6 ms·
Or maybe just revenue from eu < cost to comply
by thisgoodlife 8y ago
Or maybe just revenue from eu < cost to comply
- pmlnr 8y agocost to comply is not to log data of the same users they are showing the blockade right now. I fail to see how that's so expensive to do.
- chrismeller 8y agoNo, that's not the only requirement. At the very least there are additional record keeping steps, policies and procedures to draft, the appointment of a DPO that responds to requests for access or erasure, and the development of the features to fulfill both of those requests. Not to mention the potential risk of doing any of that wrong and dealing with the fallout if you get called on it. One of the sites on this list is the Aiken Standard. We're talking a local newspaper serving Aiken, SC - a city of less than 30,000 people. Even if an EU citizen (or someone traveling in the EU) cared about their local news, it's simply not worth it - that's not their audience.
- Drakim 8y agoWait, hold on, do you really need to do any of that if you are keeping zero data on people? I assume that kinda organization is only relevant if you are keeping data.
- IanCal 8y agoI'm pretty sure the answer here is "no".
- seszett 8y agoNo, you don't have to. > At the very least there are additional record keeping steps, policies and procedures to draft, the appointment of a DPO that responds to requests for access or erasure, and the development of the features to fulfill both of those requests. * "Record keeping steps" are not needed if you don't keep records (which is what you should do); * "Policies and procedures" are what you should already have, of course, and GDPR didn't change that in any way; * A DPO must be appointed only if processing the personal data of your customers is your core activity; * Developing features to fulfill requests for access or erasure isn't necessary if you don't keep records.
- adventured 8y agoA newspaper from Aiken, South Carolina doesn't need to worry about complying with GDPR in any regard what-so-ever, not under any realistic circumstance. It can safely entirely disregard it. The Aiken Standard doesn't have to worry about GDPR just like a small town newspaper in Spain doesn't need to worry about complying with every privacy law that every US state decides to implement in the coming years (following in California's footsteps). There is a vast misunderstanding of how jurisdiction works and how it's going to play out in the near future. The vast majority of the world will disregard GDPR and comply with their own local laws instead. Small and mid size sites from any given country are not going to attempt to comply with 407 different privacy laws from every country/city/state/region/zone/province/whatever around the world. There is no alternative to this future. The sole, sane approach is to disregard Internet privacy laws if they do not apply to you in terms of jurisdiction. You will not be able to comply with the zillions of Internet-focused laws that are going to get created across the globe in the coming decade. GDPR should act as the training wheels for people building online sites/services/businesses to understand jurisdiction.
- chrismeller 8y agoI don't disagree with your point that nothing is ever going to come of it. In the case of an independently-owned local newspaper the EU can "huff and puff" as much as they want and there's not going to realistically be any impact to them. A lot of these "local" papers are owned by large parent companies though, and that becomes a different story all together. Even if you are independent and there's nothing the EU can realistically do to you, it's just one more thing you have to deal with. Figuring out WTF is going on, getting a lawyer to verify that there's nothing they can do to you, etc. etc. There are still some hard costs associated and it's going to distract you from what your company actually does for a while.
- chrismeller 8y agoEven writing an IP address in a web server log is considered "keeping data". Most of these news sites also have some form of "create an account to get updates / comment / vote" system, which would absolutely count as "keeping data". At the very least you still need a policy to give people telling them what data you keep and who you share it with. Even if that is nothing and no one, you need to be able to tell them that and you need someone who is responsible for handling those requests when they come in. "Just don't keep anything" is not a sufficient answer.
- josteink 8y ago> Even writing an IP address in a web server log is considered "keeping data" No it's not. Stop spreading FUD. If so, every part of every Internet-connected system on earth would be required to be completely redesigned to be GDPR-compliant. Demanding anything like that is not only unreasonable, it's 100% unrealistic. The GDPR is perfectly reasonable legislation and has legroom for obvious operational requirements, like access logs. (If you however mine the access log to derive or track users, that is another matter completely.)
