Super Monday Night Combat wich was developed in the US by Uber Entertainment [1]
Ragnarok Online terminates the access from Europe. They are in Korea. [2]
1 https://steamcommunity.com/games/104700/announcements/detail...
Super Monday Night Combat wich was developed in the US by Uber Entertainment [1]
Ragnarok Online terminates the access from Europe. They are in Korea. [2]
1 https://steamcommunity.com/games/104700/announcements/detail...
There are plenty of devs out there who were running things probably at a loss, but for the sake of their community and users. Sure a few bug fixes here and there was a pain, but it was so small that it was worth it to make a couple people happy. Now they have one big reason to not keep it up.
Our dependency on services that will go away is a problem, but I'd prefer we'd search for different ways to preserve software once unmaintained. Government requires authors to send a few copies of books&newspapers to libraries... maybe something like that with source code?
The actual law is here and it applies when you offer services or goods to people in the EU or if you monitor their behavior in the EU.
The recitals are a pretty good commentary to clear up the law, the same recitals will be used by regulatory bodies and judges later on, as a guideline.
But they are not law. The law says anyone "in the Union".
Afaict from summaries on court cases in germany, "offering goods or services" definitely means you have to have more than accidental contact with EU customers. Monitoring is hopefully obvious.
The law says anyone in the EU (or is it EEA?) that you're interacting with.
Article 3:
> 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(This also seems to mean a forum with no monetary value at all, but that's another issue.)
The thing is, if you want to do business in the EU, you better know the legal system there. The US forces people in the EU to adhere to their legal system all the time.
Why? That's such a silly thing to assume. It's possible I've targeted no one by location or nationality.
> The thing is, if you want to do business in the EU, you better know the legal system there.
How is a silly forum a business?
It's not about targeting but about offering services to people in the EU. A silly forum that has a few EU users is beyond incidental/accidental contact and will have to adhere to the EU laws.
A silly forum may not be a business but atleast under german law it can be classified as business-like or otherwise commercial even if you don't make any money on it.
Atleast under german law, you are business-like if you offer a website beyond personal interest (ie, a webpage about you, your family or your hobby). A forum is certainly business-like.
The same forum can still be non-commercial, you don't have to make any money to fall under business-like.
In total, a non-commercial entity, which is business-like, and has more than incidental EU users will fall under GDPR.
>They've made a law that applies extraterritorially which requires knowledge of European cultural context to interpret correctly!
I'm sorry, the US made extraterritorial laws that require US cultural context to interpret correctly. You don't get any special treatment here.
If you save data beyond what is strictly necessary to conduct business, like doing analytics, then you will need to ask your EU users if they are OK with that. If you don't want to do that you can simply exclude EU users from any analytics.
Or exclude them from google analytics. Wouldn't be a giant effect.
For example, IP address is PII and if you derive city, region or country from that it becomes personal data. Now if you are a small project or startup there is high chance that you are using some of the external analytics tools like GA or mixpanel(as building a good analytics tool is an effort on its own). Now you have to take care of data like country there as well and be very careful that you delete data like this as well.
I don't think city itself is a personal data. You could use user's IP address to get the city and then discard it and this way you know user's city but don't have to keep their IP address.
Google Analytics can be a problem; Google or someone else should make the analytics that doesn't store IP addresses.
And I think ISPs should randomly rotate IP addresses of their customers so they cannot be used for identification.
Quote [1]:
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’);
I think that soon there will be extensions for popular servers that implement something like this. I wish it were the default configuration.
Also I think if IPSs rotated IP addresses among their customers daily it would not be a problem at all.