Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

341–350 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#341

Earlier quoted context omitted.

Consider this case, startup app in a niche market, only available on US app stores, and a one man dev team that needs to focus on app dev not compliance for some regulation that could never apply to their customers. Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list. That’s the startup I’m presently working on. We’ll expand beyond the US borders…

> NOTE: we delete all client data when they cancel already. And we don’t do any creepy marketing. Do you inform your users what data you're collecting, why you're collecting it, and get their consent? Are you taking proper precautions with the expanded PII data (encrypting at rest for example)? You've basically covered the requirements. > Yet needs to be sure they don’t end up giving the company to the EU because som…

€20M / 4% of global revenue isn't fud. Right now, that would kill our bootstrapped operation.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#342
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

I'm wondering this too actually, I run a small business, we collect only the bare minimum of information from our customers but we do have some European customers. I'm ignoring GDPR completely, is there any downside for me? Will they block customers from using my service? Will they sieze my European cloud servers? Or can I safely do nothing as I currently am because I don't reside or have a registered business in Eur…

You have two solution:

1: ignore GDPR, you'll probably fly under. And if you dont, fine are scaled for business and people affected, as well as privacy infraction. Encrypt your backups, encrypt PII if you can do it effortlessly, and you're good. If you are not using emails except for checking double inscription, encrypt them too, the entropy is low BUT this is better than nothing .

2: If you have some time and money to spend to try to improve your services: self-report. A public agent will point you the weakness of your data processing.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#343

Earlier quoted context omitted.

Playing Devil's advocate, there are 193 countries in the UN; is it reasonable to ask site owners to keep abreast of the Internet laws passed in each one, and spend a couple of days for each, even if you just serve your compatriots? I'm biased for the GDPR, since I think every site should follow its principles regardless of legal obligation, but I don't think the rationale you're proposing is scalable.

Laws are made with physical borders in mind. Digital world doesn't have those borders. But it seems that politicians are expecting those borders to work. I'm not even sure about sane way to map IP address to country. There are some geolocation services, but I doubt that they are 100% precise and probably paid. Also if I'm using geolocation service passing IP of the incoming request, does that mean that I'm already vi…

With IPv4 stretched thin, there's a lot of international trade, even of small blocks. Also, multihomed servers can announce IPv4 from one ASN on another ASN, given permission. Anyway, it's nontrivial to really know where an IPv4 is located.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#344
post #141
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

As long as you're just "responding to HTTP requests", there's nothing to worry about and the GDPR does not apply. It's when you start collecting personal data on EU residents, send their personal data to third parties for analytics/targeted advertising, and so on, that things get interesting.

I can't think of any web server that doesn't log ip addresses by default, and I think it's been established that satisfies the GDPR threshold test for personal data. So while what you say is true, I think you're being a little bit deceptive when you say 'As long as you're just "responding to HTTP requests"' because all practical and established means of doing that violate the GDPR by default.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#345
post #339

Earlier quoted context omitted.

As a French guy, these type of comments make me smile. The GDPR is basically just the implementation of the French law "Informatique et Liberté" into the European Level. (You can read on HN many Germans saying that it's actually the implementation of the Datenschutzgesetzt. The truth is: these two laws are extremely similar.) This law has been in application since 1978 [1]. And in 2018, we have adtech companies like…

Yes, none of this is new or surprising. The irony here is that American users are so used to being endlessly surveiled without consequence that they are genuinely shocked that the rest of the world refuses to put up with this bullshit. This is completely normal to them. The GDPR is just another step in a global fight by people all over the world to regain their data sovereignty and protect themselves from endless sur…

Read the thread again. Nobody has a problem with data protection but the fact that the regulation is not actually clear, hence creating more work while simultaneously being rather ineffective. How is that good for the user?

Also it's hilarious to claim China has better privacy when that government tracks everyone using facial regulation with real-time threat scoring and national social rankings called a "citizen score". A late payment on a single bill gets your face and contact info on a giant billboard so go ahead and try complaining about your data over there and see how far that goes.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#346
post #214

Earlier quoted context omitted.

