9 ms·
Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
- beefhash 8y agoThere's still the issue of enforcement. If the operators and servers are all outside the EU, how would a user effectively get courts to enforce the GDPR?
- w_t_payne 8y agoExtradition?
- Hermel 8y agoExtradition treaties usually limit extradition to things that are punishable in both countries.
- namibj 8y agoBut not being able to step foot on European soil due to an outstanding bench warrant is at least severely inconvenient.
- cdoxsey 8y agoIts ridiculous on its face. European laws don't apply to American companies if they don't do business in Europe. It will become a major international incident if people try to do this.
- deleted 8y ago[deleted]
- Bizarro 8y agoYes, extradition for EU officials who try to enforce illegal lawss against the citizens of sovereign nations.
- kuschku 8y agoBy that rule we’d have to arrest all US officials, for constantly interfering in Europe. Stuff like https://www.reddit.com/r/technology/comments/ka26b/paypal_blackmails_one_of_the_three_major_german/https://www.heise.de/newsticker/meldung/Lassen-uns-nicht-erpressen-Rossmann-schmeisst-Paypal-raus-1340041.html https://www.reddit.com/r/technology/comments/ka26b/paypal_bl... (a german company, in germany, selling cuban cigars, to a german, got as result threats from their payment processors (US companies)). Or cases like this https://en.wikipedia.org/wiki/Society_for_Worldwide_Interbank_Financial_Telecommunication#U.S._control_over_transactions_within_the_EU https://en.wikipedia.org/wiki/Society_for_Worldwide_Interban... The US has constantly stolen money from EU citizen doing business in the EU for violating US laws. And then there’s the Kim Dotcom case. Also similar story, US enforcing US law in New Zealand and Germany. The US deserves some of its own medicine.
- majewsky 8y agoIf the company does not have a data protection officer (or if the DPO doesn't comply with users' requests), users can go to their national government's data protection regulator. No need to go to court.
- Rjevski 8y agoYes but what will that regulator do once they determine the foreign government in which the offense occurred is indeed guilty?
- JumpCrisscross 8y ago> how would a user effectively get courts to enforce the GDPR? Most Americans would prefer not to have European court judgments against them. That said, I agree this is absurd. If I choose to do business in your country, that is one thing. But extending that to blocking my right not to do business in your jurisdiction is silly.
- CM30 8y agoArrests when an operator visits an EU country? I mean, that's how the US seems to get gambling company CEOs and internet betting site operators...
- Zak 8y agoI find it pretty problematic that the US does that to gambling site operators. People who do things that are legal where they live should not have to fear that they'll get arrested when they visit a foreign country just because those things are not legal in that country.
- deleted 8y ago[deleted]
- DanBC 8y agoIs anything in GDPR an arrestable offence?
- namibj 8y agoNot paying, and getting a bench warrant for an overdue fine?
- Bizarro 8y agoArrest for EU bureaucrats for when they go outside the EU for trying to enforce unlawful laws?
- TomK32 8y agoIt's not the EU but the member states that are enforcing the regulation. They are also free to make minor changes to the regulation (e.g. Austria won't allow NGOs to make complaints and releases state-run companies from the regulation's duties).
- deleted 8y ago[deleted]
- closeparen 8y agoDoes your bank need to maintain a good relationship with European governments? If not, does it need to remain connected to banks that do?
- krschultz 8y agoThat's not how most regulations work. If you are a chemical company selling something that is legal in the US but illegal in the EU, the EU doesn't use your bank to enforce their regulations on your business in the US. Using the banks to cut off commerce across borders is an enforcement action for what countries agree are crimes - terrorism, money laundering, fraud, etc. It takes a lot of political willpower and negotiation to use that tool. I sincerely doubt it would be used against American websites that choose to not serve the EU.
- kuschku 8y agoThe US used this against Rossmann GmbH, which was a German company, in Germany, selling cuban cigars to a German. And they got cut off from PayPal, and the credit card networks for quite a while. If the US can use it for selling a product in a store that’s entirely legal to sell under EU law, then the EU can also use the same rules for GDPR.
