5 ms·
Apparently, compliance with GDPR is not worth the hassle for websites that target a non-European audience.
by Hermel 7y ago
Apparently, compliance with GDPR is not worth the hassle for websites that target a non-European audience.
- tjoff 7y agoYeah, the burden of not exploiting their users really is a huge undertaking.
- Hermel 7y agoIt’s certainly much cheaper to simply block European users than to pay a lawyer to tell you what you need to change and then pay a programmer to implement these changes. Blocking the few European users is probably the right decision from an economic perspective.
- nannal 7y agoThen I'm going to vote with my European wallet and commit not to visit sites that block me. Let's see just how much they like that.
- deaps 7y agoThat'll show 'em
- pingyong 7y agoThey literally intentionally blocked you... that's kinda what they expect to happen lol.
- DarkWiiPlayer 7y agoWooooosh... (That was the sound of the joke going over your head)
- unknown_library 7y agoGDPR adds a lot of regulatory red tape to things that were previously simple. It is not only for nefarious reasons that you might want to avoid GDPR. Want to store logs? Now you need to make sure you're scrubbing any type of personal information from the logs. Want to use a third-party service? Now you need to make sure that you are using their GDPR-compliant plan, and that you are using their Amsterdam endpoints. Maybe you need to renegotiate your contract with them.
- asutekku 7y agoI mean you shouldn’t store any personal information in the logs to begin with.
- marcinzm 7y agoMost places would log the IP (for spam prevention, security tracking, etc) which is personal information under GDPR.
- DarkWiiPlayer 7y ago> which is personal information under GDPR Not exactly; it's up to the judges to decide whether IP addresses count as personal information as defined by the GDPR (in my opinion they're not, but I can see why one would think differently), so the flaw isn't as much inherent to the GDPR as to the fact that people just don't understand the internet.
- vonmoltke 7y agoRecital 30 specifically calls out IP addresses: https://gdpr-info.eu/recitals/no-30/ https://gdpr-info.eu/recitals/no-30/ While the wording of the Recital leaves some ambiguity as to whether an IP is automatically Personal Data under the GDPR, its specific call-out would make arguing that it is not difficult. This would particularly be the interpretation of American lawyers, who tend to assume that no connection is too tenuous to be held against their client by a shrewd prosecutor or regulator and will thus advise their client to treat all IPs in all situations as Personal Data.
- Balanceinfinity 7y agoon the lighter side, I do a lot of cooking and I always laugh when I visit a baking website and I get a popup that warns me about the cookie policy. Because of the context, my brain first goes to "I wonder what the recipe is for those cookies."
- nottorp 7y agoTBH it's Chicago Tribune. I bet 99.95% of the articles there aren't interesting for someone in the EU. A good part of them aren't probably interesting even for an USer living outside the Chicago area. I'd certainly never consider visiting normal US news sites unless - like in this case - they were linked to by HN or some other aggregator I do frequent. Thus, it really makes no sense for them to comply with the GDPR.
- DarkWiiPlayer 7y agoBy the same logic, they aren't really required to comply with GDPR, so they could just ignore it.
- nottorp 7y agoAre you sure they're not part of some media conglomerate that is also doing bussiness in the EU?
- rkangel 7y agoI understand the logic, and can't say I'd take a different decision in their case. As a UK fan of another NFC North team, not being able to read the Chicago Tribune (without workarounds) is moderately annoying.
- pingyong 7y agoWhat I'm wondering about is: If you're not targeting an EU-audience, and you therefore might not even have servers in the EU, and certainly don't have EU-based revenue streams - why do you even care? Can an EU court even do anything in this situation?
- alexis_fr 7y agoSometimes it’s a matter of making a point. I mean, who likes the cookie law (and bear in mind that US people don’t even see it remotely as frequently as europeans). Some people just want to send the message that EU is going too far.
- DarkWiiPlayer 7y agoFrom GDPR Article 3: > 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: > (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or > (b) the monitoring of their behaviour as far as their behaviour takes place within the Union. This makes perfect sense from the perspective of some old politician: It's like shooting someone over the country border. It fails to address the fact that unlike in physical space, on the internet it's not that obvious to see where someone is connecting from (in fact, it's impossible to really say with complete accuracy) But in my opinion, it's not the wrong choice to assume that, if you're operating on a scale where you can spy on your users and sell their data, you'd be capable of figuring out whether they're in the EU. And, honestly, it's not hard. There's third party software that you can just embed in your website and it automatically generates the cookie warning and even blocks cookies until you've accepted it.
- lloeki 7y agoIIUC, you can be a US expat living in the EU and the GDPR still applies. Even then a non-EU company may not explicitly target a EU audience but EU moral or physical person may still find interest for whatever personal reason and still be protected by GDPR. As for jurisdiction, I suppose such conflicts are resolved using international law, but if a company is reachable from the EU by individuals protected by EU laws I’m pretty sure there is applicable jurisdiction (not saying it’s an easy thing)