GDPR Article 17 expressly requires the removal of things from the global internet
> You're free to not serve your site in the EU
Geoblocking is functionally impossible
...as part of compliance with GDPR, if you choose to be compliant. Please name one instance of the EU suing and successfully removing an American website from the internet under this article, or any part of the GDPR? Considering we're talking about an actual case of the US seizing the domain of a European website, whataboutting a hypothetical with the GDPR which has never done the reverse despite being in force for 10 years is incredibly disingenuous.
---
Rate-limit edit:
> Are you saying that you don’t think that the GDPR text is written to apply outside of the EU, or that it does say that but it’s not relevant because it’s not viable for anybody to enforce that?
The GDPR is European legislation, written for the territory the EU has legal jurisdiction over. Why would anybody think it's meant to apply outside of the EU? Plenty of businesses choose to operate by two sets of privacy policies, one where they continue fucking over their American users and one where they adhere to the GDPR for European users, and that is perfectly acceptable. There is no "think" about it, the legislation obviously does not apply outside the EU, nor is it intended to.
Because it's clearly worded in such a manner, similar to US financial laws. The key difference is that the EU so far lacks the leverage to throw its weight around outside its own territory to the extent that the US does. (Also presumably politicians won't be willing to burn bridges over PII handling violations to the same extent that they do over financial crimes.)
And geo blocking may be functionally impossible but the law cares about intent and actions, not if you prevented someone who used a VPN or lied about their location from using your service.
If you say so
And yet still an attempt at extraterritorial overreach. Regardless, I imagine that the rest of us who don't do business in the EU will continue to disregard its very existence. (Except in principle when we write negative comments about it on the internet that don't in practice matter whatsoever, such as this one that you're reading right now.)
I can't recall HN asking/requiring PII from me in any fashion, so I don't see the relevance. If a commenter published some PII about me, then I wonder if HN would remove the comment if I complained to them about it. As I see it, HN isn't acting as a data controller.
Edit: it's covered by HN Privacy policy which is available here: https://www.ycombinator.com/legal/
TLDR: email privacy@ycombinator.com for privacy concerns which should cover removing comments.
In my opinion, that seems compliant with GDPR.
I fail to see the difference in principle from the federal government doing this for copyright violations.
There is a difference in kind, because it becomes impossible for the global internet to exist if thousands of local jurisdictions are being given their way, with conflicting local legislation resulting in global takedown when it is impossible to comply with two different jurisdictions. So this is noteworthy as an escalation of an already existing problem into an even worse direction.
---
Rate-limit edit:
> Which is why the Internet hasn't been global in a long time, and looks pretty different in China vs EU vs Russia.
China and Russia aren't part of the global internet because they have national firewalls and segregated themselves. The EU very much is, and with limited exceptions the internet doesn't look much different from the US, the EU, Japan, Canada, Australia, Mexico, Thailand, Brazil, or South Africa. It seems absurd to suggest that the internet isn't global when I'm in all likelihood talking to you from the opposite side of the world and this is the norm. And what is the point you're making? That we should embrace the China/Russia model and give not only every country but also every state/province/city its own Great Firewall?
Whereas this is for the most part not the scenario for major IP transit providers in Europe, the USA, Canada (top 50 by size CAIDA ASRank scale/scope ISPs ranked by ASN which are not Russian or chinese).
I actually don't have much of an opinion about what it should be, I was only discussing this from a descriptive legal standpoint. My guess is what will happen is companies will voluntarily target their sites to different regions and different legal regimes (like many big US sites do for their foreign versions, or gambling sites do here). That's kind of what's happening here, Verisign is complying probably so they can still have the TX market.
Internet from L1 to L4 is global but WWW at L5 and above was always sort of fragmented. Look at chat apps: Messenger, WhatsApp, WeChat, LINE, KakaoTalk, Telegram, etc. The fault lines for userbases of these apps roughly align regional borders.
If I were running a business that had any operations or clients whatsoever in Europe my opinion on this topic would be different (in terms of legal liability to the corporation, and necessity of compliance to ensure ongoing revenue from European customers, etc), but I am not.