Why You Can't Just Block EU Visitors, EU Customers, or Any EU Traffic Under GDPR
gettingemaildelivered.com
gettingemaildelivered.com
After thinking long and hard about the GDPR the part that bothers me the most is the expectation from the EU that foreign entities enforce their regulations because the EU cannot bare the political consequences of doing it themselves.
Imagine if China decided that Chinese citizens accessing foreign servers was a breach of national security due to the ability of these foreign servers to collect private browsing information, and imagine if China decided to make laws that fined these foreign entities in violation of their laws. It would be a fucking joke and it would be ridiculed internationally for good reason. China obviously knows this and they are prepared to get their hands dirty and implement the Great Firewall of China because they have no problem appearing as a controlling and authoritarian state.
So why doesn't Europe just do what China does and build their own firewall? If they really wanted to restrict collection by foreign servers which exist in non-EU jurisdictions and apply the regulation internally in the EU then they have the technical capacity to do so with a firewall.
Europe just can't bare the consequences of building such a firewall because it would destroy them in the court of public opinion. If EU citizens suddenly lost access to American services all hell would break loose. On a more political level the EU is a place which is generally known as being liberal and open and the construction of a mechanism designed to enforce their regulations by closing them off from the outside internet would be the construction of an authoritarian tool of censorship and restriction of freedom.
That sort of thing happens all the time - except the US is usually the one coercing foreign entities. Remember the DMCA? ThePirateBay's raid in 2006? Or the Megaupload debacle? Or how Japan was pressured by the US to adopt stricter child pornography laws?
Note, I'm not saying the people behind these were supporting moral and noble causes that the US was wrong to clamp down on. I'm certainly not saying people should comply to China's expectations on free speech and flow of information. Simply, if you feel infuriated that a foreign power is enforcing its worldview and related regulations onto you, an American citizen, know that that's what literally everyone else has been experiencing for the last decades from the people you've put in power.
But then, what the EU is trying to enforce here - more power to Internet users, essentially - is fairly benign when compared to what other foreign powers would like to enforce. If there were matters of infuriation to be had on that account, I'd start with the Mariott debacle [1].
It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules.
The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks.
The problem with the GDPR is that it’s extraterritorial application as expected by the EU is also extrajudiciary.
I would have no problem with the EU seeking ways to expand GDPR through new legal frameworks which the people that would be impacted by these changes can actually control through their own political system.
What I have a problem with is the EU essentially forcing compliance through extortion and sooner rather than later it will employ the companies that the GDPR was in spirit intended to protect us from to enforce it.
I don’t see the EU being able to enforce the GDPR even internally without essentially deputizing the likes of Google, Amazon and PayPal to enforce it across all of their customers in order for them themselves to be compliant.
Even with the fines possible under the GDPR the EU can not enforce compliance by targeting 100,000’s of small companies without going essentially bankrupt. It can however effectively target the big ones and worse make it impossible to operate within the EU without using their “GDPR complaint” platforms.
The GDPR might be a great thing on paper and even in spirit but the uncertainty and the inability to enforce complex regulation on a mass of small entities would likely cause it’s real world repercussions to be quite different than from what was imagined or intended.
>It’s applied through an established legal framework either through bilateral trade agreements or through WTO rules. >The majority of copyright enforcement outside of the US has nothing to do with the DMCA but rather copyright holders using local legal frameworks.
That means essentially the same, in effect. Very few countries have copyright laws that do not align with interests of US lobbies. If any country with significant partnerships with the US decided to tell "screw the MPAA, you can now download anything from the Internet" to its citizens, the said lobbies would pressure the US government to pressure that country through the trade agreements you mentioned, until it relented. This is something that actually happened, during e.g. the TPB raid. We can argue about the moral legitimacy of such things but the reality of the matter is, it's all power plays.
>What I have a problem with is the EU essentially forcing compliance through extortion and sooner rather than later it will employ the companies that the GDPR was in spirit intended to protect us from to enforce it.
>I don’t see the EU being able to enforce the GDPR even internally without essentially deputizing the likes of Google, Amazon and PayPal to enforce it across all of their customers in order for them themselves to be compliant.
>Even with the fines possible under the GDPR the EU can not enforce compliance by targeting 100,000’s of small companies without going essentially bankrupt. It can however effectively target the big ones and worse make it impossible to operate within the EU without using their “GDPR complaint” platforms.