Why? You're opposed to privacy? And how do you plan to react when you get penalized?

I do care about privacy - I don't use Analytics on my website, don't show any ads, don't send marketing emails and don't sell customer data to anyone. However, I will not comply with that bureaucratic law, because the EU will not be able to enforce it in my country and I have much more important things to do to stay competitive on the market (I have a lot of competitors).

While I find your stance somewhat childish, I applaud you for "don't use Analytics on my website, don't show any ads, don't send marketing emails and don't sell customer data to anyone".

You're far ahead of the curve. May you profit from it somehow.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#347

Earlier quoted context omitted.

As a French guy, these type of comments make me smile. The GDPR is basically just the implementation of the French law "Informatique et Liberté" into the European Level. (You can read on HN many Germans saying that it's actually the implementation of the Datenschutzgesetzt. The truth is: these two laws are extremely similar.) This law has been in application since 1978 [1]. And in 2018, we have adtech companies like…

You mean Criteo the company that has lost over 50% of their valuation since last year because of cookie and consent issues? Yea it's going really well for them. https://finance.yahoo.com/quote/CRTO/chart?p=CRTO The difference is that France is insignificant in the adtech market. The real money is in the US and spread out across Europe, with Asia soon to overtake. The existing rules you point to weren't affecting glob…

The entire adtech business is due for correction.

It's strange that you think the business models are going to fly in Asia. China and many Asian countries are laying out privacy regimes that are even more strict than the GDPR. Take a look at China [1] or Thailand [2]. Pretty soon it will be the case only in America that adtech companies can collect and sell endless personal information without consequence.

[2] https://www.bangkokpost.com/business/news/1455534/new-data-l...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#348
post #325

Earlier quoted context omitted.

No: the law wants you to not have to do this. The law wants you to stop collecting data for things that are not core to your business. The issue is that companies are trying to maintain the status quo as much as possible, and annoying users with these does that.

Personalized, targeted advertising is how many services make money. So what is meant by 'the law wants you to not have to do this'. The law wants these services to not make money to cover their expenses? Or scale back their operations?

The problem only arise when you out-source the tracking and personalization of the ads. You could do the profiling, aggregation AND anonymisation on your end.

You're still allowed to have personalization and targetted ads, but now you actually have a responsibility for the data you collect and I don't view that as unreasonable.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#349
post #135
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Read up on FATCA ( https://en.m.wikipedia.org/wiki/Foreign_Account_Tax_Complian... ) before you argue further down that path. The US already has extraterritorial laws that have to be enforced by banks worldwide that don’t operate in the US.

There seems to be a big difference between enforcing a law on all financial institutions and enforcing a law on all websites basically that serve the EU. The latter seems next to impossible to enforce.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#350

Earlier quoted context omitted.

Wait a minute… You provide a service, and your users are afraid the GDPR could come to them ?!? Please tell me I've read something wrong. Otherwise, this is just panic induced stupidity. I expect they will grow out of it (though maybe not before you go bankrupt, which obviously sucks big time).

Depending on exactly what the service is, this makes total sense under GDPR. The GDPR regulates both Data Controllers, and Data Processors Suppose I'm excited to hear about Hats.example, a site that sells hats. I visit, but they don't have any hats for my ostrich. Damn. But, they do have a box where I can leave my email address "to be contacted about future products". Great, maybe they'll introduce Ostrich hats. I fi…

> But then, WeSpamPeople's VC runs thin, and they cut a deal with OutrightFraudAndScams.example, which tricks people into making dubious "investments" and wants a lot of "leads". Now as well as the hats newsletters I asked for but don't really care about, I'm getting stuff inviting me to invest in Venezuelan Bitcoin mining and a project to make "Green cyber-organic goats for the blockchain". Ouch.

Just so it's clear, you're positing that when WeSpamPeople breaks every existing contract they have, that those on the other side of said contracts are now liable?

Of course it could happen, but I don't see the EU fining those on the other side of the contract as long as they moved to another DP and alerted their users when the breach of contract was discovered. Both actions should happen regardless of GDPR.

Post reply on HN