Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

171–180 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#171
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

Consider this case, startup app in a niche market, only available on US app stores, and a one man dev team that needs to focus on app dev not compliance for some regulation that could never apply to their customers. Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list. That’s the startup I’m presently working on. We’ll expand beyond the US borders…

> NOTE: we delete all client data when they cancel already. And we don’t do any creepy marketing.

Do you inform your users what data you're collecting, why you're collecting it, and get their consent? Are you taking proper precautions with the expanded PII data (encrypting at rest for example)? You've basically covered the requirements.

> Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list.

What kind of FUD are people reading...if someone voluntarily gives you their email to sign up for a list that's fine. You just need to keep that they consented to receive what they agreed to. What you can't do is use that email for crap they didn't sign up to receive. Obviously normal unbsub rules apply, which in this case says forget that someone ever signed up.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#172
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

If this is anything more than fear of change (I suspect it isn't, once people get a little more accustomed to GDPR and some of the inevitable issues are ironed out), and other device owners start blocking EU citizens, I suspect GDPR may end up being a huge boon for Europeans. Much like China, which has managed to develop a huge internet industry because it doesn't have to compete with the American competitors, the EU…

American competitors aren't going to refuse to do business in the EU. They're going to comply with GDPR for EU customers, and in some cases across the board. I keep hearing how easy it is to comply. Then that's that, it's easy and there's money to be made, so US competitors will continue to be dominant as before.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#173
post #152

Earlier quoted context omitted.

I'm curious as to how many European companies comply with SOX, HIPAA, or COPPA just for the opportunity of making security/privacy compliance better?

Please read about FATCA

That isn’t about data protection— it’s actually the opposite, it’s about Euro banks sharing data with US authorities. Furthermore the unintended consequence of FATCA is that many Euro banks stopped allowing accounts from Americans because they didn’t want compliance risk. GDPR is having the same effect: US companies will refuse service to Europeans because of compliance risk.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#174
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I really enjoyed this quote from [1] > I would be very wary of a company who claims this legislation is onerous. It is potentially life threatening to companies who do very shady things without your consent. That much is true. That is the entire point. I somewhat suspect those companies hiding behind the 'oh lets just block Europe' excuse just don't want to admit the extent of what they are doing with the data. US ci…

This might be it for like a very small handful of malicious companies. More realistically they are companies who have very little market share in the EU and their attorneys are very risk-averse and tell them a simple opt-out with few billing hours creates the most ROI.

EU citizens should not be pissed off that second-order effects exist in the world. If they are, they need to take ECN 101/102 again and pay closer attention.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#175

Joking aside, I have yet to find a site that isn't using the whole dark patterns book and then some to trick users to consent. Realy disappointing.

I received an email from a website I don't remember signing up for, and have no clue what they do. After a few attempts I am able to log in. I go through menu after menu looking for the "permanently delete all my data" button only to find an FAQ that says

"Q: How do I delete my account?"

"A: Please get in touch with our Customer Services team if you have any worries or concerns. If something at {website} has troubled you, we'll be happy to help sort it out."

To their credit, the support chat person was very efficient in complying with my request.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#176
While I know they are not recommending, recommending this, for everyone who does, this doesn’t get you off the hook at all unless you are a new site who has never had EU visitors. Also of course all the EU citizens in the US, GDPR would presumably still apply.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#177
post #169

Just curious, but what does the investors think when a company volentarly leaves the EU market because it is easier to simply ignore eu as a market then to comply to GDPR?

It all depends on your investors and who your company's target audience is.

If I run a business putting up American flags on people's houses on patriotic holidays (an actual business in my neighborhood), then ignoring the EU market is an easy decision because I already was.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#178

Earlier quoted context omitted.

Some of us do work for companies who respect and promote GDPR who are not based in EU, and we're hiring. Leave, that's a perfect example of terrible leadership.

Agreed. When the Volskswagen story broke that was my first repsonse: Management Failure. No matter how you slice it in a company that is run in a hierarchical fashion there is no way that an employee at some level decides to break the law in such a blatant manner without being pressured to do so in some way. Which in the longer term turned out to be right. I'd love to see Winterkorn behind bars for that one.

Well, that was what VW said from the beginning. Although it was presented as "rogue engineer", the person they originally presented was the head of the entire department, and a VP at VW. And VW is suing Winterkorn in a civil case, too.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#179

Keep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.

> Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#180

Earlier quoted context omitted.

The loudest GDPR advocates don’t care about you. 90 years ago they would have been the ones helping collectivize the farms, unintended consequences be damned. And this law’s effects are all about the unintended consequences. Anyone thinking government regulators are reasonable and benevolent has never dealt with said regulators beyond any trivial level. To make it more fun each member country handles enforcement, so…

> 90 years ago they would have been the ones helping collectivize the farms This is possibly the strangest comment I've seen about this whole ordeal.

I guess they are just saying you are a communist if you like GDPR. Maybe even a Stalinist.
Post reply on HN