I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…
The fact that the regulation is so vague around it in the first place is the whole problem. There are dozens of conflicting statements (from law firms, no less) about what exactly exposes you to GDPR.
GDPR for lazy people: Block all European users with Cloudflare Workers
201–210 of 1001 posts
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#202Earlier quoted context omitted.
GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes: I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required t…
> The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. (snip) That's their interpretation of GDPR. It doesn't matter whether it's right or wrong. This is the side-effect of GDPR. I understand it's frustrating on your side, because you have no control over the response of your customers. But understanding what GDP…
Your points don't "make the law right". In whose view? Right or wrong for whom? In his example he listed all the ways he is handling user data in a respectful way. And yet, he is still harmed by this law.
That the VP and President may be doing their jobs wrong (in your view) is no recourse for OP, he is harmed all the same.
And ... are they doing their jobs wrong? At the end of the day, they are limiting their risk. What threshold of risk of harm to their business and livelihoods would you feel is an acceptable tradeoff to comply?
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#203Earlier quoted context omitted.
GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes: I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required t…
Wait a minute… You provide a service, and your users are afraid the GDPR could come to them ?!? Please tell me I've read something wrong. Otherwise, this is just panic induced stupidity. I expect they will grow out of it (though maybe not before you go bankrupt, which obviously sucks big time).
The GDPR regulates both Data Controllers, and Data Processors
Suppose I'm excited to hear about Hats.example, a site that sells hats. I visit, but they don't have any hats for my ostrich. Damn. But, they do have a box where I can leave my email address "to be contacted about future products". Great, maybe they'll introduce Ostrich hats. I fill out the box.
Hats.example uses famous email deliverability company WeSpamPeople.example to ensure their marketing emails have "industry best in class reach". I soon get an email every week featuring different styles of hat, but they're all for people, disappointing.
But then, WeSpamPeople's VC runs thin, and they cut a deal with OutrightFraudAndScams.example, which tricks people into making dubious "investments" and wants a lot of "leads". Now as well as the hats newsletters I asked for but don't really care about, I'm getting stuff inviting me to invest in Venezuelan Bitcoin mining and a project to make "Green cyber-organic goats for the blockchain". Ouch.
Hats.example are a Data Controller. The GDPR says they are responsible for looking after the data that I gave to them, even if "technically" that form I filled out is a Javascript frame injected by WeSpamPeople.example, it's part of the Hats.example business, so it's their responsibility to ensure my email is not abused by a processor like WeSpamPeople.example, for example through contractual terms requiring WeSpamPeople.example to delete my email, never to send it elsewhere, etcetera.
WeSpamPeople.example are a Data Processor because they were given my email address and other details to send me "marketing" information. They have a duty under the GDPR to get reasonable assurance that this was OK with me, for example maybe Hats.example did some paperwork that promised they're legitimate and they got sign-off for these email addresses. Regardless of whether they were given terms requiring them to do so by the Data Controller, the GDPR says they have to take care not to abuse the data, for example they can't sell it to anybody, since they obviously don't have permission to do that.
OutrightFraudAndScams.example are also a Data Processor, and maybe also a Data Controller they know they didn't have permission to touch this data, but presumably they also routinely violate all sorts of other anti-fraud or anti-scam laws. Maybe the GDPR will help add to the fines and charges and put them out of business.
[Edited: minor typos / fixes]
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#204Considered this before, but it doesnt work. IIRC, the law applies to euro citizens both living in country and abroad. As such, geoip blocking is not a working strategy. (a french citizen who lives in japan still had GDPR rights) A better one would likely be a clickwrap agreement for all users stating "European citizens are not allowed on this service" which they have to click a "I am not european" tickbox to.
How the hell does the EU claim extraterritorial jurisdiction over the entire world? And people complain about America being “imperialist?”
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#205Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#206Earlier quoted context omitted.
It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…
And yet, multiple companies that do all kinds of crazy things with your data ( https://www.google.com/search?q=gdpr+shutdown ) have shut down already as a result of GDPR. You could argue that wasn't the goal but I'm pretty sure it was part of it and seems to be effective in that way at least.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#207Earlier quoted context omitted.
It all depends on your investors and who your company's target audience is. If I run a business putting up American flags on people's houses on patriotic holidays (an actual business in my neighborhood), then ignoring the EU market is an easy decision because I already was.
And if you presented a nice growth graph over American customers with the implication for expansion over other regions such as EU, whats the possibility that some investors considered that potential when they invested? Like say a software service which I would assume is more common investment target here rather than flags.
For all its noise and bluster about "500 million customers lost!" the European Union is still less than 7% of the world. I think most businesses would be happy to serve the other 93%.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#208Earlier quoted context omitted.
GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes: I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required t…
Wait a minute… You provide a service, and your users are afraid the GDPR could come to them ?!? Please tell me I've read something wrong. Otherwise, this is just panic induced stupidity. I expect they will grow out of it (though maybe not before you go bankrupt, which obviously sucks big time).
Yes.
It's not unreasonable, because GDPR has components that require vendor assurance (more or less). So the megacorp with a point-of-presence in the EU has to be cautious about what strictly-US SaaS services it uses if there's any potential for data crossing into the SaaS.
This is almost certainly exactly what GDPR is intended to do. It aims, in part, to make sure companies can't shirk their responsibilities by handing everything over to vendors who will ignore GDPR.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#209I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…
> Is the EU going to target American banks of American businesses and try to extract fines? You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely. > Is the EU going to extradite owners of these businesses? Extremely unlikely, besides that would require the cooperation of the other c…
Ahh yes, one of my favorite logical fallacies: https://en.wikipedia.org/wiki/Tu_quoque
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#210Earlier quoted context omitted.
If a company does not understand GDPR it's fair to say I don't want them handling my personal data. And it's not like this is new, there was a 2 year period to prepare for this. "Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.
The challenge is absolutely not technical, so 2 years makes no difference. The challenge is that GDPR is essentially impossible to comply 100% with, and absolutely impossible to comply without incurring extra costs. GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, incl…
You didn't (as hundreds of others), so now the EU forces you to. So now you have an opportunity to become a better company: https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...