Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

131–140 of 158 posts

Re: GDPR compliance as a service

#131
post #13

Earlier quoted context omitted.

The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.

Frightening to think something as innoculus as making a website of chocolate chip recipes and logging visitor IPs could provoke that.

It wouldn't, that's just pure FUD.

Re: GDPR compliance as a service

#132
post #99
post #89

The more I look into this, the shadier it seems. They're selling at a whooping $79/month, a single php script that does not even check any sort of authentication or API key, and only does a dumb lookup against a GeoIP database : https://gdpr-shield.io/check.php And this is called by this tiny javascript script https://code.gdpr-shield.io/script.js that just.. displays an overlay div when you're in the EU. Smells like…

The pricing is actually cheaper than "bare" geolocation APIs, which don't do the blocking-part. Have a look at https://ipstack.com/product for example. If you get a quote from an experienced data protection lawyer for GDPR compliance, GDPR Shield will be an order of magnitude cheaper in the long run. There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fee…

> There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy

I get that you're trying to sell your 'service', but that's just pure FUD.

What exactly could 'predatory law firms' sue you for? Not complying with the letter of the GDPR? The GDPR is for EU authorities to take action where deemed necessary - not law firms.

Re: GDPR compliance as a service

#133
post #97

Earlier quoted context omitted.

> There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy No there isn't. When the GPDR fines are 2% of revenue there isn't the incentive for lawyers to go after businesses earning less than a million a year in revenue.

You're mixing up the member states' enforcement (4% of worldwide turnover or €20 million, whichever is higher) and civil suits. There are law firms that send out thousands of cease and desist letters (which is a civil action) based on automated searches for mistakes. It absolutely makes economic sense for lawyers to pursue out-of-court settlements from businesses if it's mostly automated.

This is just nonsense. I don't see how the GDPR possibly allows civil actions for infractions, doubly so for countries outside the EU.

Re: GDPR compliance as a service

#134
post #42

Earlier quoted context omitted.

Wait! I was under the impression that fines due to GDPR are just that, fines. They are paid to the government, not individuals. At most, getting fined due to non-compliance can suggest that if individuals bring civil lawsuits against the company, they may win and be awarded damages, the amount of which depends on how much damages they can prove they have incurred as a result of misuse of their data, not statutory amo…

Cease and desist letters from predatory law firms are a very real thing, even in Europe. In Germany, entire law firms have been established for the sole purpose of collecting out-of-court settlement fees for small mistakes in websites' legal notices, which they find using automated searches: http://transblawg.eu/2003/10/13/u-s-comment-on-impressumgerm... GDPR will give them new ammunition on a European scale.

Your link is from 15 years ago.

Re: GDPR compliance as a service

#135

Earlier quoted context omitted.

Since I don't quite get the point you're making here, I think I should specify that I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word. Expecting them to…

> I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.

> > I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. > If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.

This attitude is really sad to me. It was and is one of the greatest things about the internet, that pretty much anyone anywhere could publish something. If you now need an "expert" to do that, we've lost something.

Re: GDPR compliance as a service

#136
post #121

Earlier quoted context omitted.

If an EU citizen believes that their personally identifiable information was obtained without their consent, the EU GDPR allows firms to do an audit on the company. The citizen who filed the complaint would enlist help from a no-win-no-fee legal firm, meaning, if they don't win (with infractions being $10 million minimum), the citizen, who is now a client of the firm, would not be out any money. If they do win, most…

> with infractions being $10 million minimum) FFS, this is a maximum , not minimum.

Fines are up to $10 million or 2%, but it can go up to $20 million or 4% of annual global revenue, whichever is higher. That percent, whichever is higher is the key. Facebook's 2017 revenue was ~40.7 Billion. Four percent of that amount isis ~1.6 billion

Re: GDPR compliance as a service

#137
post #121

Earlier quoted context omitted.

> with infractions being $10 million minimum) FFS, this is a maximum , not minimum.

Fines are up to $10 million or 2%, but it can go up to $20 million or 4% of annual global revenue, whichever is higher. That percent, whichever is higher is the key. Facebook's 2017 revenue was ~40.7 Billion. Four percent of that amount isis ~1.6 billion

You said 2 things:

> if they don't win (with infractions being $10 million minimum

But all of the numbers you give are the maximum possible fines. The actual fines imposed by the regulators will always bee smaller than that.

You also said:

> The citizen who filed the complaint would enlist help from a no-win-no-fee legal firm,

That's not how the fines work. They're fines, paid to the regulator. They're not compensation paid to the victim. There's no payout for no-win-no-fee solicitors, and so they're not going to get involved.

Re: GDPR compliance as a service

#138
"The European Union's new GDPR (General Data Protection Regulation), which takes effect on 25th May 2018, creates uncertainty and risk for website owners. It applies to businesses world-wide, because it protects all users accessing your site from the EU, regardless of where your business is located. GDPR threatens website owners with fines of 4% of turnover or €20 million (whichever is higher). If you don't have an in-house legal team, complying with the law requires you to consult with a lawyer specializing in data protection law. In addition, you're at risk of vindictive reporting from no-win-no-fee legal firms."

Total, unmitigated FUD.

Re: GDPR compliance as a service

#139
post #54

The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD. Directly from the EU: > Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ( https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Even if you just set your AdWords targeting to 'global', it might be enough to trigger this. GDPR Shield is a clear signal that you're not targeting EU users.

However specifically putting measures in place to block EU users should be sufficient to show that you are not specifically targeting them.

Re: GDPR compliance as a service

#140

Earlier quoted context omitted.

International enforcement is a can of worms. However, a lot of it is covered by: 1- US companies with a physical presence in the EU. They can fine that entity directly. 2- US companies will find they can't sell to EU businesses (B2B), as that means the EU company is carrying the can in terms of non-compliance. 3- The EU Member State could go via the International Courts. Or via some kind of bilateral agreement (e.g.…

Seems this is targeted mainly to the likes of uber, google.. small time websites who do not have much volume aren’t the target audience.

[deleted]
Post reply on HN