You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely.
> Is the EU going to extradite owners of these businesses?
Extremely unlikely, besides that would require the cooperation of the other country. But - and this is interesting - the other countries typically expect the EU to cooperate with extraditions when the law is broken and we do. So who knows.
> Are EU courts going to issue default judgements on businesses and individuals?
Against individuals: Unlikely, but it could happen, against businesses, that's typically how things go when one party doesn't show up.
But note that for that to happen you first have to ignore the regulators for long enough to get them really pissed off, an action I would recommend against.
Would be easier if Europe had a coherent voice. You got the former Eastern Bloc countries desperately clinging to the US (because they, rightfully, fear that Putin will screw them over), you got the UK which is trying to not fall apart due to Brexit, France is... France and Merkel is trying to prevent the worst of the shitshow, even though she's miserably failing at that (and under heavy pressure from the AfD nazis and her own sister party which is openly copying the nazis).
In addition, Europe is so damn far behind the US when it comes to military power - jeez, German army is practicing tank shooters with broomsticks as munition, the NH90 marine helicopters are not allowed to fly over water and we all know what a fuckfest the A400M is. No money, no competence, but it wasn't a problem since WW2 as the USA had always covered the EU... now that Trump is, well, being Trump the EU has yet another giant problem to tackle.
As a European, I consider this a good thing.
Would like more spending to make sure soldiers don't die due to shitty equipment, but still largely fine.
I am ideologically more aligned to pacifism, the problem is that it does not work in a world of wannabe highschool bullies (USA, China, Russia, Iran, Saudi-Arabia, Qatar) vying for regional dominance.
Europe is so damn powerless and underfunded that we cannot even ensure that basic human rights are respected in conflict areas. On a bully stage, the tiny kid will always be the one that's bullied. No matter how economically powerful the EU is.
They have a pretty easy to defend position.
To be honest I used to think you were just a shameless self-promoter like almost everyone else, but in this case you've risen to the occasion. Bravo. I think you're now rating quite high in most people's "mental books of good people". Or at the very least, in the minds of people who actually have a strong impact.
I'd love to see the dataset you have access to backing up any of that statement. It must be fascinating.
That would make you a sub-processor.
Yes, like America. This may shock you, but America isn't always right.
That was exactly your parent's point?
Disappointing to see so many EU apologists defaulting to whataboutism.
Ahh yes, one of my favorite logical fallacies: https://en.wikipedia.org/wiki/Tu_quoque
If Jamaica passed a law fining any company that hired homosexuals, we'd consider it bullshit even if they tried to abstract it a level up by only passing it as a local law, and then passing another law saying companies that serve Jamaicans have to have local representatives. I'm not sure why you think this is any less bullshitty a tactic, other than the fact that the law they're trying to push seems more reasonable (which I agree with).
If you don't like foreign markets, don't enter them.
> Against individuals: Unlikely, but it could happen
AFAIK IANAL: GDPR doesn't apply to individuals that e.g. host mastodon instance.
>> Agreed
Not a lawyer too, but I'm interested what makes you (and jbfoo) believe that it doesn't apply to individuals. It's a EU regulation it should apply to natural and legal persons.
Ok, it has an exception for the processing of data by natural persons in the course of a purely personal or household activity but that doesn't mean it doesn't apply to individuals in general.
If you set up a service that operates in the same way as a similar service would operate if it were done by a business then I suspect that you being a private individual is not going to be much protection, after all you are effectively roughly in the same situation as a sole proprietor business minus the incorporation.
If you process data for family and friends then that would most likely be enough to trigger the exception.
So the dividing line in the case of a Mastodon server would likely be whether or not you allow total strangers to make use of the service and whether or not you respect their rights.
However, some non-commercial Mastodon instances are now supporting thousands of users. An argument could be made that operating such instances is no longer a "personal or household activity".
Whilst I would hope that the local data protection agency would side with the Mastodon instance operator, it does put them in a rather difficult situation.
I think this possibility raises a lot of concern for operators of Mastodon instances and other online services.
I get the impression that a big part of the motivation for GDPR is this type of resentment against America.
If Facebook was german there's no way that GDPR would of passed.
