Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

141–150 of 158 posts

Re: GDPR compliance as a service

#141

Earlier quoted context omitted.

> I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.

> > I was playing the role of someone who wants to start up a website on the side but isn't an expert on computers, networking, software development, or international privacy law. > If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer. This attitude is really sad to me. It was and is one of the greate…

Unfortunately, copy/pasting a formatted comment on HN doesn't have enough newlines to quote the post properly.

Anywhere you want one newline in your output, you have to use two.

Re: GDPR compliance as a service

#142
post #41

I have this eerie suspicion that GDPR cases will be a haven for trollish and/or opportunist behavior. Instead of huge corporations having to shell out significant money to swallow up start-up competitors, they could much more cheaply pay EU citizens to exploit the huge burden of the law on small companies or even solo endeavors. I hope I can be convinced to be optimistic.

[deleted]

Re: GDPR compliance as a service

#143
post #42

Earlier quoted context omitted.

Cease and desist letters from predatory law firms are a very real thing, even in Europe. In Germany, entire law firms have been established for the sole purpose of collecting out-of-court settlement fees for small mistakes in websites' legal notices, which they find using automated searches: http://transblawg.eu/2003/10/13/u-s-comment-on-impressumgerm... GDPR will give them new ammunition on a European scale.

Your link is from 15 years ago.

[deleted]

Re: GDPR compliance as a service

#144

Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

Despite the propaganda flying around HN for known political purposes, they can't and won't arrest you because there is no jurisdiction unless you have operations in the EU.

Re: GDPR compliance as a service

#145
post #13

Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.

That's a very unlikely "solution" and is not going to happen unless the EU wants retribution in some form from the rest of the world.

Re: GDPR compliance as a service

#146
post #13

Earlier quoted context omitted.

The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.

That's a very unlikely "solution" and is not going to happen unless the EU wants retribution in some form from the rest of the world.

As mentioned, this is the retribution. The US has been enforcing their laws on the rest of the world with equally radical methods for many years already.

Re: GDPR compliance as a service

#147
post #29
post #5

The privacy of EU persons coming in from a non-EU IP address still need to be protected under GDPR. This solution is a start but it's not bulletproof. Edit: I don't want anyone to think I believe it's a good start but it is a kind of solution. I wonder if lots of US companies, once they begin to realize GDPR is a problem for them, won't decide to try one of two things: 1. This: block access from IP addresses believed…

When you make a reasonable effort to block access to EU users, EU citizens aren't covered under GDPR if they happen to access your site from a non-EU country temporarily: "This won't apply to every U.S. business — just the ones that are knowingly, and actively, conducting business in the EU. In this vein, EU courts have the discretionary ability to determine if a U.S. company was purposely collecting EU resident data…

That is an interpretation of the law and is not in accord with what the ICO (the regulator) is saying. If you have a site called "UK Expats" and you block EU IPs you will still be liable since your site is offering a service to EU citizens. A less extreme use case but equally applicable, you have a shoe store in the US and your style is liked by french citizens living in the US, since a considerable amount of traffic is coming from EU citizens you are under GDPR. even if it is only 20%, even if they are in the US, even if you blocked all European IPs

Re: GDPR compliance as a service

#148

Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?

At the moment there is no way the EU can enforce you to comply with that law, unless you have a subsidiary in the EU. Only if USA sign a special agreement with the EU this may change, but I don't think this will ever happen (very unlikely). Otherwise every country on planet can create their own draconian laws and expect that every single company in the world comply with it...

this is true, but kinda pointless, you are not gonna fight the EU over this... Several countries in the EU (UK, Ireland, ...) can assign personal liability for intentionally ignoring privacy law, in which case someone in your company is basically going to end up a wanted man in Europe

Re: GDPR compliance as a service

#149
I think this is actually good for privacy. We will know that companies using this service don't care about privacy, even for non-european users.

We could then can design a tool detecting the use of this service and notifying the user "this service doesn't care about your personal data".

Re: GDPR compliance as a service

#150
Disclaimer: This is not legal advice.

Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source).

If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU country, GDPR still applies. Any site with more than trivial traffic will have some users with those characteristics.

Experts debate whether explicitly requiring users to confirm that they aren’t in the EU - say, a country dropdown - is even a solution. If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence).

Post reply on HN