5 ms·
As a US based developer, would I have the option to ban people in the EU from using my software? It's the only way I would be able to keep distributing. Edit:
by w4ffl35 3y ago
As a US based developer, would I have the option to ban people in the EU from using my software? It's the only way I would be able to keep distributing.
Edit: I think I misunderstood. This seems to only apply to OSS non profits.
Edit 2: I am not only developing my own software, I am doing it under my LLC, packaging and distributing on itch.io, and in one case charging a low amount. So this likely would apply to me.
Since I've made a whopping $200 in donations and sales total over the course of several months, that will be the end of my side business / passive income.
And since I'm in the US this feels unfair. I really shouldn't be bound by EU laws. I'd rather just ban the EU from my software if it comes down to that.
edit 3:
ok that last bit is over the top. i understand i have to follow international law... my American-ism is kicking in.
- actionfromafar 3y agoSomebody please chip in an informed opinion on how much legal exposure a US entity has to EU litigation. Especially if said US entity doesn't really have any paying EU customers.
- alpaca128 3y agoIANAL but the EU's GDPR also applies to companies providing services "even in the absence of commercial transactions"[0]. I've seen quite a few US news sites that simply refuse to show me any content. If the EU stays consistent with this stance - and the US sites refusing to deliver content aren't just being overly cautious - then I could see providing a download may already count as providing a service in the most pessimistic interpretation. [0] https://termly.io/resources/articles/gdpr-in-the-us/ https://termly.io/resources/articles/gdpr-in-the-us/
- harvey9 3y agoI'd like to think these things are treated differently. Browsing to a web page and getting cookied is different from actively choosing to run some software. Gets more complicated with web apps, but I'm personally willing to accept a disclaimer from sites and software I'm not directly paying for.
- RobotToaster 3y agoI've wondered, how enforceable is a EU court ruling on a company with no assets in the EU? If they can't enforce it, then does it matter if they fine you a centillion euros?
- traceroute66 3y ago> I've wondered, how enforceable is a EU court ruling on a company with no assets in the EU? Article 27 GDPR. If you are not established in the EU, you must designate, in writing, a representative in the EU: The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.
- w4ffl35 3y agothis is a good point.
- tonyedgecombe 3y agoUntil you want to holiday in Europe.
- w4ffl35 3y agonever have never will. i strangely have no desire.
- em-bee 3y agothey can enforce it when you travel to the EU
- phkahler 3y agoIn a download situation, is a US site providing data to someone in the EU, or is the person requesting data from someone in the US? ;-)
- traceroute66 3y ago> Especially if said US entity doesn't really have any paying EU customers. Aah the good old US mentality, everything must revolve around money. :) My friend, "paying" doesn't come into it. It's all about PII, "Personally Identifiable Information". To paraphrase Dean Martin.... Got EU people on your mailing list ? That's GDPR. Silently harvesting telemetry, IP addresses, setting cookies etc. ? That's GDPR. etc. etc. etc.
- tzs 3y agoYou are correct that money doesn't enter into it (at least directly). The Dean Martin paraphrase however is not quit correct. Having EU people on your mailing list does not necessarily make you subject to GDPR. It depends on where you are, and possibly on your intent. The territorial rules for GDPR are: 1. It applies if you are in the Union, regardless of where the people on your mailing list are and regardless of whether processing their data takes place in the Union or not. 2. If you are not in the Union, GDPR applies to the processing of data of people in the Union where the processing activities are related to ... 2a. ... the offering of goods or services (regardless of whether payment is required or not) to people in the Union, or 2b. ... the monitoring of the behavior as far as their behavior takes place within the Union. Whether or not you are offering goods or services to people in the Union depends on whether you envisage to do so. The mere accessibility of your website from the Union is not sufficient. For example if you were running a mailing list for your small city's chess club and someone in the EU found your site and signed up, you probably would not have any GDPR obligations to them. If your chess club site also sold chess equipment that still probably wouldn't be enough unless you did something to indicate that you were actually trying to include EU. For example if your site had localization for all major EU languages, gave pricing in both dollars and Euros, and included VAT you would be covered by GDPR. But if the site is only in English (and maybe Spanish), gives pricing in dollars and only accepts dollars, only collects US sales taxes, only ships via USPS, and doesn't have anything that indicates you might be catering to EU people, you are probably in the clear.
- xoa 3y ago>As a US based developer, would I have the option to ban people in the EU from using my software? It's the only way I would be able to keep distributing. ?!?!?!?!??! No, just tell the EU to go fuck itself. If like me you're in the US they don't have any jurisdiction! It's not our problem. How the hell did the entire concept of sovereignty apparently evaporate on HN? The EU is absolutely no different than China, Russia, Iran, or North Korea in this regard. They can pass whatever domestic laws they want. They can also setup a Great Firewall and block off countries they don't like. But if you don't live there and you have no operating presence there then it doesn't matter if their people come and access our sites and services, anymore than if they flew over to the US and access it from here. It is Not Our Problem. Software is protected by the First Amendment. I don't respect blasphemy laws or any of that other crap either. >edit 3: ok that last bit is over the top. i understand i have to follow international law... my American-ism is kicking in. That's not "Americanism" nor over the top in the slightest bit. There is no such thing as "international law" in any way that's the same as domestic law. Countries can agree upon treaties, which they then translate into domestic laws for their own citizens same as any other law. But there is no World Government, and what the EU passes matters only to the extent you wish to have a physical presence in EU jurisdiction or the US agrees to the same thing and passes domestic law to that effect. Big Tech players and such obviously fall into the first bucket, at their scale and for what they offer physical presence is vital, which naturally puts them in the jurisdiction of wherever they are up to the limit of being willing to leave. For those of us who are just single devs putting out software, free or commercial, if someone from the EU wants to go after us for liability they'd have to do so in US court under US law.
