CORRECTION: As other have pointed out, the publisher is actually the student newspaper, which is independent from Purdue University itself.
CORRECTION: As other have pointed out, the publisher is actually the student newspaper, which is independent from Purdue University itself.
Yep, and - also ironically - the root of publisher is the same as public, so you want to make something public but you restrict the access to a whole subset of the public.
Besides that, if they had written (without recurring to http 451[0]) a simple message like:
"We are sorry but we cannot serve this content due to the possible non-compliance of this site with EU Laws (GDPR)"
it would have been (IMHO) much more correct/polite.
I read the message "as is" more like:
Hallo, stupid visitor from Europe, you are denied access to the contents because you voted stupid people that wrote stupid laws that we won't respect.
The page served should be reachable even from non EU countries:
https://www.purdueexponent.org/campus/article_aa3e67de-5de9-...
and it has some interesting html keywords in "base":
<meta name="keywords" content="mitch, daniels, mitch daniels, purdue, central intelligence agency, chinese embassy, tiananmen square, zhihao kong">
<meta name="news_keywords" content="mitch, daniels, mitch daniels, purdue, central intelligence agency, chinese embassy, tiananmen square, zhihao kong">
[0] the example on Wikipedia is a good one:
Also, it’s not really censorship — they have to deal with the GDPR headache, one way or the other, just like everyone else. Simply blocking the EU is a blunt but simple and effective way of doing so, and makes decent sense for a site where the interest is 99% local.
What headache? A sensible solution: when EU visitor is detected, don't set cookies. Purdue solution: when EU visitor is detected, block them.
The headache is convincing someone to pay a lawyer to agree that this is the solution when serving content to the EU is outside your publication's mission.
Also: The Exponent isn't Purdue, it's independent. Purdue chose email as their publication medium.
Fortunately there exist a very simple solution: don't gather personal data. Note that it does not necessarily applies to cookies: they are considered personal data only if they can be used to identify the individual.[0] There is exactly zero chance anybody would go after you if you don't set cookies or set them for reasons other than making personal identification possible.
[0] https://www.itgovernance.eu/blog/en/how-the-gdpr-affects-coo...
How do you know that somewhere in the stack of things the server is running isn't something that would set a cookie for some valid reason, and thus trigger the EU's stupid laws?
A positive stop, the redirect to a text page, is far better than a hope and a prayer.
[0] https://www.itgovernance.eu/blog/en/how-the-gdpr-affects-coo...
This started happening even before the GDPR was finalised.