There are many, many american sites that just block the whole EU IP ranges becaus they don't want to deal with GDPR.
There are many, many american sites that just block the whole EU IP ranges becaus they don't want to deal with GDPR.
It literally just asks that you don't spy on people. That's it. Not spying on users? Great, you don't even have to do anything.
I would be extremely surprised to see any attempt at enforcement against a website that didn't collect PII on some technicality such as not having the right footer or a contact person.
Sure. But that is much easier said than done. Especially if your previous strategy was to just keep everything, because storage is cheap, development cost is expensive, and then the data will still be there if the customer decides to return in a few years.
And in many (most?) cases it's not like you just have a single file with all the user's data, that data is spread around in many different database tables , and possibly even multiple databases. The development work to figure out how to clean everything up, without accidentally deleting anything wrong or leaving anything out can be a considerable amount of effort.
It's also not always black and white who data belongs to. If I upload an image onto a document that was shared with me, should that image be deleted if I cancel my account? What about something I posted publicly on a social media platform? Or posted privately in a group chat or DM? Does it make a difference if the content of an image or text I wrote included PII? Hopefully you have a lawyer that understands the nuances involved.
For example seemingly innocuous implementations like loading fonts directly off Google Fonts without consent (i.e. providing Google with information about visitors' browsing habits) would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking.
The American in me says that sounds like "someone will definitely complain about it, eventually, if only because they're hoping for a payout".
But maybe it's just because the US environment is so hostile that they assume it's the same in the EU.
But national regulators in the EU don't waste their time with foreign companies that might by oversight not be totally compliant since they're not even under their jurisdiction (worst is they could be fined and have to pay it if ever they incorporate in that country in the near future? Nobody's going to waste time in that).
And nobody can sue a company on gdpr grounds and get a payout. They're only fines, they benefit to central states and are a negligible amount in regard to national budgets.
"Complying with the GDPR is a huge undertaking"
"GDPR compliance (occupies) a huge amount of IT time and resources"
"Moving your organization into GDPR compliance is a process you ideally started long ago"
The article links to some ICO GDPR data processing checklist, which is a list of 18 different processes you need to have put in place.
"The GDPR is made up of 99 articles that provide a detailed description of the regulation". <- 99 different articles to understand and adhere to ...
"[I]t is impossible to provide an exact prescription that will guarantee your organization is in compliance"
"One of the most onerous obligations of the GDPR is to provide “Data Subjects” – the people whose data you are processing – with access to the data that you hold about them (Article 15)",
"They can also request rectification or completion of data if it is inaccurate or incomplete, and they can request that you delete their personal data"
"This is onerous because Data Subjects can make requests in writing or verbally, and you need to be able to comply with the requests “without undue delay"
^-- All that seems to go against your assertion that you just have to "not track them", if you have to build out a system for everyone to access all data you hold about them, rectify it, delete it, verbally or in writing, without delay.
I'm not even half way through the article and I'm skipping over tons of what it's saying needs to be done, with all the security measures that need to put in place, whether or not encrypted data is needed, breach notification, and so on.
It seems like a heck of a lot more than just "not track people", or a trivial amount of work.
It's a bit hyperbolic to say that you're, "not even half way through the article and I'm skipping over tons of what it's saying needs to be done", when you've literally only listed one thing.
I'm sure each case might be different, but I can't but help to think this is just a cheap excuse to inflate the work that is required ro comply with data Protection Regulation.
I've worked already on a few projects involving data protection, and they all boil down to two steps:
- only store anonymous data. No personal data? No problem.
- if you need to store personally identifiable information, support deleting it on request.
It might be easier to incorporate these requirements at the design stage, but by now this is a very basic set if requirements.
If you don't track people's data, that "system" becomes an automated email reply with "we don't have any data about you".
But if you deal with individuals, probably you do want to collect at least some data that would be subject to the GDPR protections, and it is definitely easier to forget all about it.
The intent of the gdpr is that you think about all of this and not simply store everything to mine, have stolen, leak or sell later on. The problem is that many companies or the software they use is literally build to abuse that data so then it is indeed 'hard' and expensive to comply.
A reminder that we're talking about passing visitors without accounts here, and for logging and analytics there shouldn't be a need to store anything longer than a couple days.
Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.
