11 ms·
I feel like we had this exact same argument over GDPR, but no horror stories have descended about Mom and Pop operations run out of business but the evil Brusse
by drewbuschhorn 8y ago
I feel like we had this exact same argument over GDPR, but no horror stories have descended about Mom and Pop operations run out of business but the evil Brusselcrats.
- yostrovs 8y agoIt's not clear what's going on with GDPR, good test cases are only now starting to be tested. But the fact that many American newspapers, for example, are blocked in Europe is certainly something to worry about.
- r3bl 8y ago> But the fact that many American newspapers, for example, are blocked in Europe is certainly something to worry about. There's just one large company that decided to block EU visitors: Tribune Publishing[0]. Yes, them blocking Europe is bad. Them owning so many local newspapers that this decision even makes an impact is a bigger problem. I'm not saying that they're the only ones blocking Europe, but I am saying that we wouldn't think of it to be as wide spread if it weren't for Chicago Tribune, Baltimore Sun, and LA Times (among others). [0] https://en.wikipedia.org/wiki/Tribune_Publishing https://en.wikipedia.org/wiki/Tribune_Publishing
- gregknicholson 8y agotronc [vt] To make content unavailable in certain jurisdictions due to unwillingness to comply with their laws. Examples: * Tribune have troncked Europe because their data control is jazzy. * Google should really tronc China - fight the Firewall!
- stef25 8y agoLA Times was blocked before but now loads fine in EU. The other two are still blocked.
- andrewnicolalde 8y ago> But the fact that many American newspapers, for example, are blocked in Europe is certainly something to worry about. They are not blocked. They have chosen to take their services offline because they don’t think changing their business model such that it no longer depends on aggressively tracking their users is worthwhile or cost-effective. Which is fine by me imho.
- yostrovs 8y agoYou must understand the economics. Newspapers have zero cash on hand these days, so their choice was to fire staff to allocate money for GDPR or not. Seeing how staff is at a minimum, that was the practical option. Result is equivalent to censorship. I'm surprised you don't find this a terrible outcome.
- gregknicholson 8y ago> Result is equivalent to censorship. I don't agree that if a business chooses not to operate in a country, because it's unwilling to spend the money required to comply with the country's laws, that that is equivalent to censorship. Another person's personal information is not protected speech.
- vedantroy 8y agoI always viewed it as a transaction--go to the news site and read the news, in exchange they will sell data on what articles you're reading, etc. I was fine with that transaction. In fact, I would rather have them sell my data instead of charging money. Consumers have a choice on whether or not they want to go to these sites, it's not like they are forced to give away their personal information to news sites. I would say the GDPR blocking news sites is a net negative because it denies consumers the choice to read news stories.
- TeMPOraL 8y ago> I always viewed it as a transaction--go to the news site and read the news, in exchange they will sell data on what articles you're reading, etc. And I always thought (back in my more naïve days) that I read the site in exchange for being advertised to. Point being, the exact details of the transaction were never shown to the visitors. GDPR fixes that by forcing companies to state the terms of this transaction explicitly, and actually ask the visitors if they're willing to participate in it. GDPR isn't blocking any sites, it's only disallowing a very particular way of getting users to give up their data and then monetizing that data. Nobody is entitled to their business model working forever, and some companies prefer to shut off a large segment of their market instead of updating their business model. It's their choice.
- drewbuschhorn 8y agoI'm not saying there won't be an effect, but having an effect it's why you pass a law. But 8 months in, and the landscape doesn't seem radically altered. If anything, major players deciding not to compete in a market is good to my mind, as a means of increasing a diversity of business styles. Laws like this make businesses pay for the actual cost of thier hidden externalities.
- paulie_a 8y agoAmerican newspapers don't need to care about GDPR. Most websites don't need to care about GDPR. Europe does not get to dictate how non European based websites operate. The GDPR can be outright ignored for a significant part of the internet. I have no idea why an American newspaper would give a shit about GDPR. They could literally put a huge banner up saying "fuck GDPR" and face zero legal consequences.
