[1] https://www.europarl.europa.eu/thinktank/en/document/EPRS_AT...
[1] https://www.europarl.europa.eu/thinktank/en/document/EPRS_AT...
I would also say though, you have to be a bit careful about "they are discussing" because there are many people across different countries with different agendas, and a huge amount of discussion between people. Your link for example is a pretty good bit of background info, clearly saying VPNs aren't just about accessing porn
> In the corporate world, VPNs are essential for secure remote work, allowing employees to access company systems without compromising sensitive information. For individual users, VPNs prevent tracking by internet service providers, advertisers and potential cybercriminals. They are also used to access educational or entertainment content that may be restricted in certain countries, including authoritarian regimes, supporting freedom of information and digital inclusivity, as censorship becomes more difficult to enforce through VPN use.
It links off to sites discussing possible approaches to age verification which highlights that various approaches in France didn't meet the regulators requirements because of a lack of privacy.
I think this is a different kind of concern about how your products must work compared to worrying that with little to no notice your country may be cut off due to a diplomatic spat from some specific service.
I agree that there is a ton of bullshit as well though. Gotta dox myself with imprints for example, so I cant share my work with people without also doxing myself. Also as a hobbyist you pretty much need all the business documents as well, like a privacy policy even if its just a small public app on the playstore. Also gotta make sure that data of European citizens never leaves Europe and and and... Lots of things to remember.
And before anyone asks, yes I know an imprint usually is only required for businesses, but nowadays pretty much everything could have business intent.
Erm, dude....
- Companies Act 2006
- Companies (Trading Disclosures) Regulations 2008
- Electronic Commerce (EC Directive) Regulations 2002
Applies to business letters, order forms, websites, emails ....Might not be called "imprint" in UK-speak, but its basically the same thing.
I avoid doing any business in Germany these days. I tried to get a VPS from Hetzner but they demanded a copy of my ID and didn't accept that I blanked out my citizen number. Which is actually recommended by our national police for identify theft risk.
I moved to Scaleway instead. Much better company.
Scaleway's compute is more like Amazon EC2.
Hardware I rend from Hetzner is usually 16 core AMD with 128GB RAM and couple of nvme's. Never had single failure. Of course I periodically buy new server, do deploy. Old one becomes standby and standby of the old gets cancelled.
Scaleway's offer of the same computing power is highly unattractive comparatively.
That's exactly what I meant by Hetzner being more traditional.
And this is a bad thing why exactly ?!?!?!
If you respect your users data and right to privacy then you've got nothing to hide by publishing an EU compliant privacy policy.
It might be "just a small app", but I and many other people still very much still "do give a damn" about what the hell you do with my data, where you store it, how long you store it and how I can exercise my GDPR rights.
If they allow you to side load you won't need to make the app publicly available and so won't need a privacy policy.
So, it is a business.
I'm see a lot of "worse" in your comment and not seeing any "better". Can you give some examples of that?
EU: Slowly makes laws with consideration of how much power the largest companies have over consumers.
Surely you can tell the difference between these two things.
We don't have any "ideal" places anymore.
And we need to defend what we support and believe.
I have seen "parallel [dial-up] modem banks" for "lawful interception", then specialized Ethernet cards for DPI, watched traffic analysis dashboard of a REDACTED country live, did DPI on powerful-enough systems myself for personal testing.
I have gone through USENET, flame wars, IRC; did my own MITM, etc. Always knew about echelon, how escrow based Encryption canceled last moment, etc. etc. etc.
At least, the barriers were higher then. These barriers required people to be considerate, well-targeted and selective. Now we don't have any of these. The overhead is almost non-existent for these things.
Doing dragnet operations were costly, and this allowed curious yet good-hearted people to understand the environment they lived in. Now, we're all blacklisted by default and whitelisted as long as we don't touch the wrong paving stone on the internet.
It used to be other way around.
TL;DR: I'm not 15 years old.
But it turn out surveillance works just fine if you only focus on the meta data. Knowing who takes to whom, and which sites people visit is much more valuable (and much cheaper) than scanning the actual payload.
