4 ms·
Pretty sure WSJ is non-compliant to GDPR by not providing the option for EU readers to opt out of their cookie policy, ironic that that will be a reason for Tro
by efbb 8y ago
Pretty sure WSJ is non-compliant to GDPR by not providing the option for EU readers to opt out of their cookie policy, ironic that that will be a reason for Tronc blocking EU readers altogether.
- philfrasty 8y ago11 cookies for me
- downandout 8y agoGDPR doesn’t apply to WSJ or any other site that doesn’t “envisage” offering its services to users in the EU. See recital 23. Edit: apparently they accept EU currencies, which means they have subjected themselves to it.
- dekrg 8y agoWhat? It says the opposite - if you are providing services to EU residents outside of the EU GDPR applies to you. http://www.privacy-regulation.eu/en/recital-23-GDPR.htm http://www.privacy-regulation.eu/en/recital-23-GDPR.htm > In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment.
- downandout 8y agoYou completely ignored the relevant part of that recital: In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union If you are not “offering goods or services to data subjects who are in the Union” then you are not subject to GDPR. As stated in the recital, the mere fact that a site is accessible from within the EU DOES NOT make it subject to GDPR. This recital tells you the test that is used to determine whether or not you are. It isn’t necessarily even required to block EU traffic to be immune from it, though it’s a good idea since you’re playing with fire. You simply can’t translate your site to EU only languages, create content or services that might appeal specifically to EU residents, etc. No targeting of EU residents = no GDPR liability.
- tobltobs 8y agoThe WSJ offers an European Edition and the subscription link is open to users from the EU.
- dekrg 8y ago>No targeting of EU residents = no GDPR liability. I'm gonna have to disagree with that interpretation. If I can use their services from within EU then they are providing services to EU residents regardless whether or they explicitly say that they want EU customers and thus are subject to GDPR.
- downandout 8y agoRead the part of the recital that you seem to be ignoring on purpose for whatever reason. It literally says that the mere accessibility of a site from within the EU does not by itself mean that the site is offering services in the EU for the purposes of GDPR. It’s not really up for debate - it is written right there in black and white. I’ve been through this with actual lawyers. There are things you can do that make you subject to GDPR without explicitly saying you want EU customers - an example might be creating a site in English but that exclusively reports German news. But, for example, if you have a US news site that doesn’t sell subscriptions to EU citizens, isn’t based in the EU, doesn’t specialize in news arising from EU countries, and doesn’t translate its content to EU-only languages, you aren’t subject to it. Again, as stated in the recital, the mere fact that an EU resident can access the site does not by itself trigger GDPR exposure.
- dazilcher 8y ago> It says the opposite - if you are providing services to EU residents outside of the EU GDPR applies to you. What the GDPR says is irrelevant in sovereign countries outside EU jurisdiction. Or do you think NY hot dog cart vendors should also follow EU laws just because they happen to sell to EU citizens?
- letsgetphysITal 8y agoDoes the WSJ accept subscriptions from non-US citizens? If so, they had better get GDPR compliant.
- dazilcher 8y agoMake them. edit: (prove that GDPR has teeth outside the EU)
- degeberg 8y agoThey do '“envisage” offering its services to users in the EU'. That page has a massive ad (700x500 px) suggesting that I buy a subscription for "DKK10 FOR 3 MONTHS". If offering their service priced in the local currency of an EU member state doesn't constitute offering services to users in the EU, then I'm not sure what could possibly qualify.
- downandout 8y agoI’m not in the EU, so I wouldn’t have seen that. They’re stupid for doing that if that’s the case. If they’re accepting EU currencies, then you are correct that they have subjected themselves to GDPR. Go file a complaint, I assume your country will tag them for millions of euros in a hurry.
- ahofmann 8y agoWhere is it written that EU citizens can refuse cookies? As far as I know one must inform that cookies are stored and for what purpose.
- tobltobs 8y agoIf those cookies are not necessary for operating, like tracking cookies, you have to ask the user before you set the cookie. If you ask, you have to be specific for what the cookie is used. The checkbox or slider has not to be prechecked. You also have to provide a way to the user to withdraw his consent. And you have to keep an audit trail for the given consent.