- oytis 8y ago> (If you however mine the access log to derive or track users, that is another matter completely.) So under GDPR you're not allowed to process data you've already got? I wouldn't call this reasonable legislation.
- marksomnian 8y agoIf the data was obtained in violation, it follows that any processing, while not technically in violation, wouldn't be looked upon favourably. Furthermore, although IANAL, I suspect that certain classes of processing fall under different rules, therefore the processing could potentially be in violation even if the collection wasn't.
- Drakim 8y agoThat seems like some twisted logic. "I was just dumping data in logs, I don't have to care about privacy concerns. Oh, and now I have all this data on my server, since it's already here I surely deserve to process it without caring about privacy concerns!"
- IanCal 8y agoI'm very sure that you do not need to appoint a DPO unless you're over a certain size.
- seszett 8y agoIt's not a question of size, it's only needed if processing your customers' private data is your core activity, ie. if you operate an ad network that builds personal profiles of people.
- repolfx 8y agoCan you back that up? This site claims otherwise: https://www.itgovernance.co.uk/data-protection-officer-dpo-under-the-gdpr https://www.itgovernance.co.uk/data-protection-officer-dpo-u... There is no exemption for small and medium-sized enterprises (SMEs), which has been reaffirmed by the Information Commissioner’s Office (ICO): "I've heard plenty of people talking about there being a DPO exemption for SMEs - this is absolutely not the case." Peter Brown, Senior Technology Officer, Information Commissioner's Office (ICO)
- pimterry 8y agohttps://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/ https://ico.org.uk/for-organisations/guide-to-the-general-da... is a good summary from the UK gov authority. It's not based on size, but it isn't applicable to most businesses anyway. You need a DPO if: * you are a public authority or body (except for courts acting in their judicial capacity) * your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking) * your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences. Imo, those are all pretty reasonable cases where you should have somebody responsible managing your data privacy. DPOs are for people managing very private data, or profiling people at very large scales. For most businesses, DPOs aren't relevant.
- chrismeller 8y agoI'm honestly not sure about the specifics on who legally has to have a DPO, just that it's a thing and a lot of people do. There's also the weird requirement that there be some EU-resident "responsible person" if your organization is not based in the EU that I'm fuzzy on the details of. Even if you can avoid both of those you still need a point person who answers GDPR-related requests. Whether you end up calling that person the DPO (with the legal responsibilities and consequences that comes with) or just the "GDPR Guy" (also known as Ted from Accounting...) it's still something new you have to deal with, train for, etc.
- josteink 8y ago> No, that's not the only requirement. At the very least there are additional record keeping steps, policies and procedures to draft, the appointment of a DPO that responds to requests for access or erasure That only applies if you illegally track users. You know what a simple solution to that is? Yup: Don't illegally track users. Pure magic, I know!
- steventhedev 8y agoOr perhaps they've been advised that because they have an email subscription, they'd need to hire a full time DPO, and their outside counsel quoted them several thousand dollars a year. It's simple arithmetic to decide it's cheaper to block all EU visitors.
- nextlevelwizard 8y agoNothing of value was lost. Good riddance!
- oblio 8y ago> they'd need to hire a full time DPO They don't. They need to designate someone as the DPO, it doesn't have to be full time.
- repolfx 8y agoThat's technically true but practically untrue. The DPO is a major imposition and simply being required to comply with the DPO parts alone is sufficient to make the EU not worthwhile for many businesses. 1. Whilst a DPO can theoretically be part time, a DPO is not allowed to have other roles in the firm that could create a "conflict of interest". This is so vague that in a company that works with data, almost any other role could be argued to create such a conflict of interest. 2. The DPO position has a list of mandatory responsibilities and even qualifications that will be accepted. For example the EU has advised DPOs need "expertise in EU data protection law". Where will foreign websites find such a person? 3. The DPO works for the firm but cannot be told how to do their job. They also cannot be fired or penalised for anything related to their job responsibilities. In practice these rules mean it's very likely everyone will outsource the DPO role to third parties.
