3 ms·
(Starting with the caveat that I’m not hugely well-versed in the GDPR:) I think that actively soliciting personal data from people (wherever they may be) and c
by robjwells 9y ago
(Starting with the caveat that I’m not hugely well-versed in the GDPR:)
I think that actively soliciting personal data from people (wherever they may be) and collecting or processing it entails a higher level of responsibility. The GDPR in that situation effectively says: if you want to collect or process data on EU citizens you have to follow some rules.
I don’t believe that simply publishing a document online, for anyone who may wish to see it, has that “active character.”
However, others have pointed out that offering the Gutenberg website in a German translation is a similar act. I do think this is arguable, and this point does appear in the court ruling:
> “Apart from that, the first defendant’s website is also intended to target German users. This is supported by the fact that the website is partially in German, that the site offers German-language works, and that the first defendant explicitly strives to make the works available globally” [from the English translation]
However, going back to my point earlier, my concern is with the idea of making the website “publicly accessible in Germany.” I think there is a disconnect here between the understanding of traditional publishing (where it takes effort to publish abroad) and internet publishing (where it takes effort to prevent access from abroad).
I worry about the chilling effect of such a ruling. Should I, out of an abundance of caution, only make my blog available to readers in the UK (where I am, and where my blog is hosted)? I think it is easy to see what the effects of such a ruling could be, and (take to their logical conclusion) would have a severely detrimental effect on information exchange via the internet.
- piotrkaminski 9y ago(Thanks for the well-reasoned reply! I'll preface mine by saying that I'm not terribly well-versed in the GDPR either... and that's really part of the problem.) AFAICT, the GDPR consider an IP address to be PII. So collecting visitor logs or sticking an analytics script on the page -- even without asking people to sign in or otherwise identify themselves -- would fall under the purview of the GDPR. I don't think doing such things should cross the line into "active character". It's also a terrible idea to infer intent from offering translations in other languages. As another comment pointed out (I presume correctly) there are more German speakers outside Germany than there are within its borders. Why should trying to improve the accessibility of a web site by people around the world make one susceptible to the laws of a language's native country? As you say, the implied end state is the real problem: do I now need to learn about the relevant laws of every country whose residents (or even citizens?) might visit my web site? That's regulation without representation, and should be resisted on principle IMHO. Or will every site need a standard disclaimer that it's only intended for residents of X? Perhaps some creative lawyer will figure out how to add a clause to Terms of Use that shifts responsibility for damages incurred by exposure to extraterritorial laws to the offending (offended?) user, and we can have a detente through mutually assured destruction of dueling lawsuits. :) And just to preempt any criticism from the European peanut gallery, I'm in favor of stronger privacy protections on the Internet but they need to be worked out and agreed on globally, not imposed unilaterally by claiming extraterritorial jurisdiction.