Live data from Hacker News

Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

gettingemaildelivered.com

81–90 of 140 posts

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#81

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

FWIW the first serious startup I worked at chose not to do CE compliance (the EU governing body for electronic devices that may interfere with RF). Thus we did not sell our product to Europe.

Every single blog post had a set of people raging that we were assholes for doing this, but the reality was the cost of compliance just didn't make sense for the MVP. It was high 5 figures in cost which was just too much at the time. If we had achieved product market fit then the obvious move would have been to do that compliance to gain more customers, but we never quite got there.

I doubt GDPR gets to that level of cost, so the ROI looks a bit different. But I still think it's a reasonable decision to say "I simply won't do business in the EU because it costs more than I'll gain". A lot of companies also don't bother to go through the effort of printing the dual language labels required to sell their products in Canada, even though it's a decent sized market close to the US.

Tech, specifically the internet, has grown without regulation for a long time. But that era is over. These kind of decisions are routine in non-internet businesses where distribution, borders, and regulations exist. I suspect we're going to have to think a lot more about this in our work in the future.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#82
post #71

Earlier quoted context omitted.

I'm sorry, but what part of the GDPR do you think demands invisibility? It doesn't even mention privacy because the GDPR stands of General Data PROTECTION Regulation.

the part where you are not allowed to profile the user based on a piece of information for which it is impossible to obtain consent (IP address). The law does not mention privacy, correct, but its entire rationale is based on the idea of privacy rights.

The IP itself isn't much use in the context of personal identifiable information with more data say from the person's internet provider. Also, having http logs with IP addresses (stored for a reasonable short amount of time) is still allowed as it is a necessity to provide any service at all.

The regulation isn't about fucking IP addresses, it's about big data collection information about, what you buy, where you go, who you are friends with and doing shady things with that data.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#83

Earlier quoted context omitted.

How will they do that to a company that has no presence in that country and is actively blocking any access from that country?

> How will they do that to a company that has no presence in that country and is actively blocking any access from that country? One of the EU's twenty-eight members will try to extradite an American executive. That will be shot down by U.S. courts. We'll throw tariffs at each other for a few months until whatever administration that happens under negotiates a compromise.

There is no extradition in civil offences. For example extradition under Europe Arrest Warrant require criminal offence carrying maximum panelty of >=1 year [1].

GDPR only fines and sanctions. Dont hold EU assets and you would be ok.

https://en.wikipedia.org/wiki/European_Arrest_Warrant

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#84

No. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.

Whenever I read "Blocking entire EU" I classify it as a romanticized revenge daydreaming. No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law. But: GDRP will filter out businesses that existed in t…

> No sane western corporation will willingly eliminate an entity about the site of USA

that's ridiculous, small companies grow by targeting audiences and computing expected future cash flow

the cost of legal action is a risk that affects the bottom line (it also affects reputation, but for new laws, the issue of reputation isn't as relevant because the laws haven't been tested by the society yet, they are fresh laws)

the idea that a corporation is "insane" for estimating the future cash flows and legal expenses for providing services to an audience is comedy

no, that's how a good, well-run, intelligent organization grows

the GDPR represents a risk to the bottom line when services are provided to European customers, and that risk must be factored in; this risk directly affects the corporate financial structure, and investors may have some input in terms of when and how to extend service to the EU

pretending that spite or some petty or small emotional frame of mind is required to apply basic sound financial principles of running a business is bizarre

when running a business, you are expected to win, and winning means not going bankrupt because some psycho lawyer in the EU wants to make money by destroying your reputation, destroying your life, and destroying your business

GDPR gives fuel to psycho lawyers. If you don't want to get sued by psycho lawyers, don't provide services to people who hire psycho lawyers, don't provide service to the EU.

If you have deep pockets and you know the expected cost of fighting off psycho lawyers is less than the expected revenue of providing service to the EU, then it may be time to expand to the EU; you and your investors should both have an understanding of the risks and rewards of expanding service.

Let me repeat: this is not an emotional matter, it is a matter of doing business.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#85
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Does your bank need to maintain a good relationship with European governments? If not, does it need to remain connected to banks that do?

That's not how most regulations work. If you are a chemical company selling something that is legal in the US but illegal in the EU, the EU doesn't use your bank to enforce their regulations on your business in the US.

Using the banks to cut off commerce across borders is an enforcement action for what countries agree are crimes - terrorism, money laundering, fraud, etc. It takes a lot of political willpower and negotiation to use that tool. I sincerely doubt it would be used against American websites that choose to not serve the EU.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#86
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

For U.S. companies that have a physical presence in the EU, the GDPR can be enforced directly.

For the other cases, EU uses intentional law. EU-U.S. Privacy Shield data sharing agreement for example.

In the case that the law can't be enforced directly against the violating company, EU can enforce it trough companies that provide the infrastructure for handling user data and have dealing with EU.

This includes trackers, online ad-selling companies, clouds providers, CDN provides, ISP's that have physical presence in EU and who handle user data when people visit the site. Like Google, FB, Amazon, cloufare, Akamai, Rackspace, Digital Ocean, ......

Also, if the company takes any money from the user from EU, they can get into trouble when banks with business in EU stop transferring payments.

Only if the company is handling all user data using companies with no EU presence and are not violating any US-EU privacy agreements, they should be safe.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#87
post #11
post #2

There's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?

Arrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...

[deleted]

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#88
This is a ridiculous interpretation of the law. Brought to you by some «experts» in Colorado.

If you had followed EU policy discussions over the last 10 years, you would realize this is about creating a single, unified online market.

Meaning a citizen living in Poland should have access to the same online services as a German, unless there are valid reasons for denying him.

Re: Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR

#89
post #65

Earlier quoted context omitted.

Imagine your country claiming taxes from you even though you are an ex-patriate and not living in that country. Oh, that does happen. You can't just build a firewall for data, especially as users will actually willingly export data. You look at the GDPR from a business side only and miss that it is about personal data and how that data has become a commodity that is being traded, mishandled and often abused. So far n…

> Oh, that does happen. That's based on international law, while there is no such thing about privacy

Actually it isn’t, in fact the US is kind of unique in that sense.
Post reply on HN