- deleted 8y ago[deleted]
- krschultz 8y agoThat's a perfect illustration of my point. The US went to pretty great lengths to have specific bans on import / export from Cuba. German train companies build plenty of things that would not meet FRA standards in the US, the US does nothing about it. But Cuba is seen as a special case. So do you think GDPR and PII are more like Cuba and terrorism, or more like chemicals and transportation standards? I think the latter.
- closeparen 8y ago
- Bizarro 8y agoThere is no enforcement because if GDPR claims that it has jurisdiction over entities not having physical presence in the EU, then the law isn't lawful to begin with. And if the EU started going after companies/individuals who don't have presence in the EU because they claim "we say so", well, then the rest of the world can play that game to. Maybe the rest of the world will put sanctions on EU bureaucrats if EU bureaucrats start trying to shake down companies that have no presence in the EU.
- Nokinside 8y agoFor U.S. companies that have a physical presence in the EU, the GDPR can be enforced directly. For the other cases, EU uses intentional law. EU-U.S. Privacy Shield data sharing agreement for example. In the case that the law can't be enforced directly against the violating company, EU can enforce it trough companies that provide the infrastructure for handling user data and have dealing with EU. This includes trackers, online ad-selling companies, clouds providers, CDN provides, ISP's that have physical presence in EU and who handle user data when people visit the site. Like Google, FB, Amazon, cloufare, Akamai, Rackspace, Digital Ocean, ...... Also, if the company takes any money from the user from EU, they can get into trouble when banks with business in EU stop transferring payments. Only if the company is handling all user data using companies with no EU presence and are not violating any US-EU privacy agreements, they should be safe.
- eksu 8y agoThe E.U. has no legal authority or enforcement mechanism to stop foreign, online companies from not doing business in the E.U.
- TomK32 8y agoIt's NOT about stopping them from doing business, it's about businesses taking personal data more serious. E.g. the right to be forgotten, EU has it US doesn't. sanctions when you forget to disclose a massive data-leak on your private escort website? $0 in the US, hopefully very expensive in the EU. Your nemesis publishes lies on the net? EU helps you have that deleted. Your supermarket tracks your shopping and knows you are pregnant before you do (this happened in the UK!), won't happen anymore in the EU. Shady Sunshine Ltd bought your email address and purchase data to spam you, bad and expensive for them. facebook won't allow you to continue unless you agree to face-recognition? This might be the first case in courts. Wait and see for the good sides once the panic has quieted down.
- gizmo686 8y agoThats all well and good. However, if a company chooses not to do bussiness in the EU, then it does not matter what the GDPR says; even if the mechanism they use to block the EU violates the GDPR.
- rdl 8y agoI predict secretive offshore entities which exploit activities banned under GDPR which have sufficient economic value. Entities which are essentially judgment proof in EU. Maybe directly affiliated with a foreign government. Being able to do certain kinds of background checks or financial risk calculations is the first use case which comes to mind.
- joshuamorton 8y agoNo. (Usual caveats, not a lawyer, not an expert). If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't. Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant. I think blocking the entire EU is lazy, but this is the non-est of nonsense.
- MatthewWilkes 8y agoIP address is PII, though. The fact that you're processing it into broader categories in order to make an automated decision is neither here nor there. Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these logs indefinitely as if they weren't sensitive.
- eganist 8y ago> IP address is PII, though. Your premise appears to be flawed in the context of established case law. IP addresses alone are not considered 'personal data' unless you have the capacity to readily add other information to add color. See below: https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-... > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and > 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. > On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD. The vast majority of entities do not meet the requirements for #2.
- MatthewWilkes 8y agoFair point. Pretty much all of my data protection work recently has been with sites that can identify the person, sorry, I let thay context affect what I said. That said, doesn't this assume the user has a dynamic IP address? You can't easily tell a dynamic from a static, so wouldn't you have to plan for the worst?