Three objections:
-The use of 'extortion' is rather harsh - the EU isn't out there to suck money out of the poor American startups, they simply want them to treat user data in a sensible manner. Now you may object to what is considered 'sensible' just like someone in Sweden (e.g. anakata) may object to what is considered a 'copyright breach' but the point here is that they are not looking to make money from fines. If you are found to be noncompliant you wouldn't get sued by troll lawyers, you'd get a couple warnings along with guidance on how to be compliant again. Fines are simply there to say they mean business so people stop ignoring the regulations like they've done with existing country-specific ones for the last decades. Again, power play.
-I really doubt Google, Amazon and Paypal would cut off the entire EU market just to avoid going through the hassle of setting up an updated privacy policy. The EU population is 500 million, way more than the US. More likely, they'll do a cost-benefit analysis that will tell them it's worth paying their lawyers to do the compliance work. It's not actually a big deal. Also, these tech giants do have offices in the EU, usually in Ireland, so it hardly counts as extraterritorial extortion.
-As for the poor hundreds of thousands of companies - well, see the above. They don't want your money, they want compliance. A fine is the absolute worst case if you are repeatedly and outrageously negligent on a very large scale. The most likely case, however, is that the GDPR isn't going to care about these startups because the European public doesn't care about them either. I don't mean to be harsh or condescending, but while lurking HNs and reading headlines about such and such service shutting its doors to European user, I couldn't recognize any of the names. No one is going to sue your ten-man startup that develops a niche/superficial app whose use cases only fit twice that many people to a EU court. It is far more likely that it will fail by itself, because that's what startups do. Should it grow, however, and be in a position to deal with enough customers data that negligence or nefarious intent when handling it would cause significant harm - that's where actual GDPR enforcement would step in.
You may say: 'but there is no guarantee', 'it's all very vague', 'this much vagueness only opens the way to corruption and preferential treatment', but that's mostly how most of the law is written here in the EU - clarity of intent and concision over clarity of wording and exhaustiveness. Against all odds I'd say it's working out pretty well for us and the vast majority of people here do not feel any defiance toward their institutions (at least when compared to other countries), so I feel confident in the GDPR's enforcement, jurisprudence cases and their future effects on the handling of my data. You may feel slighted that a foreign entity, its views and its legal culture are being imposed on you, though, and I understand. Again, power play.
You can't just build a firewall for data, especially as users will actually willingly export data. You look at the GDPR from a business side only and miss that it is about personal data and how that data has become a commodity that is being traded, mishandled and often abused.
So far none of the US-based services that I use has shut down or blocked me just because I'm under the protection of the GDPR. Those websites we see blocking users have either no interest in the European market (fair enough) or are indeed using shady practices.
That's based on international law, while there is no such thing about privacy
Universal Declaration of Human Rights: Article 12
[1] https://en.wikipedia.org/wiki/Universal_Declaration_of_Human...
The law does not mention privacy, correct, but its entire rationale is based on the idea of privacy rights.
The regulation isn't about fucking IP addresses, it's about big data collection information about, what you buy, where you go, who you are friends with and doing shady things with that data.
This can be achieved with more sane, pragmatic regulation.
I might be reading this wrong but you are saying that as a privacy valuing individual GDPR your issue is that because it is a single entity - EU has come up with the law. And the solution is not that every country in the world should pass privacy laws rather European countries should build a China-like firewall?
I can sell a wine picker to an EU customer without worrying about any regulation as they are the responsible entity.
I agree with you. Fortunately, at least in the case of GDPR, we don't have to worry about it, as this article is completely off base legally. While I'm sure there are many in the EU that would love for it to be illegal for foreign entities to block EU residents, here's the reality of this. Under Recital 23 [1], you are not subject to the GDPR if you are outside of the EU and it cannot be established that you "envisage" servicing EU customers. This Recital explicitly states that the mere accessibility of a foreign website from within the EU does not by itself subject the site to the GDPR. In other words, none of the GDPR applies to foreign websites that are blocking EU residents, because they have shown that they don't intend to serve EU residents. Since the law doesn't apply, its restrictions on automated profiling don't apply either (and you can legally store their IP address and any other information gleaned from HTTP requests for eternity and not bother responding to their "nightmare letters").
I find articles written in bad faith like this odd on a number of levels. Do people in the EU really want to falsely make sites in other parts of the world believe that they must comply with this absurd legislation? It's almost like they are trying to say "HA! We have power over you and can force you to do whatever we want!". It seems like a weird and desperate power struggle.
Block the EU, and GDPR doesn't apply (as long as you don't already hold EU resident data). It's as simple as that.
If you aren't storing the data tied to a specific person, you aren't profiling, otherwise "receiving an http request and logging that" would violate the GDPR, which it doesn't.
Second, country isn't pii under the GDPR, the location would need to be more precise to be relevant.
I think blocking the entire EU is lazy, but this is the non-est of nonsense.
Logging HTTP requests is allowed not because it contains no sensitive data, but because you have a legitimate interest in logging usage of the web server in order to defend yourself against computer crimes, for example. What you aren't allowed to do is retain these logs indefinitely as if they weren't sensitive.
Your premise appears to be flawed in the context of established case law. IP addresses alone are not considered 'personal data' unless you have the capacity to readily add other information to add color. See below:
https://www.whitecase.com/publications/alert/court-confirms-...
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and
> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.
> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.
The vast majority of entities do not meet the requirements for #2.
That said, doesn't this assume the user has a dynamic IP address? You can't easily tell a dynamic from a static, so wouldn't you have to plan for the worst?
But if it 1. isn't stored && 2 there is a good reason (e g. be able to block attacks) && 3. it isn't abused for any other illegal reason then I think they are fine, no extra consent needed to store the IP address temporarily.
But then the law has already been followed.
Edit: also I wouldn't expect anyone outside of IT to care if something is "stored" in RAM or on disk. Kn this case that might be a good thing.
Preamble paragraph 30: > Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
Without the time stamp and IP information you have zero chance at attribution during a security event.
PCI and a bunch of other regs require log retention for 1 year or even more for this reason.
No sane western corporation will willingly eliminate an entity about the site of USA out of spite and take a profit hit just because of new PII protocol. Just look at FB, Google and the rest of the advertising companies. They bent over backwards trying to accodomate the law.
But: GDRP will filter out businesses that existed in the legaly grey area because technology was faster than the law in this type of busines competitive advantage features.
Every single blog post had a set of people raging that we were assholes for doing this, but the reality was the cost of compliance just didn't make sense for the MVP. It was high 5 figures in cost which was just too much at the time. If we had achieved product market fit then the obvious move would have been to do that compliance to gain more customers, but we never quite got there.
I doubt GDPR gets to that level of cost, so the ROI looks a bit different. But I still think it's a reasonable decision to say "I simply won't do business in the EU because it costs more than I'll gain". A lot of companies also don't bother to go through the effort of printing the dual language labels required to sell their products in Canada, even though it's a decent sized market close to the US.
Tech, specifically the internet, has grown without regulation for a long time. But that era is over. These kind of decisions are routine in non-internet businesses where distribution, borders, and regulations exist. I suspect we're going to have to think a lot more about this in our work in the future.
That's true for big companies.
The calculation changes for small companies, and really changes for hobby projects.
For small companies one mistake and they could be out of business. So its easier to avoid the problem to begin with.
Maybe, maybe not. It all depends on your business and your market.
We're in the UK. If we'd understood how much trouble the EU VAT rules were going to cause when they came in three years ago, we would have excluded customers from the remaining EU member states rather than adapting our systems and processes to comply -- and it would have been one of the clearest and easiest business decisions we'd ever made.
Given the amount of uncertainty and liability involved with the GDPR, it seems entirely possible that some non-EU services will take a similarly conservative approach.
Considering how many US-only startups I see on HN every day, this is patently false.
Did they? Isn't Facebook's GDPR flow "agree or fuck off forever"? https://techcrunch.com/2018/05/25/facebook-google-face-first...
Two things: they are still operating in EU, and it didn't go well for Microsoft itself when they tried to disobey EU.
So, we'll see how it ends.
Probably not. It would make sense to roll out services on a country-by-country basis, limiting exposure to those where the national data regulator is known. EU lobbyists and lawyers were just granted a massive break.
that's ridiculous, small companies grow by targeting audiences and computing expected future cash flow
the cost of legal action is a risk that affects the bottom line (it also affects reputation, but for new laws, the issue of reputation isn't as relevant because the laws haven't been tested by the society yet, they are fresh laws)
the idea that a corporation is "insane" for estimating the future cash flows and legal expenses for providing services to an audience is comedy
no, that's how a good, well-run, intelligent organization grows
the GDPR represents a risk to the bottom line when services are provided to European customers, and that risk must be factored in; this risk directly affects the corporate financial structure, and investors may have some input in terms of when and how to extend service to the EU
pretending that spite or some petty or small emotional frame of mind is required to apply basic sound financial principles of running a business is bizarre
when running a business, you are expected to win, and winning means not going bankrupt because some psycho lawyer in the EU wants to make money by destroying your reputation, destroying your life, and destroying your business
GDPR gives fuel to psycho lawyers. If you don't want to get sued by psycho lawyers, don't provide services to people who hire psycho lawyers, don't provide service to the EU.
