Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

131–140 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#131
I didn't get past the first paragraph. The site lobbed four interruptions my way:

  - Agree to cookie
  - Forced "Do you want our newsletter" prompt
  - Request to show notifications
  - Pop-up icon to subscribe to notifications
... and one non-intrusive top-of-page banner notification, " Awesome! Your IP is not in our blacklists of abuse...". This last item (when dismissed) may have triggered the 4th item above.

Edit: fix list formatting

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#132
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Recital 23 [1] of the GDPR excludes most US-based businesses from compliance with GDPR. It essentially says that sites that don’t “envisage” (their word) offering services in the EU are in fact not offering services there for the purposes of the GDPR and are thus are not subject to it. It also explicitly states that the mere accessibility of a foreign-based website from within the EU does not by itself subject the site to GDPR.

So while blocking the EU isn’t required, the other tests they use to determine whether or not you intended to offer services to EU residents are a bit murky. In light of that, what better way is there to make your intention to not serve EU users clear to all than to block EU users? That’s the main reason to do it. This kind of blockade will not prevent all EU users from accessing your site, but it doesn’t matter. You’ll have made your intent to not serve EU users clear, which will preserve your immunity to GDPR.

[1] http://www.privacy-regulation.eu/en/recital-23-GDPR.htm

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#133

Earlier quoted context omitted.

If a company does not understand GDPR it's fair to say I don't want them handling my personal data. And it's not like this is new, there was a 2 year period to prepare for this. "Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.

The challenge is absolutely not technical, so 2 years makes no difference. The challenge is that GDPR is essentially impossible to comply 100% with, and absolutely impossible to comply without incurring extra costs. GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, incl…

It's not possible for a financial institution to exist without incurring 'extra costs' for SOX and KYC compliance. And yet they all do. That pesky regulation seems to be useful.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#134
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I really enjoyed this quote from [1]

> I would be very wary of a company who claims this legislation is onerous. It is potentially life threatening to companies who do very shady things without your consent. That much is true. That is the entire point.

I somewhat suspect those companies hiding behind the 'oh lets just block Europe' excuse just don't want to admit the extent of what they are doing with the data.

US citizens should take note of this, because it's their data too.

[1] https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#135
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Read up on FATCA (https://en.m.wikipedia.org/wiki/Foreign_Account_Tax_Complian...) before you argue further down that path. The US already has extraterritorial laws that have to be enforced by banks worldwide that don’t operate in the US.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#137
post #126

Keep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.

Genuinely curious; how is that even remotely possible to enforce?

It's not. If you have any legal disagreement with a company outside the EU they tell you to complain on that company origin.

I experienced this myself. EU is absolutely powerless outside their borders.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#138

Earlier quoted context omitted.

If a company does not understand GDPR it's fair to say I don't want them handling my personal data. And it's not like this is new, there was a 2 year period to prepare for this. "Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.

The challenge is absolutely not technical, so 2 years makes no difference. The challenge is that GDPR is essentially impossible to comply 100% with, and absolutely impossible to comply without incurring extra costs. GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, incl…

What are these companies doing that makes it so hard to comply?

I've been involved in GDPR efforts at work and all the policies seem fairly straight forward to me. If you're not doing shady shit and you're upfront with your users what you are collecting the data for, how long you keep it and what access policies you have set up.

Not a problem if you ask me.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#139

Earlier quoted context omitted.

>Nothing has been learned In my limited view, this is pretty much the case. When I was telling our management team about the GDPR and how it relates to our new European-focused project, the first thing the CEO said was "how do we get around this?" Management decided we're not gonna comply with the GDPR and just hope nobody notices.

Some of us do work for companies who respect and promote GDPR who are not based in EU, and we're hiring. Leave, that's a perfect example of terrible leadership.

Agreed. When the Volskswagen story broke that was my first repsonse: Management Failure. No matter how you slice it in a company that is run in a hierarchical fashion there is no way that an employee at some level decides to break the law in such a blatant manner without being pressured to do so in some way.

Which in the longer term turned out to be right. I'd love to see Winterkorn behind bars for that one.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#140
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Yes, this is the way the law, prosecution and judgement works. If you violate GDPR and the EU prosecutes you and you don't even show up to court and there is judgement against you and you are fined, the EU can try to get paid from your bank. That's how law, prosecution and judgement work in America too. How else would it work? Why would anyone obey any regulation or ever show up to court otherwise?

That being said, the starting point shouldn't be, "there's no need to imagine that I'm violating GDPR. I only serve Americans". The starting point should be, "I had better imagine that I might be violating GDPR even though I only intend to serve Americans. Are there things I haven't considered? Are there resources I should seek out? As a service provider of some kind, hadn't I better spend a day or two imagining the ways I might run into trouble and plan to avoid it?"

Post reply on HN