U.S. news outlets including WRAL.com and its affiliates as well as The Chicago Tribune, The Los Angeles Times and The Arizona Daily Star abruptly blocked access to their websites from Europe on Friday, choosing to black out readers rather than comply with a strict new data privacy law in the European Union that limits what information can be collected about people online.

The decision by Capitol Broadcasting, the corporate parent, includes WRAL.com, WRALSportsFan.com, HighSchoolOT.com and WRALTechWire.com

Here is the notice as published by WRAL.com that has begun appearing:

“We are a local media company based in Raleigh, North Carolina, USA. We have detected that you are in one of the member countries of the European Union, which is now subject to the General Data Protection Regulation.

“We are currently assessing methods for complying with the detailed requirements of GDPR. Currently, only about 2 percent of our website traffic originates from EU countries.

“Until we are able to ensure our full compliance with the rigorous GDPR requirements, we are blocking access from EU countries to our websites, which include wral.com, wralsportsfan.com, highschoolot.com and wraltechwire.com. We take the GDPR seriously. Penalties for GDPR violations are as high as 4 percent of a publisher’s annual revenue.

“We hope to restore access soon as we work through the administrative, legal and technical requirements involved with GDPR compliance. We apologize for the temporary inconvenience.

“If you believe you have received this message in error, please send your IP address to support@wral.com. You can retrieve your IP address by going to whatismyipaddress.com.

“Send feedback to support@wral.com.”

GDPR rules in effect

The new rules, known as the General Data Protection Regulation, strike at a core element of businesses that offer free content online but that make money by collecting and sharing user data to sell targeted advertising. The shutdowns came as a surprise to readers of the publications, because companies had two years to prepare for the new regulations.

The most notable blackouts were by news organizations tied to the American media company Tronc. In addition to The Chicago Tribune and Los Angeles Times, newspapers including The New York Daily News, The Orlando Sentinel and The Baltimore Sun were also unavailable to readers in Europe. (Tronc announced in February that it was selling The Los Angeles Times.)

“We are engaged on the issue and committed to looking at options that support our full range of digital offerings to the EU market,” the Tronc-owned newspapers said on their websites. “We continue to identify technical compliance solutions that will provide all readers with our award-winning journalism.”

The decision illustrated that some companies would prefer to lose European customers than risk being hit with the stiff penalties allowed under the new law: Fines can reach 4 percent of global revenue.

A Tronc spokeswoman was not immediately available to comment Friday.

Several other outlets chose to restrict access for readers in Europe, including newspapers belonging to Lee Enterprises, like The Arizona Daily Star and St. Louis Post Dispatch.

The websites of many other U.S. news organizations, including The New York Times, USA Today and The Washington Post, were accessible from Europe. Some acknowledged the new privacy rules with large disclaimers and other information to explain what information was being gathered when a reader visits the site.

“Welcome to USA Today Network’s European Union Experience,” the news organization posted at the top of its website, explaining that the company would not collect personally identifiable information or other data commonly used to sell online advertising.

Andrea Jelinek, chairwoman of the new European Data Protection Board, which will coordinate enforcement of the new law, criticized the blackout and said that companies had been given a long time to prepare. For weeks, businesses as varied as Uber, bike shops and restaurants have been sending notes to alert people to updated privacy policies as a result of the law, known as GDPR.

“It didn’t just fall from heaven,” Jelinek said in a statement. “Everyone has had plenty of time to prepare.”

News organizations were not alone in erecting barriers for European users. The U.S. television broadcaster A&E Networks cut off the websites of its A&E, History and Lifetime channels. The digital advertising company Drawbridge, the social media tracker Klout and the save-it-for-later reading app Instapaper also stepped back.

Europe’s new privacy measures allow people to limit the information they leave behind when browsing social media, reading the news or shopping online. Businesses must detail how someone’s data is being handled, and clear a higher bar to target advertising using personal information.

The law had been seen as focusing on Silicon Valley tech giants like Facebook and Google, but publishers and advertising companies have warned that it will harm their businesses in particular because it restricts how information is packaged and shared to sell advertising. It is common for websites to use tracking software to gather information about visitors in order to better target ads. Digital advertising is an important source of income for many news organizations, particularly as print readership and advertising fall, but policymakers in Europe argue the practices have become intrusive and ripe for abuse, with personal information shared far beyond what most people realize.

Julia Shullman, the chief privacy counsel for the digital advertising firm AppNexus, said an “unintended consequence” of GDPR was that Google would become more powerful. To compete with the online search giant, publishers and advertisers have bought, sold and traded data with different sources, a bespoke approach that is now severely restricted under the European Union’s new rules. Many companies will now partner with the bigger company, Shullman said.

“At least in the short term, it pushes publishers to these large platforms that dominate the market already,” Shullman said in an interview.

On Friday, privacy lawyer Max Schrems filed some of the first legal complaints using GDPR, alleging Google and Facebook are violating the law with their terms of service.

The law requires “informed” consent from users, but Schrems, who has successfully sued Facebook in the past and leads the nonprofit group None of Your Business, said the two companies were using “forced” consent because users must accept a blanket privacy policy in order to continue using the service.

The complaints were filed in Austria, Belgium, France and Germany, and will now be reviewed by European data protection authorities.