If you have deep pockets and you know the expected cost of fighting off psycho lawyers is less than the expected revenue of providing service to the EU, then it may be time to expand to the EU; you and your investors should both have an understanding of the risks and rewards of expanding service.
Let me repeat: this is not an emotional matter, it is a matter of doing business.
Anyone really believe they’ll litigate against companies that block them entirely? That want nothing to do with the EU market as a result of this law?
I seriously doubt it, but this is a great example of the 2 years of legal arguments and debates happening in companies because of GDPR.
All it takes is a single populist data regulator in one of the EU's twenty-eight members,. Will they win? I don't think so. But in the meantime, you'll be dragged through costly regulatory negotiations. Those negotiations would become much more expensive if one had any European users.
Litigating on this particular issue would be an incredible stretch though. Offends basic sense of fair play imo.
If Turkey gets EU membership, it would be a hoot to see how Erdogan uses this law.
At least litigation has a clear end. The problem is more endless requests for information, each requiring research and drafting by expensive EU lawyers. A burden irrespective of whether you did anything wrong.
One of the EU's twenty-eight members will try to extradite an American executive. That will be shot down by U.S. courts. We'll throw tariffs at each other for a few months until whatever administration that happens under negotiates a compromise.
GDPR only fines and sanctions. Dont hold EU assets and you would be ok.
I have US-only clients currently freaking out because they think they are going to be sued into oblivion, but I can't imagine they have anything to worry about (we've been giving them the whole "we can't provide legal advice, talk to your lawyer about what you need to do and we'll work with you to make it happen" line)
That's seriously optimistic. From what I can tell, most companies realized about a week and a half ago that this was going to be an issue and freaked the hell out.
I'm still getting a stready stream of better-late-than-never GDPR emails.
E.g. the right to be forgotten, EU has it US doesn't. sanctions when you forget to disclose a massive data-leak on your private escort website? $0 in the US, hopefully very expensive in the EU. Your nemesis publishes lies on the net? EU helps you have that deleted. Your supermarket tracks your shopping and knows you are pregnant before you do (this happened in the UK!), won't happen anymore in the EU. Shady Sunshine Ltd bought your email address and purchase data to spam you, bad and expensive for them. facebook won't allow you to continue unless you agree to face-recognition? This might be the first case in courts.
Wait and see for the good sides once the panic has quieted down.
The cookie banner is different because everyone knew it was completely meaningless. Whether GDPR is or not remains to be seen; it's certainly not an "everybody knows" situation yet.
But remember: The GDPR protects people's data. Companies aren't people (at least in the EU).
Most Americans would prefer not to have European court judgments against them. That said, I agree this is absurd. If I choose to do business in your country, that is one thing. But extending that to blocking my right not to do business in your jurisdiction is silly.
And if the EU started going after companies/individuals who don't have presence in the EU because they claim "we say so", well, then the rest of the world can play that game to.
Maybe the rest of the world will put sanctions on EU bureaucrats if EU bureaucrats start trying to shake down companies that have no presence in the EU.
Using the banks to cut off commerce across borders is an enforcement action for what countries agree are crimes - terrorism, money laundering, fraud, etc. It takes a lot of political willpower and negotiation to use that tool. I sincerely doubt it would be used against American websites that choose to not serve the EU.
And they got cut off from PayPal, and the credit card networks for quite a while.
If the US can use it for selling a product in a store that’s entirely legal to sell under EU law, then the EU can also use the same rules for GDPR.
For the other cases, EU uses intentional law. EU-U.S. Privacy Shield data sharing agreement for example.
In the case that the law can't be enforced directly against the violating company, EU can enforce it trough companies that provide the infrastructure for handling user data and have dealing with EU.
This includes trackers, online ad-selling companies, clouds providers, CDN provides, ISP's that have physical presence in EU and who handle user data when people visit the site. Like Google, FB, Amazon, cloufare, Akamai, Rackspace, Digital Ocean, ......
Also, if the company takes any money from the user from EU, they can get into trouble when banks with business in EU stop transferring payments.
Only if the company is handling all user data using companies with no EU presence and are not violating any US-EU privacy agreements, they should be safe.