- majewsky 8y agoIs it intentional that the site is blank for me (in the EU), or is their JS just crap?
- StreamBright 8y agoI guess the site got hackernewsd (old lingo is slashdotted).
- dahdum 8y agoSo the GDPR was vague, and while I would say poorly written, many have claimed that the EU will focus more on the spirit of the law vs the law itself. Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law? I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies because of GDPR.
- JumpCrisscross 8y ago> Anyone really believe they’ll litigate against companies that block them entirely? All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.
- dasil003 8y agoHow will they do that to a company that has no presence in that country and is actively blocking any access from that country?
- JumpCrisscross 8y ago> How will they do that to a company that has no presence in that country and is actively blocking any access from that country? One of the EU's twenty-eight members will try to extradite an American executive. That will be shot down by U.S. courts. We'll throw tariffs at each other for a few months until whatever administration that happens under negotiates a compromise.
- wtfstatists 8y agoThere is no extradition in civil offences. For example extradition under Europe Arrest Warrant require criminal offence carrying maximum panelty of >=1 year [1]. GDPR only fines and sanctions. Dont hold EU assets and you would be ok. https://en.wikipedia.org/wiki/European_Arrest_Warrant https://en.wikipedia.org/wiki/European_Arrest_Warrant
- gizmo686 8y agoAssuming the article is correct in its interperatation of the law, it is still missing the point. If you do neot operate out of, or do business in, the EU, then the EU has no claim for jurisdiction. The only simmilar case I can think of is the Isreali law which prohibits entry into the country by anyone supporting BDS. Notably, in this case they are not even claiming that everyone on the planet is required to not support BDS; because it is obvious that they have no jurisdiction to do so. EDIT: You also have China and Saudi Arabia who have internet restrictions. However, they also do not claim jurisdiction over foreign sites. They only require compliance by sites that operate within their jurisdiction; and have built the infrastructure to enforce their digital border.
- MatthewWilkes 8y agoThen why block the EU to begin with? The argument is clear, blocking users is not a panacea.
- gizmo686 8y agoBecause if you do not block the EU then the EU can claim to have jurisdiction.
- johnchristopher 8y agoExcept the purpose of that block is clearly defined and it doesn't need to store personnal/private data to work.
- marcoperaza 8y agoYou can’t force people to operate in your country. The EU does not have sovereignty over the whole world. This is nonsense and is certainly not what is contemplated by the law. Making it undesirable for some businesses to operate in your country is part of the cost-benefit analysis you have to do when passing laws.
- Bizarro 8y agoThe EU is overplaying its hand by claiming global sovereignty. If the EU really wants to play hard ball, the rest of the world can impose sanctions against the EU and bureaucrats who try to enforce illegal laws
- mbroncano 8y agoNobody is claiming global anything, the rest of the world is not the US, and illegal law is an oximoron.
- eivindga 8y agoYou guys really dont understand this law. Or how it is going to be enforced. EU will regulate what businesses doing business in the EU can do. All other talk is just noise.
- eganist 8y agoSite got hugged. Google cache: http://webcache.googleusercontent.com/search?q=cache:www.gettingemaildelivered.com/why-you-cant-just-block-eu-visitors-eu-customers-or-any-eu-traffic-under-gdpr&strip=1 http://webcache.googleusercontent.com/search?q=cache:www.get... In short: the opinion expressed by that link appears to be plainly wrong as the organization using IP addresses to restrict EU traffic for the sake of GDPR would need the ability to actually identify people from that information, a power arising from access to other information. The vast majority of entities lack that additional, so for them, IP addresses are not 'personal data' under existing case law. In long: I'm not providing legal advice, only forwarding details (again, non-representative) conversations I've had or been party to with various lawyers on this topic. Notably: the consensus opinion is that determining a potential IP range is specific to the EU is not the same as geolocating them as that location information is not specific enough to determine who the person is, and partly as a result of a lack of this capability and others, IP addresses cannot alone be determined to be personal data. Related: https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-... > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and > 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. > On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD. By precedent (unless I'm missing more recent case law), for the vast majority of entities possessing IP addresses e.g. through request logs, an IP address is not "personal data," and determining the continental whereabouts of an IP would therefore not be considered "profiling." I'm not a lawyer; I'm only relaying what's come up in conversation between attorneys covering the topic. I'm open to seeing the position I'm relaying above proven wrong.
