Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

11–20 of 158 posts

Re: GDPR compliance as a service

#11
Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me?

What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

Re: GDPR compliance as a service

#13

Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.

Re: GDPR compliance as a service

#15
I can't tell if this is a fake service or not, but blocking users from EU IP address ranges (which I'm assuming how it works) will still not stop the EU from following a trail of data that could originate from your organization.

That's the biggest thing from the EU's GDPR rules - what is your organization's data inventory, how does it map outside of your organization, and how are you securing PII?

If a complaint is made from someone who is an EU citizen, and another organization shows logs that they got this information from your web app or service, that will trigger an audit from the EU. Blocking access to a subset of IP ranges will do absolutely nothing to stop this, and will not stop the sharks once they have smelled blood.

In a sense, the EU has plain rules that you can protect against, unlike the FTC/FDA (for HIPPA etc) who are vague and will not disclose how you can protect your own organization.

Re: GDPR compliance as a service

#17

Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

I always found this interesting because surely no matter what effort you go through to prevent yourself from providing your service to EU citizens, you're probably going to collect enough information to be subjected to GDPR during the period where you did not remotely know a set of users were EU citizens. (e.g., those residing overseas, traveling, etc)

And then -- what if you finally have confirmation? You were attempting to avoid it, but now you cannot. If your attempt is to avoid it at all costs, you're effectively required to validate whether users are EU citizens much earlier in the process than before GDPR, which means GDPR already has had a big impact despite efforts to avoid its umbrella.

Re: GDPR compliance as a service

#18
post #12

Anyone can expand on what "vindictive reporting from no-win-no-fee legal firms" would exactly consist of?

Law firms who proactively investigate infringing companies, then sell their service to citizens willing to sue. As an incentive for the potential customer, they agree to only charge if they win.

Re: GDPR compliance as a service

#20

I'm currently an EU-ish Citizen, not residing in the EU. Will it block me? Also will it block JS-blocking EU Citizens residing in the EU? Let's not mention VPNs. Let's not mention Tor. This feels like a "registry cleaner" for GDPR o. xkcd: https://xkcd.com/1969/

> This feels like a "registry cleaner" for GDPR

Probably. It seems like a quick "let's make some money" scheme to milk the GDPR panic.

Post reply on HN