So while blocking the EU isn’t required, the other tests they use to determine whether or not you intended to offer services to EU residents are a bit murky. In light of that, what better way is there to make your intention to not serve EU users clear to all than to block EU users? That’s the main reason to do it. This kind of blockade will not prevent all EU users from accessing your site, but it doesn’t matter. You’ll have made your intent to not serve EU users clear, which will preserve your immunity to GDPR.
But I don’t disagree that some EU countries that intend to abuse the GDPR for the purpose of generating massive amounts of revenue from fines may try to make this kind of claim. One of the problems with GDPR is that when you combine unclear regulation with the lack of moral hazard that government agencies enjoy and the financial incentive of massive fines, you create a monster that will constantly seek to expand who and what is covered under it.
Regardless, it’s one more reason to block radioactive EU traffic.
Probably you can offload some challenges to the ad network, if they don't tell you enough of their business, but that's between you and them. For me I'm accessing your site.
You aren’t serving any ads in the case of an ad network. You contracted with an ad network that is within the US and the site on which you served their code is not otherwise subject to the GDPR. Your intent to not serve the EU market is clear.
Note that a common response by foreign banks to FATCA is to refuse to do business with Americans, which is very likely the best course of action. So it shouldn't be surprising when companies take similar precautions because of GDPR.
It's when you start collecting personal data on EU residents, send their personal data to third parties for analytics/targeted advertising, and so on, that things get interesting.
I run a small UK based IT firm. So far I've turned down some of the logging on my HA Proxy instances and stopped logging IPs and user agents in general and a few other things. If I need to do some diags then I'll turn them on again. That's on the long term stored logs (due to backups). So far, my backups are smaller 8)
I do keep very detailed logs with IPs (actually full packet capture) in the ES cluster for IDS purposes but those are turned over (deleted) within a few hours. Less detailed logs last a lot longer.
Or, maybe, just block all of the EU.... probably a lot easier for a small site.
- You make a note that this data is being logged.
- You state for how long this is logged (6 months is reasonable), and justify that time frame.
- You state who else has access to these logs.
- You state what steps you have taken to try to minimize unauthorized access to these logs.
- In a register (these statements should be delivered on request of a law supervisor) you also provide your personal details, which users are affected by this data processing, and your goal (which should be something along the lines of: "fraud prevention and intrusion mitigation" to have legitimate interest. Expect big companies with law firms to push this "security interest"-angle hard, as they try to justify their data processing).
Pretty reasonable, no? It would be nice if the large web logging softwares provide standard options to automatically limit disclosure of PII web logs.
If you have a lawful basis for collecting the information, you're only passing it along to others as necessary to provide your service to your customers, the customers have clearly consented, and you employ reasonable protection of that data... it's extremely unlikely that you're in violation.
And if you were, they'd come to you first with a warning (at least based on past behavior). They're not going to seize assets unless you seriously provoke them.
1: ignore GDPR, you'll probably fly under. And if you dont, fine are scaled for business and people affected, as well as privacy infraction. Encrypt your backups, encrypt PII if you can do it effortlessly, and you're good. If you are not using emails except for checking double inscription, encrypt them too, the entropy is low BUT this is better than nothing .
2: If you have some time and money to spend to try to improve your services: self-report. A public agent will point you the weakness of your data processing.
The entire point is, NO you can't just ignore GDPR. Your lack of action toward compliance is negligent.
Anyone not up to shady activity can afford to wait for the case law and best practices to settle before doing anything.
I don't comply with laws from many other jurisdictions either. Should I start applying censorship laws for China and Saudi Arabia too? Why should the EU be special?
People get used to accepting the stupid cookie law and it becomes a habit, and in a couple of years the law lost it's meaning (people blindly accept cookie law) and no-one cares about "the great privacy laws of the EU".
This is probably how GDPR will end up, no sane person would have the time to read all the privacy notices and the crappy opt-ins to just order food as fast as possible.
Hey I'm starving I need that food ordered now, here's my location so you can deliver food here, I don't give a rat's ass about your privacy statement and clickady clack are there any more opt-ins to check before I can finally order my food?
My feeling is it is going to end up like the cookie law, but who knows at this stage.
GDPR only applies if you are providing a service to a EU citizen. That also explains what EU will do if a company doesnt comply with GDPR (where it should); they will stop the company from providing those services to the EU citizen.
This is also why blocking EU traffic doesnt make you GDPR compliant (I can use a vpn or visit your site when travelling, and then you are still providing a service to a EU citizen).
If the case really is as you say, with just serving http request, then you have no issue with being GDPR compliant, because you dont store and information about the EU citizen. If however you are not just serving http requests, but track the user or otherwise store information on the site visitor, then you may have GDPR issues. But if you do store data about your users, you really should treat the data correctly.
GDPR is common sense, and if you bother to understand it correctly, its fairly easy to be compliant. Though I’d say, the bigger the company the more complex the implementation.
As Americans we're particularly sensitive about having to follow rules made by people who don't represent us and are not accountable to us. This is a totally fair and justifiable reason to be against GDPR even if you agree with its objectives.
That may be one of the most ironic comments I’ve ever heard. I love americans, but as a super power you stick your nose into so many other countries business, directly or indirectly. So, lets just say that argument is not gonna change my view in any way.
I don’t think I am mistaking intent with implementation. The regulation’s written text leavea many details to be answered along the way and the first couple of rulings on GDPR will (hopefully) bring us a lot of insigts into how to interpret and implement GDPR in practice. So I guess no one really knows the implementation yet. Until then we have to go by what is reasonable and the intent. And if you store data on private citizens you better treat it correctly.
A) The law seems to extend beyond the borders of the EU.
B) It's extremely long and vague, doesn't really offer a lot of actionable advice, and nobody outside of privacy lawyers seems to really understand it fully.
C) The penalties are harsh.
Further muddying the waters, the EU and US already have some existing bilateral agreements with respect to data privacy [1], but does the GDPR supersede or unilaterally invalidate these...? Who knows?
[1] https://en.wikipedia.org/wiki/EU%E2%80%93US_Privacy_Shield
Hi guys,
It's Kim from the Best Korea, and we just decided that we are going to allow our people to access the Internet.
There is a tiny little thing though, our internet policy stipulates that for every traffic hit to sites outside our borders, the country of origin either donates 1 nuke or if it doesn't have nukes an item of great value, or a 24 hour TV broadcast featuring me.
A) It covers behaviour towards the citizens (ie passport carrying members) of the EU. It basically says: "please do not be evil" - OK it says a lot more but I think you get the idea.
B) It does cover a lot of ground but it is written in pretty accessible language for such a large and complex subject.
C) The possible maximum penalties are set at a level that will not destroy a serial transgressor but should hopefully deter anyone from becoming such a beast in the first place.
Overall, GDPR is really a manifesto for how people should be treated in the burgeoning data economy. I still find it hard to understand how such a reasonable and farsighted set of regs came to be designed in the first place. As a citizen of the UK, at least I am reasonably certain that the GDPR will stay on the local statute books post Brexit because to contemplate otherwise is economic suicide.
I wouldn't call that a similar law at all, because the spirit of it is so that the government can have access to that data…
That being said, the starting point shouldn't be, "there's no need to imagine that I'm violating GDPR. I only serve Americans". The starting point should be, "I had better imagine that I might be violating GDPR even though I only intend to serve Americans. Are there things I haven't considered? Are there resources I should seek out? As a service provider of some kind, hadn't I better spend a day or two imagining the ways I might run into trouble and plan to avoid it?"
I'm biased for the GDPR, since I think every site should follow its principles regardless of legal obligation, but I don't think the rationale you're proposing is scalable.
I'm not even sure about sane way to map IP address to country. There are some geolocation services, but I doubt that they are 100% precise and probably paid. Also if I'm using geolocation service passing IP of the incoming request, does that mean that I'm already violated someone's privacy? This is weird.
Its your favorite dictator, the leader of Crazystan and from 29th of May 2018 I ask that from that date, for every site accessed by citizens of my country I require the hosting company to send one employee to be sacrificed to our mighty gods.
Failure to comply will attract a fine of 50 Gazillion dollars.