to do a lot of relatively costly stuff that are not worth doing otherwise?
Post reply on HN