And why collect all that data yourself if ad companies are happy to sell it to you, ie to the government? (Huh, maybe that's why Facebook changed its name to Meta, come to think of it)
It's horrible everywhere. If you're in the EU go donate to: https://epicenter.works/ They're a citizen rights NGO working against all that BS in the EU (and in Austria, where they're from).
First the systems have to be up. Then we can deal with the spying and nonsense.
Utah, meanwhile, has an actual law in place that makes site owners (!) responsible for their users using VPNs: https://www.tomshardware.com/software/vpn/utah-becomes-first...
Oh FFS!
Governments discussing such things doesn't _remotely_ mean there is a political will for them, or that they will be voted into law. Governments are expected to research and discuss paths of legislation (and in this case, come to the conclusion banning VPNs is both harmful and ridiculous).
This is how our democracies work!
Implying government discussions will be approved legislation is, at best ignorant, at worst trolling.
Don't get too much up in your arms about it, any topic about Europe and EU on HN ends up with huge swaths of American commentators seemingly willfully misunderstanding or spreading FUD in these comment threads.
You'll get used to it eventually, so you can identify what's the real criticism and worthwhile discussions, vs the easy trolling attempts.
It’s people being paid off and it’s obvious.
IMHO, you're both right: There is an active, covert political campaign for more online surveillance under the guise of child protection going on world-wide right now; so much is clear to anyone following the various attempts everywhere. Yet as of now, this campaign hasn't lead to actual, harmful legislation in the EU.
Just like with encryption, there will always be an idiot politician somewhere discussing banning it. Mr Google tells me, for example, that lawmakers in Michigan (US) recently proposed " Anticorruption of Public Morals Act" which contained VPN banning clauses.
Frankly, until such time as it actually NEARS, let alone BECOMES legislation, the only thing posts such as yours are doing is spreading FUD.
The clue is in the URL you post "thinktank". It not even EU parliament, let alone been through the parliament debates, let alone passed to votes, let alone passed to being implemented by member states .... its just a random idea someone wrote down.
And quite frankly, I would still much rather be in the EU's digital environment than that of the US.
It's a result from the "European Parliamentary Research Service", hosted on the official website of the European parliament. And it is fully inline with recent attempted and success legislation of the same parliament. I am not sure why you would call this a "random idea" and an established member of the Parliamentary Research Service as "someone".
Not implementation.
Dude, just go read the damn website.
The research service does not operate on its own volition. An MEP requests a piece of research to assist them in their parliamentary work because they require independent, objective and authoritative analysis of a topic.
Please stop with the damn conspiracy theories. Sheesh.
A random MEP asked for this research. The MEP may or may not ever table anything based on the research. Ergo, it may or may not ever progress into the parliamentary debate, let alone votes, let alone member state implementation.
Its just RESEARCH.
Stop with the FUD.
An independent, objective, and authoritative analysis requested by a MEP speculates that a restriction or ban on VPN is likely. I think this is valuable information. You are saying this is worth nothing until it actually gets up to a vote. I disagree, I see your point and maybe it's fine to panic only when it actually comes to a vote, but I prefer to know what to expect, and what the Research Service considers an "independent, objective, and authoritative analysis" on this topic.
What the hell are you on about ?
There are what, 700 MEPs from 27 member states ?
Do you even realise the sheer amount of work required to get it from "piece of RESEARCH an MEP requested" to "legislation enacted by member state" ?
And that assumes it survives parliamentary debates and votes intact !
Just because an MEP requested a piece of RESEARCH it DOES NOT MEAN it is "likely" to become legislation.
Stop with the conspiracy theories.
And do you think the research would be complete or honest if it didn't present criticisms and a comprehensive list of use cases for VPNs? It says so many positive things about VPNs and describes them as "essential" so it's really difficult to comprehend how anyone could spin it as somehow calling for a VPN ban.
>As the EU reviews cybersecurity and privacy legislation, VPN services may also come under stricter regulatory scrutiny. For instance, it is likely that the revised Cybersecurity Act will introduce child-safety criteria, potentially including measures to prevent the misuse of VPNs to bypass legal protections.
