Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

251–260 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#251
post #222
post #214

Earlier quoted context omitted.

Why? You're opposed to privacy? And how do you plan to react when you get penalized?

Because he's lazy and thinks he'll get away with it. He'll come into compliance after penalties outweigh the costs of changing the way he does business. This is probably the reaction of the vast majority of folks dealing with customer data, and not at all unexpected — they have a business to run, and costs to customer privacy are an externality being rolled into their costs via regulation.

Also, this is one of the sane solution if he know he has not that much user data. First fines will not be high or won't happen at all, and he will receive advice and even help from regulatory instances if he is ever reported.

If every business owner commenting those GDPR post on HN could act the same and not like headless chicken, discussions would be more healthy.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#252
post #197

Earlier quoted context omitted.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

And yet, multiple companies that do all kinds of crazy things with your data ( https://www.google.com/search?q=gdpr+shutdown ) have shut down already as a result of GDPR. You could argue that wasn't the goal but I'm pretty sure it was part of it and seems to be effective in that way at least.

Like what exactly? The vast majority of them don't do anything that crazy other than storing an email or running some ads on the site, which is completely insignificant compared to the detailed profiles that Facebook and Google have and will continue to maintain. And it doesn't even touch the ISPs, credit unions, medical companies or other deep databanks.

Right now there are billions of people around the world clicking "yes" on all the privacy and consent popups while grumbling about the annoying notices and just wanting to get back to what they were doing. Meanwhile there are also plenty of people creating havoc by filing lawsuits against every company they can, adding up to billions demanded on just the first day.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#253

I plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.

...and why would you do that?

We'll soon get used to websites following good privacy policies, so your SaaS will just look less appealing to Europeans.

Is it really hard paying attention to how you handle people's sensitive information without selling it to third-parties?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#254
post #214

I plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.

Why? You're opposed to privacy? And how do you plan to react when you get penalized?

I do care about privacy - I don't use Analytics on my website, don't show any ads, don't send marketing emails and don't sell customer data to anyone. However, I will not comply with that bureaucratic law, because the EU will not be able to enforce it in my country and I have much more important things to do to stay competitive on the market (I have a lot of competitors).

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#255

To offer a non-dev perspective on Hn, it feels like tech companies are really trying to annoy us users with GDPR updates in an effort to nurture opposition to similar proposed regulations in the future. I hope it doesn't work. I love GDPR, getting rid of the WHOIS database stuff alone is enough to make me a huge fan. The option to delete my data is also amazing.

>To offer a non-dev perspective on Hn, it feels like tech companies are really trying to annoy us users with GDPR updates in an effort to nurture opposition to similar proposed regulations in the future. I hope it doesn't work.

You think businesses are that forward thinking? You think there is some grand conspiracy to annoy users so that they hate regulation?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#256
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

Pretty awful.

I guess they can afford it.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#257

Earlier quoted context omitted.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

What you have described is _exactly_ how regulation works. It's still a hundred times better than what most countries in the world produce, since it's designed around the average human and not a megaco.

This isn't about how it works, it's about whether it works or not. That companies need to follow the law isn't exactly confusing, and nobody is saying they shouldn't, but when the law cant even clearly answer basic questions of who it applies to and when, that's a problem.

There are examples of regulation that does work, but GDPR is not really in that category.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#259
post #13

Earlier quoted context omitted.

You're the third person to ask this and I'd like to ask you: is this idea coming from a specific source? The law, like any other EU law, obviously does not apply outside the EU. It applies to companies that do business in the EU (even if they are based outside), but it can't apply to companies that don't do business there. https://ec.europa.eu/info/law/law-topic/data-protection/refo...

It actually isn't clear that it doesn't, as best I can tell. I don't have the text in question in front of me, but one of the questions I've asked and haven't gotten a solid answer on is - who is covered by GDPR? Is it only EU citizens residing in the EU, or EU citizens generally? If it's the latter, then someone with both US and German citizenship could be covered even if they've never been to the EU.

"data subjects in one or more Member States in the Union."

People (regardless of EU citizenship status) who are physically in the EU.

This isn't so hard.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#260

Earlier quoted context omitted.

>because its based on principles rather than hard rules They tried hard rules, rather than principles with the cookie laws and the companies around the world turned a good idea into a shit-show of popups while continuing to behave like nothing happened. Honestly the more I read and the more I see how different business react I start to view the GDPR as EU finally showing that will not accept businesses viewing it as…

95% of my GDPR work has done nothing for actual privacy. If this is how the EU "represents the best interest of 500 million people," then no thank you.

Can you elaborate please ? And what about the other 5% ?

I mean, if companies cared about privacy in the first place, there probably wouldn't be the need for such a regulation. At the very least, GDPR will get the general population be conscious about what the hell is going on under most websites.

Post reply on HN