It will become a major international incident if people try to do this.
Stuff like https://www.reddit.com/r/technology/comments/ka26b/paypal_bl... (a german company, in germany, selling cuban cigars, to a german, got as result threats from their payment processors (US companies)).
Or cases like this https://en.wikipedia.org/wiki/Society_for_Worldwide_Interban...
The US has constantly stolen money from EU citizen doing business in the EU for violating US laws.
And then there’s the Kim Dotcom case. Also similar story, US enforcing US law in New Zealand and Germany.
The US deserves some of its own medicine.
The only simmilar case I can think of is the Isreali law which prohibits entry into the country by anyone supporting BDS. Notably, in this case they are not even claiming that everyone on the planet is required to not support BDS; because it is obvious that they have no jurisdiction to do so.
EDIT: You also have China and Saudi Arabia who have internet restrictions. However, they also do not claim jurisdiction over foreign sites. They only require compliance by sites that operate within their jurisdiction; and have built the infrastructure to enforce their digital border.
If you had followed EU policy discussions over the last 10 years, you would realize this is about creating a single, unified online market.
Meaning a citizen living in Poland should have access to the same online services as a German, unless there are valid reasons for denying him.
In short: the opinion expressed by that link appears to be plainly wrong as the organization using IP addresses to restrict EU traffic for the sake of GDPR would need the ability to actually identify people from that information, a power arising from access to other information. The vast majority of entities lack that additional, so for them, IP addresses are not 'personal data' under existing case law.
In long: I'm not providing legal advice, only forwarding details (again, non-representative) conversations I've had or been party to with various lawyers on this topic. Notably: the consensus opinion is that determining a potential IP range is specific to the EU is not the same as geolocating them as that location information is not specific enough to determine who the person is, and partly as a result of a lack of this capability and others, IP addresses cannot alone be determined to be personal data.
Related: https://www.whitecase.com/publications/alert/court-confirms-...
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and
> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.
> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.
By precedent (unless I'm missing more recent case law), for the vast majority of entities possessing IP addresses e.g. through request logs, an IP address is not "personal data," and determining the continental whereabouts of an IP would therefore not be considered "profiling."
I'm not a lawyer; I'm only relaying what's come up in conversation between attorneys covering the topic. I'm open to seeing the position I'm relaying above proven wrong.
> The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Further, the GDPR has rules around two things you mention, but they are different: (1) profiling; (2) automated decision making.
Profiling has three elements, as described by the A29 WG:
* An automated form of processing.
* Carried out on personal data.
* For the objective of evaluating personal aspects about a natural person.
As for IP addresses, mapping them to an ASN is fully anonymized. Since an anonymized IP address is not personal data, using it is not profiling.Blocking users from using your site is highly unlikely to have the "legal effects" enumerated in the above clause.
CJEU case law has determined that IP addresses are not considered "personal data" except in certain cases (https://www.whitecase.com/publications/alert/court-confirms-...)
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
> 1. there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and
> 2. the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.
> On the facts, if the BRD has the legal power to compel the relevant ISP to disclose sufficient information to identify Mr Breyer, then Mr Breyer's IP address will be personal data in the hands of the BRD.
The vast majority of entities do not meet the requirements for #2. Therefore, automatic profiling rules could not apply since the automatic analysis being performed is not against personal data.
GEO-IP is not a profile unless it is stored with additional data.
If they don’t do business in EU, then they dont have to follow eu rules.
> which produces legal effects concerning him or her or similarly significantly affects him or her, such as automatic refusal of an online credit application or e-recruiting practices without any human intervention.
Blocking someone from reading a news website is clearly not a decision along these lines. Obviously this would need to be tested in court, but I would bet on it being allowed.
Also, the GDPR only applies at all if the business operates in the EU. If they clearly don't (e.g. by blocking European visitors) then the GDPR does not apply and you obviously can't use text in the GDPR itself to prove that you can't do that.
This article is nonsense.
Fun fact: The word "citizen" doesn't actually appear in the GDPR at all.
Being able to do certain kinds of background checks or financial risk calculations is the first use case which comes to mind.
Note that EU law does apply for visitors, so look forward to data tourism!
Making it undesirable for some businesses to operate in your country is part of the cost-benefit analysis you have to do when passing laws.
EU will regulate what businesses doing business in the EU can do.
All other talk is just noise.
Wrong. Just because a few guys vote on something and then write it down on a piece of paper doesn't make it lawful.