> GDPR does not regulate “sharing,”
13.1.e requires at least the notification of the recipients of the data. With the requirement about the purpose of use, it effectively regulates sharing.
> since you must process IP addresses in order to serve a website
That's right and that places the IP in the 4.1.f "processing is necessary for the purposes of the legitimate interests pursued by the controller" area which doesn't require consent.
The irony here is that the people who think they’re standing up for GDPR are actually the ones not taking it seriously, while the people who take it seriously are the ones who know what a pain it is to comply with.
That publisher's page lists the third party processors for the documents, (as expected) but not the hosting provider. I'd love to see a counterexample.
I’ll edit to add that the user must be notified that you are collecting and processing personal data, which includes IP address. And the hard part is that you must also have internal paper trails that prove that you have written that notification in full knowledge of all the data processing done on your behalf by all your service providers. Is a data center owner routing traffic to your server? You need paperwork in which they commit not to store the IP addresses of your visitors, for example. That is not public-facing but must be available to regulators upon their request.
That’s the hard part of compliance and what most people skip. They click OK on the standard agreements with service providers and put up a standard privacy template. That is not actually compliant but folks are essentially betting that they are small enough that data regulators won’t ever come call them on it.
That's complete nonsense.
This is 100% not true and would be a violation under the GDPR. You need not share any data and if you do nothing, you'd be violating the GDPR.
> Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.
Nope, this is also not true. At least, it's not just "data requests."
You are in violation of the GDPR.
We need more of the world to implement similar rules so that it becomes infeasible to choose that option.
It seems stupid because just because someone is overseas doesn’t mean they can’t have valid business with a US state or local government. Maybe they are an American who is travelling and has to attend to some official business back home while they are away. Foreigners are allowed to purchase US real estate and incorporate companies in the US, which gives them heaps of legitimate reasons for interacting with local and state governments. In part due to these kinds of issues, many use some local agent in the US to handle government interactions for them, but a person can have valid reasons to engage directly.
I don’t necessarily agree with various official Australian attempts to impose Australian law on foreign non-government websites, but I don’t see how that is relevant to whether US governmental websites permit access from Australia
Here's a analogously real example from current US-Ukraine policy:
> For example, one current social goal in the U.S., given the geopolitical conflict with Russia, is to avoid facilitating activities that could aid the adversary. As Russia has invaded Ukraine, the U.S. has positioned itself in opposition to Russia but not Ukraine. Banks, therefore, need to align with these geopolitical stances, leading to decisions that might catch some individuals in the crossfire, even if they’re not directly involved.
> Financial institutions often interpret this as: if they're not deeply specialized in doing business in Ukraine, they should avoid it altogether. They fear they won’t be able to consistently ensure compliance with these complex directives from the government [especially because there's a chance those directives might change in a week, or a month, or 3 months].
> This creates a split-brain problem within U.S. decision-making. The government intends to say, "Please cut down on oligarch money laundering that supports Russia’s war effort." However, financial institutions hear this as, "Under no circumstances should you fund anything related to Ukraine," including, for example, scholarships for Ukrainian high schoolers—a slight exaggeration, but not far from the reality in some cases.
(source: https://www.complexsystemspodcast.com/episodes/true-crime-ba...)
I personally doubt US state and local governments are specifically targeting Australia in the way you suggest.
I actually doubt they are thinking about Australia at all. I also doubt their legal departments are worried about the Australian government, since the Australian government taking legal action against a foreign government (even a local or subnational one) would in most cases be illegal under all three of international, Australian and foreign law due to sovereign state immunity, and diplomatically they wouldn’t do it to the US because it would offend their American allies. If for some strange reason an Australian government agency had a bone to pick with some US state or county, they’d aim to solve it with the US State Department. Private corporations and individuals are not protected by the same legal doctrines or diplomatic protocols.
I think they just see some option in their firewall config (or Cloudflare or whatever) called “limit countries allowed to access”, they turn it on and add only the US, and then they think “see I’ve kept all the foreign hackers out now!”.
[1]A big troll that I respect.
Most frustrating is not even being able to cancel things like a US streaming service subscription from an EU IP (of course these things usually have no contact email address available either).
Europeans usually have no reason to read these, the only reason I know is that I googled a few of my American friends at one point and kept hitting these.
or cannot afford to. add in DSA and DMA as additional burdens.