5 ms·
Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on ar
by CorpOverreach 8y ago
Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me?
What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?
- kuschku 8y agoThe most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.
- paulddraper 8y agoFrightening to think something as innoculus as making a website of chocolate chip recipes and logging visitor IPs could provoke that.
- tzahola 8y agoTip: don’t log the IPs then.
- ovao 8y agoWhich is relatively easy when you’ve written the software stack powering the recipe site, or can at least grok its source (if available). It may not A) be clear to the operator of a recipe site that their stack is logging IPs and B) be reasonably straightforward for the owner of a recipe site to stop their software from doing so. Some things are very deliberate, but others are the consequence of decisions far removed from those of site operators.
- reificator 8y agoI spin up a Wordpress site with default options to host my chocolate chip recipes. Is it GDPR compliant? I go through and toggle all the settings the internet tells me to, even though I don't know their meaning or effect. Am I GDPR compliant? I install a Wordpress plugin that sets up a Really Simple Chocolate Chip Syndication server, or RSCCS. That plugin logs IPs. If I was GDPR compliant previously, now I'm not, and how would I ever know?
- ams6110 8y agoIf you don't know what you're doing, don't involve others.
- reificator 8y agoSince I don't quite get the point you're making here, I think I should specify that I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word. Expecting them to know that starting a website with a plug and play webserver could collect sensitive information on their behalf is pushing it a bit. Expecting them to know they have to comply with a law passed by a governing body they've never come within 1k miles of...
- majewsky 8y ago> I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.
- reificator 8y agoWhile I agree, if you're an American setting up a plug-and-play site with chocolate chip cookie recipes, that happens to collect data out of the box, where along the process are you going to realize that you even need to know anything about EU regulations? I've never hired a Wumbologist because I don't know what Wumbology is or where it applies.
- redblacktree 8y ago> > I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. > If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer. This attitude is really sad to me. It was and is one of the greatest things about the internet, that pretty much anyone anywhere could publish something. If you now need an "expert" to do that, we've lost something.
- tscs37 8y agoYour chocolate chip recipe website will have to be compliant to a number of laws, GDPR isn't the only law in the internet.
- GordonS 8y agoIt wouldn't, that's just pure FUD.
- Bizarro 8y agoThat's a very unlikely "solution" and is not going to happen unless the EU wants retribution in some form from the rest of the world.
- kuschku 8y agoAs mentioned, this is the retribution. The US has been enforcing their laws on the rest of the world with equally radical methods for many years already.
- chrononaut 8y agoI always found this interesting because surely no matter what effort you go through to prevent yourself from providing your service to EU citizens, you're probably going to collect enough information to be subjected to GDPR during the period where you did not remotely know a set of users were EU citizens. (e.g., those residing overseas, traveling, etc) And then -- what if you finally have confirmation? You were attempting to avoid it, but now you cannot. If your attempt is to avoid it at all costs, you're effectively required to validate whether users are EU citizens much earlier in the process than before GDPR, which means GDPR already has had a big impact despite efforts to avoid its umbrella.
- zenovision 8y agoAt the moment there is no way the EU can enforce you to comply with that law, unless you have a subsidiary in the EU. Only if USA sign a special agreement with the EU this may change, but I don't think this will ever happen (very unlikely). Otherwise every country on planet can create their own draconian laws and expect that every single company in the world comply with it...
- saf2002 8y agothis is true, but kinda pointless, you are not gonna fight the EU over this... Several countries in the EU (UK, Ireland, ...) can assign personal liability for intentionally ignoring privacy law, in which case someone in your company is basically going to end up a wanted man in Europe
- paulddraper 8y ago> Several countries in the EU (UK, Ireland, ...) UK is not part of the EU. > assign personal liability Citation needed? If CEO decides to ignore privacy law, everyone else is accountable?
- sebow 8y agowell technically you're kind of operating on 2 continents,mainly because you're storing data about an EU citizen on your servers located in US. Since the data is originating from an EU citizen,i assume the GDPR is making sure you at least inform the user of the data collection. Also consider that GDPR is kind of a TOS for connecting with an EU citizen,some sort of a "copyright" system. As an EU citizen, "cheap" wourkarounds like these ones will definitely not solve the problem, might actually make it worse.It's like an anti-adblocker, it won't work on the long run,people who are tech literate enough will just start using a VPN
- jwilliams 8y agoInternational enforcement is a can of worms. However, a lot of it is covered by: 1- US companies with a physical presence in the EU. They can fine that entity directly. 2- US companies will find they can't sell to EU businesses (B2B), as that means the EU company is carrying the can in terms of non-compliance. 3- The EU Member State could go via the International Courts. Or via some kind of bilateral agreement (e.g. Privacy Shield). I expect #3 will need to egregious to really make sense. However, I also expect a significant amount is already hovered up by #1 or #2. Certainly many of the cases that GDPR wants to target. Additionally, the EU may cut deals with other states to bring in enforcement powers (fines).
- mkagenius 8y agoSeems this is targeted mainly to the likes of uber, google.. small time websites who do not have much volume aren’t the target audience.
- deleted 8y ago[deleted]
- Bizarro 8y agoDespite the propaganda flying around HN for known political purposes, they can't and won't arrest you because there is no jurisdiction unless you have operations in the EU.