Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

111–120 of 158 posts

Re: GDPR compliance as a service

#111
post #54

The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD. Directly from the EU: > Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ( https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Even if you just set your AdWords targeting to 'global', it might be enough to trigger this. GDPR Shield is a clear signal that you're not targeting EU users.

> How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR.

Does that mean that (e.g.) German bloggers are not bound to the GDPR when they just add "made for the Swiss" to their header?

Re: GDPR compliance as a service

#112
post #72

Earlier quoted context omitted.

If you don't know what you're doing, don't involve others.

Since I don't quite get the point you're making here, I think I should specify that I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word. Expecting them to…

> I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law.

If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.

Re: GDPR compliance as a service

#113

The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD. Directly from the EU: > Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ( https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

Overall I'm content with the GDPR as it is a long needed corrective action for the path we've been treading in the West as a whole. One requirement, imho, is quite ridiculous, however. That is the need for entities which need to abide by the GDPR but do not have a presence in the EU to assign a representative in the EU. This part definitely needs some relaxation. Just complying with the regulation ought to be enough…

> Just complying with the regulation ought to be enough as the first step, especially for start-ups.

It is enough; most start-ups won't need a representative.

That requirement only applies to large-scale processing of special categories ( i.e. sensitive ) of data or that relating to criminal convictions and offences.

Article 27 applies: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...

It's basically to prevent big data processors from claiming 'we don't have an EU presence so you can't fine us'.

Re: GDPR compliance as a service

#114

Earlier quoted context omitted.

Since I don't quite get the point you're making here, I think I should specify that I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word. Expecting them to…

> I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.

While I agree, if you're an American setting up a plug-and-play site with chocolate chip cookie recipes, that happens to collect data out of the box, where along the process are you going to realize that you even need to know anything about EU regulations?

I've never hired a Wumbologist because I don't know what Wumbology is or where it applies.

Re: GDPR compliance as a service

#115
post #54

Earlier quoted context omitted.

How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Even if you just set your AdWords targeting to 'global', it might be enough to trigger this. GDPR Shield is a clear signal that you're not targeting EU users.

> How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Does that mean that (e.g.) German bloggers are not bound to the GDPR when they just add "made for the Swiss" to their header?

Well, if you're in the EU you have to obviously implement the regulation either way.

Re: GDPR compliance as a service

#116
post #13

Earlier quoted context omitted.

The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.

Frightening to think something as innoculus as making a website of chocolate chip recipes and logging visitor IPs could provoke that.

Your chocolate chip recipe website will have to be compliant to a number of laws, GDPR isn't the only law in the internet.

Re: GDPR compliance as a service

#117
post #54

Earlier quoted context omitted.

How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Even if you just set your AdWords targeting to 'global', it might be enough to trigger this. GDPR Shield is a clear signal that you're not targeting EU users.

> How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Does that mean that (e.g.) German bloggers are not bound to the GDPR when they just add "made for the Swiss" to their header?

What personal data are German bloggers gathering?

Re: GDPR compliance as a service

#118
post #79

Earlier quoted context omitted.

you could use cloudflare IP geolocation to block EU countries based on the Cf-Ipcountry header they provide. Though just by checking their IP I think you may need to comply with gdpr

Is just checking IP with no other personal information a violation of GDPR? Particularly if that IP is not retained in a database (just temporarily in production logs)? Asking for a friend...

If you don't keep it around and only use it to block traffic then I don't see which parts of the GDPR would cause any problem.

IPs may be personal data but if you don't store it there is no problem.

Re: GDPR compliance as a service

#119
post #96

Earlier quoted context omitted.

Thanks! You're right, there are many ways to achieve this goal, I just wanted to provide a drop-in solution that's independent of the infrastructure.

You might as well be selling an image saying "EU customers go away!" With regards to GDPR compliance it's just as good in that, at best, you're showing intent not to serve EU customers (yet you still don't actually block requests, you just serve them different content and log all the same data).

Or an image saying "We don't care about keeping your personal data safe".

Re: GDPR compliance as a service

#120
post #12

Anyone can expand on what "vindictive reporting from no-win-no-fee legal firms" would exactly consist of?

Law firms who proactively investigate infringing companies, then sell their service to citizens willing to sue. As an incentive for the potential customer, they agree to only charge if they win.

That's not how GDPR is enforced.

It's enforced by a regulator. The fines are fines, not compensation, and the fines go to the regulator.

There's no route for a private citizen to hire a lawyer and sue.

Post reply on HN