- deleted 3y ago[deleted]
- layer8 3y ago> If like me you're in the US they don't have any jurisdiction! They do if you do business in Europe, for example by serving users in Europe.
- w4ffl35 3y agothis is where my confusion is: i am writing software and adding to github, compiling on github and pushing to itch.io. lots of people from EU have downloaded my software and even donated. am i serving customers in the EU? IMO no, but i could see how others would argue that I am. edit: i think itch.io and github are serving customers in the EU, not me.
- pabs3 3y agoYour license wouldn't count as open source any more if you discriminate against Europeans in it. Sounds like it already isn't FOSS though? You did mention GitHub further down so hmm.
- dogma1138 3y agoIn the license add a section that prohibits people from the EU using it.
- phkahler 3y agoNot feasible to do license changes on larger projects.
- dogma1138 3y agoWhy not?
- phkahler 3y agoBecause every contributor has to be contacted and agree to the change. If one can't or won't your only option is to revert their changes and everything derived from them. This is yet another way the OSI was a bad idea. For a while they approved a bunch of open but incompatible licenses that couldn't be changed
- seydor 3y agoAs an EU developer i would also like to know how to block the EU from my customer base.
- rurban 3y agoAs an EU developer I would also like to know how to block fascists from my customer base, esp. US, Russian and Chinese companies and state orgs.
- numpad0 3y agoThey are not expecting the xkcd “Dependency” comic situation to be possible in the first place, and trying to pressure commoners to sort it out by an “or else,” threat, which isn’t working well. 0: https://xkcd.com/2347/ https://xkcd.com/2347/
- blueflow 3y ago> They are not expecting the xkcd “Dependency” comic situation to be possible Rightfully so if you assume certain engineering standards. "Made by a nameless guy in a shack in oregon" is something you never want your auditor to hear.
- phkahler 3y ago"Made by a nameless guy in a shack in oregon" is something you never want your auditor to hear. If you are a business buying software from a business, sure. But if you are anyone getting your OSS from the guy in Oregon, sure. The goal here seems to be shielding larger companies when they use 3rd party OSS. Exploitation at its finest. Besides, what about EULAs and other liability limiting license terms?
- ChrisMarshallNY 3y agoI think that having some kind of "supply chain accreditation" might be something to look at. However, this kind of thing can become a nightmare. I used to work for an ISO-9000 company.
- rs999gti 3y ago> some kind of "supply chain accreditation" As long as the for profits and governments that use OSS are paying for the process and regulations, otherwise you are putting undue burden on OSS developers.
- w4ffl35 3y agonow that I am fine with, but i still think this is nutty overall. there's nothing wrong with anon contributions to software.
- orwin 3y agoYeah, i just read the proposal, there is a lot of holes, but, from general to specific: First: even if you piss off a EU member state and they direct their watchdog to your product (i trust my country's watchdog wouldn't listen 99% of the time, but we are 28, so it could potentially happen), this has to go to the court. You won't have to pay for a lawyer and still have competent representation, and likely win because the ECJ dislike state entities going after small business. It's the same for GDPR btw. The watchdog would rather needle you to implement changes than go to court. And it's the same for trade laws (I know an irish business importing to France that have production facilities in Scotland, who kinda broke import laws multiple time since brexit and is still fine, even received a procedure on "how to fill you paperwork). Second: Not sure how this will apply. From what i got, this can either go "internationnal treaty", and in this case it will apply to all europe the same way, or the "each country implement the idea however they want, this is the baseline" way. If its the second, the baseline will be much lower because... Third: this isn't even the final proposition. Even if it was, it has to go through the parliement and will be changed. I would love having a diff tool to show people how much the parliement change the law from the initial proposition (either european or my country, sometime the final law can be on the opposite of the proposed law (or at least orthogonal)).
- academia_hack 3y agoInternational law is not the same thing as the EU dictating laws that they want to apply internationally. It think it's totally reasonable to say that you didn't vote for any EU legislators, couldn't even if you wanted to, and they have as much right to tell you what to do as the Kremlin does - zero. If your own elected representatives want to enter into an enforcement or reciprocity agreement with the EU on this matter, that's fine, but until then extra-territorial regulation of technology is a pretty clear moral overreach.
- w4ffl35 3y agoagreed on all this > International law is not the same thing as the EU dictating laws that they want to apply internationally I definitely used the wrong term.