- seszett 8y ago> they've been advised that because they have an email subscription, they'd need to hire a full time DPO, and their outside counsel quoted them several thousand dollars a year. I think a large part of the scare that can be observed among American companies is due to legal advisers jumping on the opportunity to make big money by misleading their customers into thinking there are enormous, complicated and unlikely requirements for compliance, and huge risks to making any mistake.
- oytis 8y agoA news website won't build a tracking system themselves, they would rather use ready-made analytics plugins. Making them selective might be a pain (I'm not a web developer, just guessing). Even after that you need a lawyer with some technical knowledge to assess that you've done everything right. And also a lawyer that would deal with some random complaints that will still land in your message box. Can be pretty expensive.
- alerighi 8y agoNot logging data means no revenue from ads, or smaller revenue, and thus it's not convenient to comply.
- mcroft 8y agoSkimming the list, it does seem very heavily dominated by US local news sources.
- mrweasel 8y agoInstapaper is sort of the only site where it's an actual problem. I get the feeling that the rest are just running on some common platform, which have the feature of being able to block the EU after some US corporate lawyer overreacted.
- josteink 8y ago> after some US corporate lawyer overreacted Given how US techies here on HN seems to constantly overreact and loudly proclaims how the GDPR means they need to hire 20 new employees and how they all will be suited into bankruptcy anyway... If they are now stuck in a needlessly rigid legal regime, it's hard NOT to say they brought it on themselves.
- starquake 8y agoMaybe even because they would make less money if they can't sell your data anymore.
- AmericanChopper 8y agoMaybe they just don’t do any business or have any audience in Europe and are faced with cost of compliance (more than $0) vs block Europe ($0).
- adventured 8y agoIf they're doing no business in Europe, they do not need to worry about complying with GDPR at all and can freely track European users any way they see fit. The EU has no jurisdiction over newspapers in South Carolina. It is that simple legally. If I visit a random popular Chinese site, landing on a Chinese mainland server in the process, the US Government is not going to get to tell that Chinese site how it can legally use my data in their country. Shouting that I'm an American citizen and that they must comply with US privacy laws, will do no good: the US Government has no jurisdiction over the matter. It works exactly the same way for the US-EU-GDPR as it pertains to a newspaper from South Carolina.
- AmericanChopper 8y agoCan you point to some case law that says EU data subjects consuming US based services will not protected by GDPR? Because one of the main points of the legislation is that the EU will use it to protect their data subjects in every jurisdiction. You’re probably right, but you won’t be able to direct me to a lawyer who would be willing to evaluate a business and determine its GDPR exposure for $0.
- adventured 8y agoYou're asking me to argue or prove a negative. You might as well apply the same premise to US vs EU vs Chinese (vs any other country) freedom of speech laws. It's the exact same jurisdiction premise on how rights are governed, whether we're talking about privacy or otherwise. Just because I'm an American, that doesn't give me US freedom of speech protections when I step foot into EU countries or Brazil or China or North Korea. I'm bound by the local laws on most things, with few exceptions.
- raynr 8y agoSo much this. You have a business with an online B2C component and your contract with your suppliers and/or service providers requires you to comply with the GDPR. You are in no position to comply because your primary area of business isn't the EU, sure your website is accessible but no one is realistically going to engage your services from Germany. Meanwhile the GDPR has extra territorial reach and is so broadly worded that you don't know the ways in which you will be impacted. Your legal counsel is telling you "they ain't budging, why not manage it practically, by explicitly not target the EU?" So you block access to your goods/services/website to EU IP addresses. Your suppliers and service providers are happy, your legal counsel is happy, and your business is not impacted in any meaningful way at all. I haven't looked at the sites on the list, which may well contain "shady" websites, but bear in mind that these are the entities who have looked at the GDPR and concluded it was somehow or other better to expressly tell visitors that they do not comply with the GDPR. A shady business wouldn't even bother putting a notice up on their website!