Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

71–80 of 158 posts

Re: GDPR compliance as a service

#71

Earlier quoted context omitted.

And if your site loads their Javascript to block anyone from the EU from visiting, then it's clear that you're not targeting customers in the EU.

You're still gathering the data on every request. And since all requests go to the site anyway (to load the JS) you might as well just put a text saying, "nothing to see here for EU citizens"—that'd be a lot cheaper than buying this silly service and it would send the same signal. This service isn't blocking requests to your site, it's just showing the visitors different content after the fact.

[deleted]

Re: GDPR compliance as a service

#72
post #39

Earlier quoted context omitted.

Tip: don’t log the IPs then.

I spin up a Wordpress site with default options to host my chocolate chip recipes. Is it GDPR compliant? I go through and toggle all the settings the internet tells me to, even though I don't know their meaning or effect. Am I GDPR compliant? I install a Wordpress plugin that sets up a Really Simple Chocolate Chip Syndication server, or RSCCS. That plugin logs IPs. If I was GDPR compliant previously, now I'm not, and…

If you don't know what you're doing, don't involve others.

Re: GDPR compliance as a service

#73

From GDPR-shield's terms and conditions ( https://gdpr-shield.io/terms ): 1. GDPR Shield Service Overview The Service provides a social media management tool that enables users to customize the link preview window of websites under their control on social platforms, in addition to other analytics tools to help bolster users' social media content. ...what? Is this a botched copy/paste job?

Yep, it's copy pasted from https://buffer.com/terms

He's running a really shady business.

Re: GDPR compliance as a service

#74
post #57

Earlier quoted context omitted.

This is what you're trying to reference: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

That explanation is the first one I've seen that makes GDPR sound reasonable. The main problem overall is that the EU appears to consider information about someone as being owned by that person. That is quite foreign from a US individual perspective and having some blogs. I don't see how the learning I have acquired about people places and things, which I acquired without any promise of confidentiality, can be owned…

There are other interests that get balanced against the individual's right to privacy, including public interests like newsworthiness.

But indeed that can go both ways - the website of a newspaper might be required upon request to remove a 20-year-old crime blotter item reporting a single petty theft conviction for an otherwise law-abiding non-celebrity; they wouldn't be required to do that for a 2-year-old murder conviction.

Re: GDPR compliance as a service

#75
post #72

Earlier quoted context omitted.

I spin up a Wordpress site with default options to host my chocolate chip recipes. Is it GDPR compliant? I go through and toggle all the settings the internet tells me to, even though I don't know their meaning or effect. Am I GDPR compliant? I install a Wordpress plugin that sets up a Really Simple Chocolate Chip Syndication server, or RSCCS. That plugin logs IPs. If I was GDPR compliant previously, now I'm not, and…

If you don't know what you're doing, don't involve others.

Since I don't quite get the point you're making here, I think I should specify that I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law.

I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word.

Expecting them to know that starting a website with a plug and play webserver could collect sensitive information on their behalf is pushing it a bit. Expecting them to know they have to comply with a law passed by a governing body they've never come within 1k miles of...

Re: GDPR compliance as a service

#78
post #12

Anyone can expand on what "vindictive reporting from no-win-no-fee legal firms" would exactly consist of?

If an EU citizen believes that their personally identifiable information was obtained without their consent, the EU GDPR allows firms to do an audit on the company. The citizen who filed the complaint would enlist help from a no-win-no-fee legal firm, meaning, if they don't win (with infractions being $10 million minimum), the citizen, who is now a client of the firm, would not be out any money. If they do win, most…

> with infractions being $10 million minimum

Stop talking nonsense. It is up to $10 million or 2% of revenue.

https://www.gdpreu.org/compliance/fines-and-penalties/

And so for most websites the fine would be significantly smaller than what lawyers typically earn to litigate.

Hence your entire "no win no fee" premise falls completely apart.

Re: GDPR compliance as a service

#79

I wonder if you can do something like this directly in Cloudflare.

you could use cloudflare IP geolocation to block EU countries based on the Cf-Ipcountry header they provide. Though just by checking their IP I think you may need to comply with gdpr

Re: GDPR compliance as a service

#80
post #60

Earlier quoted context omitted.

Wait! I was under the impression that fines due to GDPR are just that, fines. They are paid to the government, not individuals. At most, getting fined due to non-compliance can suggest that if individuals bring civil lawsuits against the company, they may win and be awarded damages, the amount of which depends on how much damages they can prove they have incurred as a result of misuse of their data, not statutory amo…

Yes, your understanding is completely correct. Only EU member states can levy fines under the GDPR, and it's likely few will have any interest in trying to fine small businesses. Lawsuits are possible, but only for damages, and good luck showing any damages from a minor technical violation by a small SaaS tool. And without any prospect of large damages from a deep-pocketed defendant, good luck finding a law firm will…

I don't have a lot of actual information on this, but the buzz in my privacy professional listservs is that EU courts have been VERY expansive about what constitutes "damage" in related legal spheres, and that those of us coming from a US legal background should not rely on our instincts about what kinds of damage could actually create a cause of action worth suing over.
Post reply on HN