Romania has already deployed GDPR as a weapon against its press [1]. I also have a short list of anecdotes of economic activity (start-ups and other new market entrants) that would have happened in the EU but, in large part due to compliance costs–including GDPR–wound up happening outside the EU.
Giving people in power broad discretion with the law and then counting on them being nice is a delicate strategy. It counts on every administration being benevolent.
> Romania could just have used another law or just made a new one to harass the press
There is a big difference between using the authority of the EU, through an EU regulation, and passing a domestic law to go after people you don't like.
More broadly, this argument can be made against any over-reaching law. Just because some hypothetical law could be bad doesn't make an ambiguous law granting widespread power to select bureaucrats okay.
The information is requested by the national GDPR enforcer so it bypasses the prevention written in the GDPR about news leaks.
Now there's a trial going around with this which blocked any further spread of that information until it's solved. It can be easily seen how the GDPR can be weaponized.
So the pretext they're using is that they want to see the information to make sure that the news organisation is not selling it or mishandling it to other third parties. In the process, they'll be able to get the information and maybe it will go to the people involved in the corruption charges (which is the head of one part of the Parliament).
For example, can't you check for all data to verify that the business is not doing anything with forbidden individuals or countries? (think OFAC)
I don't think GDPR allows anything more than any other law.
It's like a factory that dumped toxic waste into a river complaining that, because of a ban on dumping toxic waste into rivers, they now "have to" dump them to nearby meadows instead, and that makes local customers unhappy.
"Detrimental effect on user experience" is an intended effect that clearly signals the company doesn't want to stop abusing its users.
The status quo where corporations make vast profits peddling ever finer-grained user data unbeknownst to the consumer with no oversight is not good. A cultural shift is necessary. I'm glad to see the EU has the stones to tackle the issue because there is zero political will stateside for any political action other than driving corporate profits masked by populist appeals to xenophobia and whatever other irrelevant distractions they can cook up.
Every business: "Stuff in here causes cancer."
Every customer: "Okay."
GPDR:
Every business: "Hey, we use cookies to provide a better experience. That okay?"
Every customer: "OK."
They're not required to unless they're using cookies for something other than providing better experience. Also, that's cookie laws, not GDPR.
It's more like:
GDPR: "We see you doing X, Y and Z which are pretty abusive. We want you to not do X, Y and Z, but if you absolutely must, you can only do that to volunteers and you can't deny service to people who do not volunteer. Oh, and it really must be opt-in."
Every business: "Hey, we do X, Y and Z. That okay? [x] no >>> [ ] <<< !! YES PRETTY PLEASE".
GDPR is a massive win for the individual.
Cookies are a separate law and entirely unrelated to GDPR.
Also the annoying "this is what we are doing, you have to agree to this to proceed" is explicitly forbidden for the GDPR. So your criticism does not apply.
As an American who spends a lot of time in Europe, what I have noticed is that a majority of local news sites in the US block me from accessing them using IP geolocation.
AFAIK, no independent lawyer can sue you for violating the GDPR. Only the German regulatory body could sue them.
Now I don't know German law, as I'm not German, but it felt like they were really afraid that it could happen.
The problem comes when a nation decides to use those rules in a way that is detrimental to the populace or a service they see as troublesome.
law need to be tested trough time, because it will be used by the next party in power for hundreds years, whether you like the party in power or not.
the only reasonable way to reason about law is full on pessimism.
it's like we already forgot the tyranny that was going on less than a century ago and was acquired through escalating legal abuse.
I don't get it. How is GDPR an attack on general purpose computing?
Ya lost me on the reporting to the mothership thing, that is definately what many power centers would like, for example, non-DRM 3D printers that can cheaply print metal objects will be reserved for criminals in countries controlled by repressive regimes because they can make effective life saving tools.
There's just one large company that decided to block EU visitors: Tribune Publishing[0]. Yes, them blocking Europe is bad. Them owning so many local newspapers that this decision even makes an impact is a bigger problem.
I'm not saying that they're the only ones blocking Europe, but I am saying that we wouldn't think of it to be as wide spread if it weren't for Chicago Tribune, Baltimore Sun, and LA Times (among others).
Examples:
* Tribune have troncked Europe because their data control is jazzy.
* Google should really tronc China - fight the Firewall!
They are not blocked. They have chosen to take their services offline because they don’t think changing their business model such that it no longer depends on aggressively tracking their users is worthwhile or cost-effective. Which is fine by me imho.
I don't agree that if a business chooses not to operate in a country, because it's unwilling to spend the money required to comply with the country's laws, that that is equivalent to censorship.
Another person's personal information is not protected speech.
I was fine with that transaction. In fact, I would rather have them sell my data instead of charging money.
Consumers have a choice on whether or not they want to go to these sites, it's not like they are forced to give away their personal information to news sites.
I would say the GDPR blocking news sites is a net negative because it denies consumers the choice to read news stories.
And I always thought (back in my more naïve days) that I read the site in exchange for being advertised to. Point being, the exact details of the transaction were never shown to the visitors. GDPR fixes that by forcing companies to state the terms of this transaction explicitly, and actually ask the visitors if they're willing to participate in it.
GDPR isn't blocking any sites, it's only disallowing a very particular way of getting users to give up their data and then monetizing that data. Nobody is entitled to their business model working forever, and some companies prefer to shut off a large segment of their market instead of updating their business model. It's their choice.
*metaphors can get quite silly
Self blocking in response to a law to avoid the penalties under the law is being blocked by the law.
That's all there is to it. GDPR isn't banning news sites, or other companies; it's banning a very particular set of antisocial business practices.
The problem isn't only adjusting business models. It's proving you've adjusted your business model to twenty-eight EU regulators. If one of them misbehaves, you now have to wage a legal fight in a foreign jurisdiction. Against those costs and risks is a minimum required revenue. If that revenue doesn't exist, it doesn't make sense to serve that market. Regardless of your business model.
If anything, major players deciding not to compete in a market is good to my mind, as a means of increasing a diversity of business styles. Laws like this make businesses pay for the actual cost of thier hidden externalities.
More seriously, GDPR should not extend beyond its jurisdiction. It does though, and there are consequences. Blocking european IPs cost (loss of revenue) must be balanced against compliance costs.
Claims that "they've had N years to prepare" are specicious, if for no other reason than they aren't bound by the specific law. Meanwhile the law introduces a new, potentially large, liability. Which results in companies self censoring by geolocation.
This is what you call an unintended consequence. Remote access to quite a few resources outside of Europe is likely to be restricted should this pass into EU law. As we like to say here, elections have consequences.
FWIW, I support the aims of GDPR, and wish we would get a sane law on this here in the US as well. But I don't want our law extending to others. That would be unfair to them.
The US is probably the biggest "exporter" of laws that are forced down the throaths of all other countries.