3 ms·
Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users wo
by VortexDream 5y ago
Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users won't do it because they want those users.
- tzs 5y agoPeople like to infer from this that those sites are gathering and processing data in ways that would be hard to make GDPR-compliant. My guess is that in a lot of cases though it is that they simply do not want to deal with Article 27. Article 27 is a hassle even if all your data processing itself is fully compliant with GDPR. Article 27 requires entities not in the Union to designate a representative in the Union that people and governments can use as a contact when they have GDPR concerns. (Don't confuse this with Article 37, which requires the appointment of a "data protection officer". Article 37 only applies in most cases if you are doing large scale processing). The representative seems to be more than just a communications go-between to provide an easy way for people in the EU to contact the processor/controller. One of the Recitals says "The representative should be explicitly designated by a written mandate of the controller or of the processor to act on its behalf with regard to its obligations under this Regulation" and "The designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor". There are EU companies that provide as a service being your Article 27 representative, but because it seems to be more than just a simple communications go-between they charge typically at least a couple hundred Euros or so a year for the service (sometimes much more).
- wglb 5y agoThat provision is not so hard. Most companies I have talked to don't know what data they have collected, where it is stored, and who it is shared with. That is the thing that gets the attention of US companies.
- guitarbill 5y agoI'm not sure I buy that. It really comes down to the question of why do small, local US news sites care about the GDPR at all? I can think of three reasons: 1. They are actually all owned by a multi-national entity that is scared of the GDPR because it also operates in Europe 2. The news sites and their owner(s) aren't bothered; but the ad networks are. Maybe it's a "cross-contamination" issue. So they say something like "to keep using us, block European visitors, we'll provide that capability", and the news sites are probably fine with it because European visitors are a tiny fraction 3. It's a political statement, not an actual GDPR issue