> "may also come under," "it is likely that," "potentially including."
And that's potentially including only " measures to prevent the misuse of VPNs to bypass legal protections" which is a very specific thing.
And it even comes as part of a report that also lists genuine uses of VPNs including secure remote work, protection from surveillance and circumventing authoritarian censorship.
Meanwhile, "researching" chat control, VPN restrictions, etc.? "Oh it's just research, they're not actually going to do it."
No? He was making direct threats.
> Oh it's just research, they're not actually going to do it."
Yes, would you rather they just legislate by pure vibes?
And if we go to the homepage for "European Parliamentary Research Service", we see:
EPRS’ mission is to provide Members of the European Parliament, and where appropriate parliamentary committees, with independent, objective and authoritative analysis of, and research on, policy issues relating to the European Union, in order to assist them in their parliamentary work.
So a Member of Parliament asked them to conduct this piece of RESEARCH, so what ? It may or may not ever see the light of day in parliament !Across all publication types, the "European Parliamentary Research Service" published 1034 documents in 2025 and, 486 documents so far in 2026. And for this specific publication type ("At a glance"), they published 285 in 2025 and 113 so far this year.
How many of those hundreds of documents per year of RESEARCH actually make it all the way through to legislation I don't know .... but I think you'll find its a safe bet that its a fraction.
Jokes aside, the long arm of the law takes some time, it took us long time go get Apple to even allow alternative app stores. Eventually they'll get fined and actually start following the spirit of the regulations, but it'll take time as they try to drag it out as much as they can.
It makes a lot more sense if you realize pretty much the sole motivation behind all this digital virtue signaling is "put my data somewhere Trump isn't."
Notice how no one really lists contingencies for "what if the EU goes off the rails"? There's always an implicit assumption that EU politics will always be "sane" (read: "aligned with my personal politics").
Where did you try to find this? And what does "EU goes off the rails" actually mean here? There are a bunch of contingencies already in place for economic instability both for individual members states and EU-wide, there is "Article 7 of the Treaty on European Union" in case there is one rogue member, and then each member state has a bunch of their own contingencies already too.
What exactly is missing here?
> There's always an implicit assumption that EU politics will always be "sane" (read: "aligned with my personal politics").
I think you might severely misunderstand how decisions are made in EU, and also how regulations and such are actually implemented. I don't think there is any such assumptions at all, that's why we have elections, votes and referendums, because people and states have different opinions about what is sane vs not.
Where are you even getting these misconceptions from?
> And what does "EU goes off the rails" actually mean here?
It means, "what if the EU starts acting belligerently to other countries like the US has?" Where, hypothetically, would someone move their data since now the US and EU are off the table?
And if your answer is "well, you see that would simply be impossible because <waves hands about EU policy making>", then I guess you're an example of someone believing that EU politics will forever remain sane.
> that's why we have elections, votes and referendums, because people and states have different opinions about what is sane vs not.
Same situation as the US...
You mean if a EU member state does this? Then those contingencies I mentioned earlier will be used.
If you're a EU member and another EU member does that, you'd still have your data in EU, just not in that member state, if you had that.
> And if your answer is "well, you see that would simply be impossible because <waves hands about EU policy making>", then I guess you're an example of someone believing that EU politics will forever remain sane.
I've literally pointed you to concrete and very real contingencies that exists today, zero hand-waving.
> Same situation as the US...
I don't know how it works there, I just know that no one in the EU assumes everyone else will always agree with you, and if you look at how democracy works in EU and in the member states, I don't think anyone has those assumptions there either.
How? With what army? The EU is, on purpose, physically incapable of doing this.
From this thread, I am not convinced you really grasp how the EU works or what it actually is.
Things can of course turn sideways in the EU too, but it’s massively more difficult to do so without a broad coalition across multiple independent nations.
I think it's much less an expectation of sanity and more that the EU doesn't really host or do much of anything actually "important". The USA quite literally runs half the world so people are rightfully worried about it going "rogue".