Blocking 500 million users is easier than complying with GDPR

Jamie McKane

MyBroadband Journalist
Joined
Mar 2, 2016
Messages
7,000
Reaction score
1,008
Blocking 500 million users is easier than complying with GDPR

For some of America’s biggest newspapers and online services, it’s easier to block half a billion people from accessing your product than comply with Europe’s new General Data Protection Regulation.

The Los Angeles Times, the Chicago Tribune, and The New York Daily News are just some telling visitors that, "Unfortunately, our website is currently unavailable in most European countries."

[Bloomberg]
 
They had over 2 years to prepare but decided to still not be on time and breaching the law at the same time. Well done...
 
Seems like a viable option - if they don't particularly care about the traffic why should an American corporation be bothered about the "European Parliament on General Data Protection Regulation 4.5.2016 L 119/1"?

I'm all for privacy, etc, but when you try to force reams of your local intractable bureaucratic regulations onto entities that have nothing to do with your market on the other side of the planet, unintended consequences such as this will follow.
 
Seems like a viable option - if they don't particularly care about the traffic why should an American corporation be bothered about the "European Parliament on General Data Protection Regulation 4.5.2016 L 119/1"?

I'm all for privacy, etc, but when you try to force reams of your local intractable bureaucratic regulations onto entities that have nothing to do with your market on the other side of the planet, unintended consequences such as this will follow.
Are you saying that:
a) Being insecure with customer privacy data is a viable option?
b) Losing 30%-50% of your customers is a viable option?

After having my private data exposed by ViewFines and Master Deeds I welcome GDPR.
 
I'm all for privacy, etc, but when you try to force reams of your local intractable bureaucratic regulations onto entities that have nothing to do with your market on the other side of the planet, unintended consequences such as this will follow.

Very narrow statement. If they have a significant portion of traffic from Europe, then Europeans ARE their market.

GDPR is a massive pain in the ass (I've spent the last few weeks helping with our compliance), but it's a properly good thing for consumers.
 
Seems like a viable option - if they don't particularly care about the traffic why should an American corporation be bothered about the "European Parliament on General Data Protection Regulation 4.5.2016 L 119/1"?

I'm all for privacy, etc, but when you try to force reams of your local intractable bureaucratic regulations onto entities that have nothing to do with your market on the other side of the planet, unintended consequences such as this will follow.

It’s not a viable option... any savvy American will avoid sites that aren’t gdpr compliant... it’s pretty much the best regulation for its type in the world.... everyone should strive to be gdpr compliant even if their market isn’t europe
 
Are you saying that:
a) Being insecure with customer privacy data is a viable option?
b) Losing 30%-50% of your customers is a viable option?

After having my private data exposed by ViewFines and Master Deeds I welcome GDPR.
Viewfines has nothing to do with Europe so it won't change a thing.
 
Viewfines has nothing to do with Europe so it won't change a thing.

If they store European consumer data, they would have to comply, regardless of their market.

And many people living between SA and Europe so viewfines would make themselves unavailable there.
 
If they store European consumer data, they would have to comply, regardless of their market.

And many people living between SA and Europe so viewfines would make themselves unavailable there.
Seriously doubt they care. Europe had no jurisdiction over SA companies.
 
Seriously doubt they care. Europe had no jurisdiction over SA companies.

It's up to individual member states to define penalties (in addition of the 4% of the worldwide revenue fine).

If one of the 27 countries decides it's a criminal offense, the directors can become delinquent and/or undesirable in Europe.

Art. 84 GDPR Penalties
1Member States shall lay down the rules on other penalties applicable to infringements of this Regulation in particular for infringements which are not subject to administrative fines pursuant to Article 83, and shall take all measures necessary to ensure that they are implemented.
2Such penalties shall be effective, proportionate and dissuasive.
Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

The penalties for failure are groundbreaking, with fines as
much as 4% of annual worldwide turnover, or €20 million,
whichever is higher. Meanwhile, GDPR reinforces the potential
for criminal prosecution to be sought against directors and
officers for deliberate breaches. Simply put, board members
could go to jail.

https://diligent.com/wp-content/uploads/2017/11/WP0032_US_The-GDPR-Checklist-for-Directors.pdf
 
Last edited:
Seems like a viable option - if they don't particularly care about the traffic why should an American corporation be bothered about the "European Parliament on General Data Protection Regulation 4.5.2016 L 119/1"?

I'm all for privacy, etc, but when you try to force reams of your local intractable bureaucratic regulations onto entities that have nothing to do with your market on the other side of the planet, unintended consequences such as this will follow.

Well it's only to protect EU residence, some companies opting to apply these rules to all users while others like this one are choosing to block these users.
 
Its not just a few niche sites, the whole internet ecosystem seems to be affected: http://www.bbc.com/news/technology-44252327

Complaints have been filed against Facebook, Google, Instagram and WhatsApp within hours of the new GDPR data protection law taking effect.

The companies are accused of forcing users to consent to targeted advertising to use the services.

Privacy group noyb.eu led by activist Max Schrems said people were not being given a "free choice".

If the complaints are upheld, the websites may be forced to change how they operate, and they could be fined.

What's the issue?

The General Data Protection Regulation (GDPR) is a new EU law that changes how personal data can be collected and used. Even companies based outside the EU must follow the new rules if offering their services in the EU.

In its four complaints, noyb.eu argues that the named companies are in breach of GDPR because they have adopted a "take it or leave it approach".

The activist group says customers must agree to having their data collected, shared and used for targeted advertising, or delete their accounts.

This, the organisation suggests, falls foul of the new rules because forcing people to accept wide-ranging data collection in exchange for using a service is prohibited under GDPR.

"The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent," said noyb.eu in a statement.

"GDPR is very pragmatic on this point: whatever is really necessary for an app is legal without consent, the rest needs a free 'yes' or 'no' option."

Privacy advocate Max Schrems said: "Many users do not know yet that this annoying way of pushing people to consent is actually forbidden under GDPR in most cases."
 
They are going to kill their own economies due to their pettiness and the small number of morons lobbying for these laws. Go ahead, you shall reap what you sow.
 
They are going to kill their own economies due to their pettiness and the small number of morons lobbying for these laws. Go ahead, you shall reap what you sow.

We shall see. Nobody complained about the GDPR but you must know better.

It is actually a benefit in the long term for the IT industry since consumers gain more trust. Google, Facebook and all major companies are happy to comply with it (hint: they've been extensively consulted and given 2 years to prepare for it).

I guess POPI should be scrapped and companies entitled to store their consumer credit card information in servers without firewalls in Macedonia in your world?
 
Are you saying that:
a) Being insecure with customer privacy data is a viable option?
b) Losing 30%-50% of your customers is a viable

Just as viable as simply cutting them off if you can’t be bothered. Hopefully also deleting their data, lol. There’s no law that you *have* to provide service to a foreign market with compliance requirements you might find too onerous.

If their primary market is US based and that’s where they monetize the traffic it makes perfect sense to cut off a more costly segment of your foreign market if you can’t monetize it as easily.
 
We shall see. Nobody complained about the GDPR but you must know better.

It is actually a benefit in the long term for the IT industry since consumers gain more trust. Google, Facebook and all major companies are happy to comply with it (hint: they've been extensively consulted and given 2 years to prepare for it).

I guess POPI should be scrapped and companies entitled to store their consumer credit card information in servers without firewalls in Macedonia in your world?

If they complied with it, then why is there complaints already?
 
Top
Sign up to the MyBroadband newsletter
X