- jdietrich 8y agoThe GDPR is very similar to the old Data Protection Directive, which came into force in 1995. Many member states had done a piss-poor job of implementing and enforcing the DPD, which was largely the motivation for passing the GDPR. Directives have to be transposed into national law by individual member states, while regulations are immediately applicable across the entire Union. https://en.wikipedia.org/wiki/Data_Protection_Directive https://en.wikipedia.org/wiki/Data_Protection_Directive
- hpcjoe 8y ago[humor] Given the "quality" of reporting in most of the publications here, we should be thanked for that outcome [/humor] More seriously, GDPR should not extend beyond its jurisdiction. It does though, and there are consequences. Blocking european IPs cost (loss of revenue) must be balanced against compliance costs. Claims that "they've had N years to prepare" are specicious, if for no other reason than they aren't bound by the specific law. Meanwhile the law introduces a new, potentially large, liability. Which results in companies self censoring by geolocation. This is what you call an unintended consequence. Remote access to quite a few resources outside of Europe is likely to be restricted should this pass into EU law. As we like to say here, elections have consequences. FWIW, I support the aims of GDPR, and wish we would get a sane law on this here in the US as well. But I don't want our law extending to others. That would be unfair to them.
- stolsvik 8y agoHave you ever heard about the financial law Fatca? Please read up. What about sanctions of Iran that the US forces the rest of the world to go along with? The US is probably the biggest "exporter" of laws that are forced down the throaths of all other countries.
- KevanM 8y agoThese are enforced on a national level though aren't they, in the UK ICO doesn't have the resources to hunt people down and are probably only going to enforce action against major players in the market as they are under the most scrutiny. The problem comes when a nation decides to use those rules in a way that is detrimental to the populace or a service they see as troublesome.
- fuscy 8y agoThis is not related to business but there's a horror story with Romania (it's in the EU) asking a news organization to provide informants information related to some corruption leaks. The information is requested by the national GDPR enforcer so it bypasses the prevention written in the GDPR about news leaks. Now there's a trial going around with this which blocked any further spread of that information until it's solved. It can be easily seen how the GDPR can be weaponized.
- tomp 8y agoIsn't that just straight abuse of the law? AFAIK GDPR only protects your personal information, it can't be used to request someone else's personal information (if anything, you could argue that GDPR prevents you from giving out another person's info).
- graeme 8y agoPotentual for abuse of laws is one of the concerns people have about laws.
- SiempreViernes 8y agoThey aren't actually following the letter of the law, so to me it's unclear how much they actually abuse the law rather than simply pasting the GDPR logo in one corner in a sort of legal phishing attempt.
- tomp 8y agoIt's a concern people have about governments.
- fuscy 8y agoThis isn't the police or the parliament asking for the information. It's the regulatory body that does inspections to companies to see if they respect GDPR. So the pretext they're using is that they want to see the information to make sure that the news organisation is not selling it or mishandling it to other third parties. In the process, they'll be able to get the information and maybe it will go to the people involved in the corruption charges (which is the head of one part of the Parliament).
- Zak 8y agoGDPR is still fairly new, and it usually takes a while for the full consequences of complex new legislation to be felt. As an American who spends a lot of time in Europe, what I have noticed is that a majority of local news sites in the US block me from accessing them using IP geolocation.
- LoSboccacc 8y ago> no horror stories law need to be tested trough time, because it will be used by the next party in power for hundreds years, whether you like the party in power or not. the only reasonable way to reason about law is full on pessimism. it's like we already forgot the tyranny that was going on less than a century ago and was acquired through escalating legal abuse.
- ric2b 8y agoDoes the EU parliament even have parties?
- LoSboccacc 8y agono they forbid dual mandate, they have now groups but those are super nationals. but the country receiving the regulations do, so there's that.
- stef25 8y agoGDPR has had a very detrimental effect on user experience, with never ending popups and warnings about crap nobody understands. And being in the EU there's several US publications we can no longer access.
- TeMPOraL 8y agoI can buy arguments that extra compliance efforts make some businesses not cost-effective in Europe, but this particular argument is nonsense. It's like a factory that dumped toxic waste into a river complaining that, because of a ban on dumping toxic waste into rivers, they now "have to" dump them to nearby meadows instead, and that makes local customers unhappy. "Detrimental effect on user experience" is an intended effect that clearly signals the company doesn't want to stop abusing its users.
