Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

911–920 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#912
post #902

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

Yep. Doing a one person startup (in the US) I absolutely do not have time (or money) to mess around trying to figure out GPDR compliance. I'm not selling data to anyone, and I'm not collecting anything beyond an email address during sign-ups at this point, in any case. If a user decides they want to store PII or other sensitive data on my system, I can't stop them, but I'm not going to go combing through their data i…

Sounds like you wouldn't have to change anything then.

Make extra personal data stuff opt-in, rest should be the same as usual.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#913

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

The thing for me is that it requires me to log additional data. Now I need to know where my users are from, how old they are, and how often and how they access their account.

All data I happily ignored so far to increase privacy.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#914
post #865

Earlier quoted context omitted.

Because if your business model is based on selling user data, it doesn't matter if you're a small startup, it absolutely is meant to target you. If you aren't competent at responsibly handling personal data and you want to build a project or startup, pick one that doesn't handle personal data, or put in the effort to learn how to do things properly.

How does for example a small yoga studio’s email list fit in your examples? Or even just it’s website? Without cookies and login even - the IP adress in the log files alone is considered potential personal data that basically puts people in the need of consulting a lawyer about how to safely deal with that. And makes you a potential target to being sued and getting a lot of hassle. Even found nit guilty in the end, n…

IP address are permitted under the security exception: Storing personal information in order to protect information or information systems is permitted without need for consent. Using your log files for security explicitly permitted and there is nothing that changed a system administrators job before or after GDPR on this point.

If you are using a email list in order to fulfill a contract to your members by informing them about times and so on then that is also permitted by GDPR. If a customer buys a subscription then the company in order to fulfill their side of the contract can then naturally store information to do so.

Mailing lists also has had a long history of best practices in order to not get marked as spam by the large email services. Get consent so users don't mark it as spam and allow unsubscribing. If a small yoga studio used a email list for a significant time and not been forced to do shady behavior in order to bypass spam filters, then they are almost guarantied to be compliant with GDRP.

Similar an online business has a contract when a customer buy a product or service. In order to fulfill that contract a email address is commonly used. Perfect GDPR compliant. Hard to imagine a online business before GDRP that did not have a contract with customers.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#915

Earlier quoted context omitted.

> It's a foreign requirement that feels like a violation of sovereignty. Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws. EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local…

>Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws. If I have a brick and mortar business in the US and some one from the EU decides to do business, do I have to follow EU consumer protection laws? Unless I have an physical presence in the EU why should I have to follow their regulations? Further, why cannot the…

> If I have a brick and mortar business in the US and some one from the EU decides to do business, do I have to follow EU consumer protection laws? Unless I have an physical presence in the EU why should I have to follow their regulations?

You don't.

If they're not In The Union, and you're not In The Union, then you're not required to comply with the GDPR.

> Further, why cannot the EU just allow its citizens just do business with other extra-national companies if they choose to? Meaning, if an EU citizen chooses to do business with a non-GDPR compliant website, why does the EU care?

It's impossible to give consent for something if you don't fully understand the ramifications of what you're consenting to[1].

[1]: https://www.nytimes.com/2018/03/17/us/politics/cambridge-ana...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#916

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

I think businesses should just charge EU customers more for their products, in order to make up for the compliance costs of GDPR. That should make most people happy.

Great! That opens the door for other startups that ARE responsible with people's personal data.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#917
Encouraging this attitude is childish. GDPR (which has been around for 2 years now) is a way for people to say "ok now grow up guys, we know you like to tinker, but we're getting screwed in ways we don't like and we've given you enough rope". This post is saying "so just don't sell soylent in the US because we're too good to bother passing FDA".

No serious and earnest would/should consider this.

Your work affects lives. Period.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#918
post #633

Earlier quoted context omitted.

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

It's reassuring to hear that the GDPR is not meant to target little startups and projects but I would like it a lot better if it said that in the actual law, rather than just trusting all current and future regulators to treat me kindly. If it's only meant to be used against big companies or extreme offenders, why doesn't it say so? It seems like the spirit of the law and the language of the law are not aligned and i…

I'm sure a whole cottage industry around GDPR compliance will be up and running by the 26th. :|

We're a small agency and all of the legal worries around the GDPR have essentially put one of our revenue streams on hold until we sort out the legalities. Like the comment above, we simply do not have $300/hr available for lawyers to go over everything.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#919

HN Meta: Is it really necessary to split 1k comments into 5 pages? Many sites serve a homepage much larger than every comment here on a single page.

It isn’t just to limit page size, it also works as a damper on heated discussions, as most people won’t read more than the first page, but comparatively few people stop reading in the middle of a page, regardless of length.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#920

Earlier quoted context omitted.

"but I would like it a lot better if it said that in the actual law" Have you read the bloody law! http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... This is legislation designed to protect not only me (as an individual) but you as well (as a probable foreigner) from me!

Reading the law, I only see a single exception for small companies: Article 30.1 and 30.2 doesn't apply for companies less than 250 employees. Out of an 88 page law, 1% of an auxiliary middle of the law is carved out for small companies. I'm not sure that counts as differential application for small companies. In the US at least, large portions of entire key burdensome laws don't apply for employers below size 50, 10…

Similar laws have existed for many decades. In The Netherlands, privacy laws date back to the 1970s.

At least my reading of the GDRP is that it tries very hard not be a big burden. If you are a small company or organisation and you collect a minimal amount of information (for example to contact them) there is not a lot you have to do.

The main thing is, you are not allowed to be sloppy. If you collect personal data, you have to think about whether you should collect it at all, where to store it, process it, and when to delete it. And you have to tell people that before you ask them for personal data.

Nothing like, we just collect a bunch of data, give copies to everybody, and have no idea what we collected. That attitude no longer works.

If you set up food regulations, are you going to exempt restaurants with only one cook? Or have aviation regulations that do not apply to airlines with only one pilot?

Given that the entire GDRP is less then a hundred pages, you can easily read it in one evening and get an idea of what you can do, have to do, and what the corner cases are that you may need to discuss with a lawyer.

Post reply on HN