Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

811–820 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#811

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

The european union provides a FAQ for the GDPR so you don't need a lawyer if you have a small business: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

The "best practice" you mention was already illegal if you have European users, the right to be forgotten was already a consequence of existing laws and directives (just ask Google).

As for startups the GDPR already takes company size into account, so unless their business is literally being a private NSA/Stasi/etc. they don't have much burocracy to deal with (https://ec.europa.eu/info/law/law-topic/data-protection/refo...)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#812
post #613
post #590

Earlier quoted context omitted.

This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every websi…

> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every web…

I have a blog. No ads. No revenue.

1. I have been using Google analytics for their entertainment value. I assume that's verboten now.

2. I assume the IP addresses in my logs are PII. Should I shut off logging?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#813

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

Technical person here! I was tech lead at an energy company in the Netherlands. We had a compliance dept (mostly 1 person) I worked closely with before GDPR was on the radar as the energy sector here is fairly well regulated.

It’s true that compliance can sometimes be scary and requirements are not always clear. Big company ending fines probably keep some people awake at night.

The point is regulators don’t generally want to end your company, they want to see (proof of) reasonable efforts towards full compliance.

Compliance does take time and effort and can be technically challenging. It can be a constant overhead on regular technical / development efforts. But it also isn’t rocket science. It would help people to not overreact (also, there has been lots of time to prepare for it).

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#814
post #375

Earlier quoted context omitted.

> ban on EU IPs is both draconic and ineffective It doesn't matter it's ineffective. The block means they're complying with GDPR's requirement that they not target Europeans.

But they still process European user data if they do not block my IP. So they are not complying at all with GDPR's main requirement, just a poorly singled-out subclause.

No, the blame would be on you then and you would be held responsible for whatever legal action is necessary, not the company trying to block Europeans users like you. Benefit of the doubt is for the company because of their best effort European citizen blocking.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#815
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

Silicon Valley folks need to pay their mortgages, fancy cars and Faberge eggs. Privacy to their victims is a minor concern.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#816

Earlier quoted context omitted.

Well thats because you dont understand GDPR. If the company doesnt conduct any business in EU - or more correctly with EU private persones - then GDPR doesnt apply to the company. It also doesnt apply for any Business-2-business relations. GDPR only applies if you are providing a service to a EU citizen. That also explains what EU will do if a company doesnt comply with GDPR (where it should); they will stop the comp…

You're mistaking GDPR's intent with its implementation, an error that lots of people are making. As Americans we're particularly sensitive about having to follow rules made by people who don't represent us and are not accountable to us. This is a totally fair and justifiable reason to be against GDPR even if you agree with its objectives.

“As Americans we’re particularly sensitive about having to follow rules made by [others]”

That may be one of the most ironic comments I’ve ever heard. I love americans, but as a super power you stick your nose into so many other countries business, directly or indirectly. So, lets just say that argument is not gonna change my view in any way.

I don’t think I am mistaking intent with implementation. The regulation’s written text leavea many details to be answered along the way and the first couple of rulings on GDPR will (hopefully) bring us a lot of insigts into how to interpret and implement GDPR in practice. So I guess no one really knows the implementation yet. Until then we have to go by what is reasonable and the intent. And if you store data on private citizens you better treat it correctly.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#817

Earlier quoted context omitted.

Funny thing is there are also mandatory data retention regulations that say data MUST be maintained for a certain period of time by law. It's getting worse, but it's generally been the case that it's impossible for an individual to bootstrap a company and be 100% compliant with every law and tax regulation. You would never have any time to actually provide a product and service customers. You just do the best you can…

GDPR just says that if you are keeping data, you have to have a good reason for it. If you have to retain certain data for eg tax purposes, then that sounds like a good reason to me.

More than that, "compliance with a legal obligation" is specifically called out as one of the six legal bases for processing data.

It's like people are complaining about something they haven't taken the trouble to understand. That couldn't possibly happen HERE, the bastion of rational hacker ethic, could it?

I miss the days when "hacker ethic" meant weird Unix enthusiasts and not neolibertarian grifters...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#818

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

>The number of people who are saying it’s no big deal to comply with this huge law

It's not if you're actually thinking about what you should be doing with user data from an ethical perspective. Our company has had zero problems complying with GDPR.

>My biggest fear is that all of these complex bureaucratic laws

Allow me to be extremely blunt here. If you think these laws are complex and if you have to resort to meaningless U.S. connotations of bureaucracy, you shouldn't be handling user data.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#819

Earlier quoted context omitted.

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

How do you handle developer computers with possible client data on them, even semi-anonymized? Or when communicating issues on the live server, you might transfer client information to other stake holders to debug issue. Are you tracking that communication. Where does the communication data reside, perhaps on a server outside of the EU? There is a lot of complications that arise if you think about the second order/th…

If you have developer computers with client data on it, semi-anonymized or not, I want you fined until you stop. What the hell is wrong with that hypothetical business?

It's like restaurants putting the toilet in the kitchen. Shut the business down!

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#820
As a person on both sides of this regulation I have to say I'm not conflicted at all were I stand. On a professional level this will have a huge impact on the firm that I've been employed for more than 5 years because of the legacy practices used in the software. This has been the proverbial "clusterfuck" at work. This might even have serious implications to the future of the firm as most of our customers reside in EU. Nevertheless on a personal level I'm so happy and relieved that finally something is being done to protect information. In fact I believe that the tighter the screw on the regulation the better. If some businesses have to stop entirely in order to reevaluate what has been done, why it shouldn't be done this way(I like the analogy about slavery I read in the comments here) and start from scratch if possible at all, then so be it. Even if it threatens my job security(and I just bought myself an apartment) I'd still be in favour of this. In fact I believe that in a few years if this sticks it would be much easier if not trivial to deal with GDPR regulations and then my only regret would be that this was not implemented sooner.
Post reply on HN