- zerostar07 8y agoSomeone on reddit noted that this may be true for one more reason: the law does not allow automatic profiling of the user (Article 22) > The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
- deleted 8y ago[deleted]
- x0x0 8y agoThat quote is incoherent. Your quote -- clause 1 from A22 -- indeed points out that profiling is permitted under circumstances enumerated at the end. Further, the GDPR has rules around two things you mention, but they are different: (1) profiling; (2) automated decision making. Profiling has three elements, as described by the A29 WG: * An automated form of processing. * Carried out on personal data. * For the objective of evaluating personal aspects about a natural person. As for IP addresses, mapping them to an ASN is fully anonymized. Since an anonymized IP address is not personal data, using it is not profiling. Blocking users from using your site is highly unlikely to have the "legal effects" enumerated in the above clause.
- eganist 8y ago"Article 4 (4): ‘profiling’ means any form of automated processing of personal data" CJEU case law has determined that IP addresses are not considered "personal data" except in certain cases (https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...) > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and > 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. > On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD. The vast majority of entities do not meet the requirements for #2. Therefore, automatic profiling rules could not apply since the automatic analysis being performed is not against personal data.
- ddtaylor 8y agoJuristiction. By this same logic you have to comply by the rules of the Great Firewall of China.
- ceejayoz 8y agoOr Saudi Arabia's content rules.
- shiado 8y agoAs somebody who values privacy greatly something about the GDPR just doesn't sit right with me, which is confusing and conflicting because somebody who values privacy should be naturally aligned with it. After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves. Imagine if China decided that Chinese citizens accessing foreign servers was a breach of national security due to the ability of these foreign servers to collect private browsing information, and imagine if China decided to make laws that fined these foreign entities in violation of their laws. It would be a fucking joke and it would be ridiculed internationally for good reason. China obviously knows this and they are prepared to get their hands dirty and implement the Great Firewall of China because they have no problem appearing as a controlling and authoritarian state. So why doesn't Europe just do what China does and build their own firewall? If they really wanted to restrict collection by foreign servers which exist in non-EU jurisdictions and apply the regulation internally in the EU then they have the technical capacity to do so with a firewall. Europe just can't bare the consequences of building such a firewall because it would destroy them in the court of public opinion. If EU citizens suddenly lost access to American services all hell would break loose. On a more political level the EU is a place which is generally known as being liberal and open and the construction of a mechanism designed to enforce their regulations by closing them off from the outside internet would be the construction of an authoritarian tool of censorship and restriction of freedom.
- zerostar07 8y agoAs an EU citizen I agree. Also, GDPR is problematic because it confuses privacy with invisibility. I hope this problematic law is amended soon.
- TomK32 8y agoI'm sorry, but what part of the GDPR do you think demands invisibility? It doesn't even mention privacy because the GDPR stands of General Data PROTECTION Regulation.
- verdverm 8y agoWhat happens when an EU citizen travels to the US and accesses a website?
- labster 8y agoU.S. law applies, just like normal, unless the website is located in the EU. The EU claiming jurisdiction over transactions entirely in another country would be a major breach of sovereignty, which is why the law uses the phrase "data subjects in the Union". Note that EU law does apply for visitors, so look forward to data tourism!
- MaikuMori 8y agoI'm a traveler, just because I'm not coming from EU IP address range, doesn't mean I'm not EU citizen with rights established by EU.
- zerostar07 8y agothats in general false, you cant claim legal protections in every territory on earth and beyond.