- erik_seaberg 8y agoIt's not just the costs, it's attaching a 20M EUR risk to activity that may not even be worth 20M of revenue.
- dasil003 8y agoNo, the risk is created by abusing customer data. If the cost was less than revenue then it’d be a toothless law.
- erik_seaberg 8y agoGDPR is the size of a novel and attorneys can't even agree yet on what counts as PII. It's nowhere near a crisp law that only prohibits bad things you'd know not to do.
- dasil003 8y agoYes, that's right, it's messy when you are tackling legislation to play catch up with technology. We've seen how wrong it can go with stuff like the last generation of cookie laws that were too tightly coupled to implementation details. GDPR is actually a nice step forward into resolving these huge gray areas that the web and smart phones have enabled as they become mainstream. The status quo where corporations make vast profits peddling ever finer-grained user data unbeknownst to the consumer with no oversight is not good. A cultural shift is necessary. I'm glad to see the EU has the stones to tackle the issue because there is zero political will stateside for any political action other than driving corporate profits masked by populist appeals to xenophobia and whatever other irrelevant distractions they can cook up.
- JumpCrisscross 8y ago> we had this exact same argument over GDPR, but no horror stories have descended Romania has already deployed GDPR as a weapon against its press [1]. I also have a short list of anecdotes of economic activity (start-ups and other new market entrants) that would have happened in the EU but, in large part due to compliance costs–including GDPR–wound up happening outside the EU. [1] https://euobserver.com/justice/143356 https://euobserver.com/justice/143356
- foepys 8y agoAnd the EU is trying to prevent Romania from doing it. I don't see your point. Romania could just have used another law or just made a new one to harass the press.
- JumpCrisscross 8y ago> the EU is trying to prevent Romania from doing it Giving people in power broad discretion with the law and then counting on them being nice is a delicate strategy. It counts on every administration being benevolent. > Romania could just have used another law or just made a new one to harass the press There is a big difference between using the authority of the EU, through an EU regulation, and passing a domestic law to go after people you don't like. More broadly, this argument can be made against any over-reaching law. Just because some hypothetical law could be bad doesn't make an ambiguous law granting widespread power to select bureaucrats okay.
- nicoburns 8y agoGDPR has a very worthy purpose though: companies were taking far too many liberties with people's personal data. I don't see analogous problems with copyrighted material (there is some infringement, but it doesn't really seem problematic to society).
- jakeogh 8y agoThat's not what it's for. The GDPR legslates what events one can remember (using incrementalisim). It's ultimately an attack on general purpose computing.
- brokenmachine 8y ago> It's ultimately an attack on general purpose computing. I don't get it. How is GDPR an attack on general purpose computing?
- jakeogh 8y agoDoes your GPC comply with the GPDR?
- brokenmachine 8y agoBut people can store data on themselves on their own PC of course. I don't see how GPDR affects that. I don't want a GPC that sends personal data back to the mothership anyway.
- jakeogh 8y agoIt's incremental. The companies covered by the EU's GDPR are untimately comprised of people too. It's easiest to start with a subset, and the GDPR is no exception to that rule. Ya lost me on the reporting to the mothership thing, that is definately what many power centers would like, for example, non-DRM 3D printers that can cheaply print metal objects will be reserved for criminals in countries controlled by repressive regimes because they can make effective life saving tools.
- beezischillin 8y agoAn old client of mine, an actual mom and pop operation in Germany was harassed and was almost ran out of business by a law-firm who went around, the moment GDPR dropped, trying to find targets to sue.
- hyperman1 8y agoDo you have any details? What did the mom and pop operation sell? How did they go afoul the GDPR with this? AFAIK, no independent lawyer can sue you for violating the GDPR. Only the German regulatory body could sue them.
- beezischillin 8y agoThey received a letter threatening a lawsuit due to the fact that they had a newsletter sign up form without double opt-in feature on their site and some explicit legal documentation missing. Other than that it was a really simple presentational site made in Wordpress. Our business relationship ended years ago but I received a mail from them years ago asking for help in putting those things in because they were afraid of having to deal with legal stuff over such small bs. I obviously did. Now I don't know German law, as I'm not German, but it felt like they were really afraid that it could happen.