Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

101–110 of 158 posts

Re: GDPR compliance as a service

#101

Put your site behind CloudFront, block EU countries. There, we've solved the problem without a shady SaaS. Edit: which wasn't even a problem to start with but if this is the route you want to go, the above is nearly fool proof and costs next to nothing.

There are many ways to achieve this goal, I just wanted to provide a drop-in solution that's independent of the underlying infrastructure.

Re: GDPR compliance as a service

#102

I'm currently an EU-ish Citizen, not residing in the EU. Will it block me? Also will it block JS-blocking EU Citizens residing in the EU? Let's not mention VPNs. Let's not mention Tor. This feels like a "registry cleaner" for GDPR o. xkcd: https://xkcd.com/1969/

When you make a reasonable effort to block access to EU users, EU citizens aren't covered under GDPR if they happen to access your site from a non-EU country temporarily:

"This won't apply to every U.S. business — just the ones that are knowingly, and actively, conducting business in the EU. In this vein, EU courts have the discretionary ability to determine if a U.S. company was purposely collecting EU resident data and subverting GDPR compliance. So, in some cases, the inadvertent collection of personal data will be forgiven if it is found to have been occasional and "unlikely to result in a risk to the rights and freedoms of natural persons."

(from https://community.spiceworks.com/topic/2007530-how-the-eu-ca... )

Re: GDPR compliance as a service

#104
post #79

Earlier quoted context omitted.

you could use cloudflare IP geolocation to block EU countries based on the Cf-Ipcountry header they provide. Though just by checking their IP I think you may need to comply with gdpr

Is just checking IP with no other personal information a violation of GDPR? Particularly if that IP is not retained in a database (just temporarily in production logs)? Asking for a friend...

Not really sure as well but from https://www.gdpreu.org/the-regulation/key-concepts/personal-... personal data seems to include "online identifiers", further defines online identifiers as "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifier"

Re: GDPR compliance as a service

#105
post #69

niko001 / Niklaus or whatever. This is extremely shady. You've copy pasted your whole terms and conditions from this page : https://buffer.com/terms VS: https://gdpr-shield.io/terms - Saved here https://web.archive.org/web/20180504020320/https://gdpr-shie... for good measure Which is illegal to begin with. You even forgot to replace the part that explains what the service does and left the part that says that gdpr sh…

Copying legal documents isn't illegal, and in fact many lawyers will just run a search & replace on an existing client's T&C to generate a new T&C. This is also how T&C generator websites work. It's actually recommended, as then you have standardized language that is all well-defined in the eyes of the courts.

Re: GDPR compliance as a service

#106
post #96
post #91

Earlier quoted context omitted.

Niko, your implementation may not be right like others have mentioned (in that it triggers GDPR on your customers), but I fully support this methodology. If it helps, I use AppEngine for my App which already provides geolocation information in the IP and my app blocks it the moment it receives the request. Users will only see a re-direction to a notice relating to GDPR and what they'll need to do if they still want t…

Thanks! You're right, there are many ways to achieve this goal, I just wanted to provide a drop-in solution that's independent of the infrastructure.

You might as well be selling an image saying "EU customers go away!" With regards to GDPR compliance it's just as good in that, at best, you're showing intent not to serve EU customers (yet you still don't actually block requests, you just serve them different content and log all the same data).

Re: GDPR compliance as a service

#107
post #69

niko001 / Niklaus or whatever. This is extremely shady. You've copy pasted your whole terms and conditions from this page : https://buffer.com/terms VS: https://gdpr-shield.io/terms - Saved here https://web.archive.org/web/20180504020320/https://gdpr-shie... for good measure Which is illegal to begin with. You even forgot to replace the part that explains what the service does and left the part that says that gdpr sh…

Copying legal documents isn't illegal, and in fact many lawyers will just run a search & replace on an existing client's T&C to generate a new T&C. This is also how T&C generator websites work. It's actually recommended, as then you have standardized language that is all well-defined in the eyes of the courts.

You are going to have to do a better job of backing that claim up. It certainly seems to be an obvious breach of intellectual property law at the very least. Citing that some lawyers do this does not automatically make it legal.

Re: GDPR compliance as a service

#108

Earlier quoted context omitted.

Copying legal documents isn't illegal, and in fact many lawyers will just run a search & replace on an existing client's T&C to generate a new T&C. This is also how T&C generator websites work. It's actually recommended, as then you have standardized language that is all well-defined in the eyes of the courts.

You are going to have to do a better job of backing that claim up. It certainly seems to be an obvious breach of intellectual property law at the very least. Citing that some lawyers do this does not automatically make it legal.

My initial claim is perhaps a bit too strong. Case law is basically that the unique portions of a T&C or other contract are protected by copyright law, but boilerplate terms that have appeared in lots of different firms' documents are considered public domain.

http://pub.bna.com/ptcj/1051462Jan11.pdf

GDPR-shield's original T&C was actually copied from ShareKit, which is another product from the same company:

https://www.sharekit.io/terms

But going paragraph by paragraph down the terms, you get this list of companies, all with the same language:

https://www.google.com/search?q=%22Except+for+certain+kinds+...

https://www.google.com/search?q=%22You+must+be+at+least+%5B1...

https://www.google.com/search?q=%22To+access+most+features+o...

https://www.google.com/search?q=%22The+Service+will+require+...

https://www.google.com/search?q=%22may+seek+pre-authorizatio...

https://www.google.com/search?q=%22The+Service+may+include+a...

https://www.google.com/search?q=%22may%20suspend%20or%20term...

That's only through section 4, but so far every clause is legal boilerplate except for the first paragraph of section 4, which is unique to ShareKit (and ThreadRadar, another product by the same entrepreneur).

Re: GDPR compliance as a service

#109
post #99
post #89

The more I look into this, the shadier it seems. They're selling at a whooping $79/month, a single php script that does not even check any sort of authentication or API key, and only does a dumb lookup against a GeoIP database : https://gdpr-shield.io/check.php And this is called by this tiny javascript script https://code.gdpr-shield.io/script.js that just.. displays an overlay div when you're in the EU. Smells like…

The pricing is actually cheaper than "bare" geolocation APIs, which don't do the blocking-part. Have a look at https://ipstack.com/product for example. If you get a quote from an experienced data protection lawyer for GDPR compliance, GDPR Shield will be an order of magnitude cheaper in the long run. There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fee…

>There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy.

What do you base that assesment on? GDPR mostly just consolidates multiple privacy laws into one.

Re: GDPR compliance as a service

#110
post #5

The privacy of EU persons coming in from a non-EU IP address still need to be protected under GDPR. This solution is a start but it's not bulletproof. Edit: I don't want anyone to think I believe it's a good start but it is a kind of solution. I wonder if lots of US companies, once they begin to realize GDPR is a problem for them, won't decide to try one of two things: 1. This: block access from IP addresses believed…

Why doesnt EU instead implement a continent wide firewall and allow access to only GDPR compliant sites
Post reply on HN