- Silhouette 8y agoThe GDPR's scope is based on geography, not citizenship. If you're an EU citizen currently in the US, you do not necessarily enjoy whatever rights and protections the GDPR might offer you if you were within the EU. If you're a US citizen currently in the EU, you do enjoy those protections.
- MaikuMori 8y agoHmm, that's interesting, I was convinced it's based on citizenship.
- Silhouette 8y agoIt's a common misconception, and has been widely reported even in the mainstream media. FYI it's Article 3 of the GDPR that specifies the territorial scope authoritatively. Fun fact: The word "citizen" doesn't actually appear in the GDPR at all.
- zenovision 8y agoI have ~600 small business customers from the EU who are using my SaaS product and until now I received zero requests regarding GDPR. It seems it was the right decision to ignore this law, because no one cares about it. The same thing was with the cookie banner. Never built it into the product and in 6 years not even a single person asked about it...
- zerostar07 8y agoif you 're likely to receive requests, you re most likely to receive them now that gdpr is in the news.
- TomK32 8y agoSimple advise: If ever anyone asks: Be active and responsive. But remember: The GDPR protects people's data. Companies aren't people (at least in the EU).
- taejo 8y agoThe GDPR has been in effect for less than three days, two of which have been weekend. A bit premature to say, "nobody's enforcing this law", isn't it? The cookie banner is different because everyone knew it was completely meaningless. Whether GDPR is or not remains to be seen; it's certainly not an "everybody knows" situation yet.
- JumpCrisscross 8y agoThere is a lot of discussion about GDPR from an American perspective. I'm curious about the Chinese one. Does the EU really expect Baidu, WeChat and Tencent to comply with these rules? Or is this just a roundabout way of extracting bureaucratic benefits from American technology companies?
- eivindga 8y agoYes, of course. If they do business in the eu, they will need to comply. If they don’t do business in EU, then they dont have to follow eu rules.
- deleted 8y ago[deleted]
- JumpCrisscross 8y agoIf Facebook certifies deletion of certain data, and somebody doesn't believe them, they can sue in an American court. If WeChat certifies deletion of certain data, and somebody doesn't believe them, they're SOL.
- joejerryronnie 8y agoHa! Good luck getting a single euro out of China! We've already seen the EU roll over when Russia's energy giant Gazprom applied a little pressure.
- jon__k 8y agoWhy are most companies (i.e. USAToday complying) when they have no market, interest, or presence in the EU?
- eivindga 8y agoThis is a ridiculous interpretation of the law. Brought to you by some «experts» in Colorado. If you had followed EU policy discussions over the last 10 years, you would realize this is about creating a single, unified online market. Meaning a citizen living in Poland should have access to the same online services as a German, unless there are valid reasons for denying him.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- IshKebab 8y agoThis is a clear mis-reading of the law. Look at the examples that you can't use profiling (including geo-IP) for: > which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention. Blocking someone from reading a news website is clearly not a decision along these lines. Obviously this would need to be tested in court, but I would bet on it being allowed. Also, the GDPR only applies at all if the business operates in the EU. If they clearly don't (e.g. by blocking European visitors) then the GDPR does not apply and you obviously can't use text in the GDPR itself to prove that you can't do that. This article is nonsense.
- wildguyd 8y agoignore the gettingmaildelivered blog... one certainly can take active measures to exclude EU visitors as a way of avoiding scope of GDPR. Get real legal advice if curious rather than relying on a blog.
- wildguyd 8y agorest assured you would not see major newspapers doing exactly that without them having checked the legality. The analysis in the blog is wrong because the first question to be asked is "is the business within the scope of the GDPR", and _if you are a business in scope_, then you can't process personal data or track/monitor EU residents. However, you are not a business in scope of GDPR if you don't have a business presence in the EU and don't hold out your services to EU residents. Blocking that region demonstrates clear intent _not_ to offer services to EU residents and thus puts your business out of GDPR scope.