Hacker News new | past | comments | ask | show | jobs | submit login

> We value your privacy

I hate popups that can't be dismissed. But reader mode works regardless, at least.




Edit: Refusing tracking-free access violates GDPR.[0] That is, unless you explicitly deny access to EU residents.[1]

0) https://www.gdprtoday.org/dutch-dpa-rules-websites-must-allo...

1) https://law.stackexchange.com/questions/29562/is-it-possible...


[1] is not the only way

There are a number of ways to demonstrate that you are not doing business in the EU and thus do not have to comply with the GDPR and can refuse tracking-free access.


How so?

But yes, I do see that Atlas Obscura does do that. On their privacy policy page, I find:

> The Website is hosted in the United States and is intended for and directed to users in the United States. If you are accessing the Website from the European Union, Asia, or any other region with laws or regulations governing personal data collection, use, and disclosure, that differ from United States laws, please be advised that through your continued use of the Website, which is governed by U.S. law, this Privacy Policy, and our Terms of Use, you are transferring your personal information to the United States and you consent to that transfer.


Edit: Upon reflection, I don't think that this satisfies GDPR. They would need to entirely deny access to users in the EU. Just telling them that US law applies, and that they can access the site only if they agree to give up their rights, doesn't suffice.

But I guess that we'll see. I'm sure that complaints have been lodged.


I think the key part is this assertion: "The Website is hosted in the United States and is intended for and directed to users in the United States." As long as there aren't other indications that the business is actually doing business in the EU (e.g. has German or French localization, sells stuff to EU based customers, etc), this helps demonstrate that they don't need to comply with the GDPR.

While there are many companies that have chosen to try and block users in the EU, I don't think this is required, or intended by GDPR.


Maybe so. I guess that we'll see.


GDPR applies regardless of whether you're doing business, and IIUIC applies to _people_ from the EU rather than just people currently in the EU.


> applies to _people_ from the EU rather than just people currently in the EU.

No, it applies to "data subjects who are in the Union" (art. 3 - "Territorial scope"), not from the Union.

(This is for non-EU data processing organizations; the EU-based organizations/companies must apply the GDPR to everyone in the world)


I read it as they are "in the Union" by virtue of nationality; that is they are "[legally] in the Union" [https://gdpr-info.eu/art-3-gdpr/]; but it seems you're right, eg. https://ec.europa.eu/info/law/law-topic/data-protection/refo...


The company I work for interprets it as any EU citizen any where on the globe, so we just implemented GDPR for every one regardless of their location or particulars.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: