Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

121–130 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#121
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

> It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy.

Why would you think that SV would be interested in offering anything for its own sake? The vast majority of the model is to create new rent-seeking profit opportunities for investors, with internet users as a mere means to that end.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#122
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

> Is the EU going to target American banks of American businesses and try to extract fines?

You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely.

> Is the EU going to extradite owners of these businesses?

Extremely unlikely, besides that would require the cooperation of the other country. But - and this is interesting - the other countries typically expect the EU to cooperate with extraditions when the law is broken and we do. So who knows.

> Are EU courts going to issue default judgements on businesses and individuals?

Against individuals: Unlikely, but it could happen, against businesses, that's typically how things go when one party doesn't show up.

But note that for that to happen you first have to ignore the regulators for long enough to get them really pissed off, an action I would recommend against.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#123

Earlier quoted context omitted.

I can see why you'd be disappointed - if popular websites started blocking US customers I'd be pretty bummed out as well (even if it was easy to circumvent). As a dev though, I also understand the frustration. Creating startups is already time-intensive and stressful. A lot of us are on shoestring budgets. Most startups will fail. To a solo developer in the US, the idea of spending time understanding and complying wi…

As a developer I can understand this point of view, but as a consumer I say it's time to grow up. Internet startups have taken a "move fast and break things" approach that is analogous to early industrial revolution approaches to worker safety, product efficacy and safety, and environmental protection. You're working in the real world, with real consequences if you end up exposing people's personal data. The party is…

> You're working in the real world, with real consequences if you end up exposing people's personal data. The party is ending. Either deal with it, or find something else to do.

They are dealing with it... by limiting their liability.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#124
post #50

Earlier quoted context omitted.

Is it onerous because you are doing dodgy things with EU citizens data, because you don't take information security seriously or because you've fallen for some of the FUD around GDPR (having to hire a DPO, being fined 2 trillion dollars, etc etc)? If it's too hard for you to copy paste a GDPR compliant privacy policy and monitor a GDPR email address then well, maybe you're in the wrong job.

We do take security seriously and we're not doing anything dodgy. We have business reasons for collecting user data, and users have no real reason to tell us to delete it at will, other than the fact that it makes them feel "creeped out". The future is probably going to be super creepy. If you want to participate, get over it.

Here is the thing: my email and personal info is mine. And if you are using my info to provide me your service that is also ok - I will rent that to you. And give you my CC#.

But if I do not use your service, then I want that you delete all my personal data. Why is that so hard?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#125
post #116

Earlier quoted context omitted.

I'm curious as to how many European companies comply with SOX, HIPAA, or COPPA just for the opportunity of making security/privacy compliance better?

How many European companies deal with US health data (HIPAA)?

If it worked the same as GDPR, I could start forcing them all to just by emailing them my health records.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#126

Keep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.

Genuinely curious; how is that even remotely possible to enforce?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#127
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

> Nothing has been learned.

Yet. Give it some time.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#128

Keep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.

I understand why you think this way. After all, GDPR is about human rights!

In practice, GDPR is binding on businesses that operate within the EU. An EU citizen in the US doing business with a US-only company is not afforded any protections under GDPR.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#129

Earlier quoted context omitted.

As a developer I can understand this point of view, but as a consumer I say it's time to grow up. Internet startups have taken a "move fast and break things" approach that is analogous to early industrial revolution approaches to worker safety, product efficacy and safety, and environmental protection. You're working in the real world, with real consequences if you end up exposing people's personal data. The party is…

> You're working in the real world, with real consequences if you end up exposing people's personal data. The party is ending. Either deal with it, or find something else to do. They are dealing with it... by limiting their liability.

They are avoiding it. Essentially they are voting themselves off the island to avoid having to play nice with the other inhabitants.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#130
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

Consider this case, startup app in a niche market, only available on US app stores, and a one man dev team that needs to focus on app dev not compliance for some regulation that could never apply to their customers. Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list. That’s the startup I’m presently working on. We’ll expand beyond the US borders…

An admirable effort, but all the fans of this law seem to hear is "You're not 100% compliant with the GDPR? You're scummy and shady and don't care about my privacy. I hope you fail immediately because the world is better off without you."

Meanwhile they'll be using VPNs to access your site anyway :)

Post reply on HN