Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

211–220 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#211

Earlier quoted context omitted.

Recital 23 [1] of the GDPR excludes most US-based businesses from compliance with GDPR. It essentially says that sites that don’t “envisage” (their word) offering services in the EU are in fact not offering services there for the purposes of the GDPR and are thus are not subject to it. It also explicitly states that the mere accessibility of a foreign-based website from within the EU does not by itself subject the si…

A point with many sites is that they use ad networks and those ad networks send localized ads to Europeans, thus the site targets (or "envisages") Europeans. Even if the actual content is about quite local things.

In my personal opinion, that would be both a stretch of this recital and an abusive use of the GDPR. You don’t control what ads are shown to anyone because they are served by a third party, and you have a good faith belief that you are not subject to GDPR under Recital 23. My guess is that if you used an ad network that specialized in EU ads, you’d be subject to it. But using code from a US ad network that may have some EU advertisers now or in the future shouldn’t expose you.

But I don’t disagree that some EU countries that intend to abuse the GDPR for the purpose of generating massive amounts of revenue from fines may try to make this kind of claim. One of the problems with GDPR is that when you combine unclear regulation with the lack of moral hazard that government agencies enjoy and the financial incentive of massive fines, you create a monster that will constantly seek to expand who and what is covered under it.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#212

Earlier quoted context omitted.

If there's a successful business that blocks EU access due to GDPR, that's a huge immediate opportunity to enter that market in the EU (unless, of course, the business model is based on resale of personal information).

Which is exactly the point of the law — it’s a trade barrier.

EU companies also have to abide by it so I don't know how it is a trade barrier.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#213
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Yes, this is the way the law, prosecution and judgement works. If you violate GDPR and the EU prosecutes you and you don't even show up to court and there is judgement against you and you are fined, the EU can try to get paid from your bank. That's how law, prosecution and judgement work in America too. How else would it work? Why would anyone obey any regulation or ever show up to court otherwise? That being said, t…

Playing Devil's advocate, there are 193 countries in the UN; is it reasonable to ask site owners to keep abreast of the Internet laws passed in each one, and spend a couple of days for each, even if you just serve your compatriots?

I'm biased for the GDPR, since I think every site should follow its principles regardless of legal obligation, but I don't think the rationale you're proposing is scalable.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#214

I plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.

Why? You're opposed to privacy? And how do you plan to react when you get penalized?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#216

Earlier quoted context omitted.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

>because its based on principles rather than hard rules They tried hard rules, rather than principles with the cookie laws and the companies around the world turned a good idea into a shit-show of popups while continuing to behave like nothing happened. Honestly the more I read and the more I see how different business react I start to view the GDPR as EU finally showing that will not accept businesses viewing it as…

95% of my GDPR work has done nothing for actual privacy. If this is how the EU "represents the best interest of 500 million people," then no thank you.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#217

Since there are IP addresses collected and sent to third parties without consent, it violates the GDPR.

An IP address is not regular PII, its 'linked PII'. It must be collected in conjunction with information that can identify a user to fall under GDPR, an ip on its own is worthless. If an IP address allows you to link information from HTTP logs with a user database that does have PII, then the ip address is part of the PII. If you aren't collecting any actual identifying information, then an ip is fine.

I hate the GDPR hysteria as anyone but you might be approaching this topic a bit too casual. The GDPR doesn't speak of "regular PII" or "linked PII".

Article 4.1 defines an identifiable natural person as one who can be identified, directly or indirectly, in particular by reference to for example an online identifier.

IP addresses are specifically mentioned as online identifiers in recital 30:

> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags

Only time will tell how this will be interpreted specifically but we have at least one court decision already [1]:

> What makes a dynamic IP address personal data?

> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:

> there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and

> the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual.

[1] https://www.whitecase.com/publications/alert/court-confirms-...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#218
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

As a French guy, these type of comments make me smile. The GDPR is basically just the implementation of the French law "Informatique et Liberté" into the European Level. (You can read on HN many Germans saying that it's actually the implementation of the Datenschutzgesetzt. The truth is: these two laws are extremely similar.)

This law has been in application since 1978 [1]. And in 2018, we have adtech companies like Criteo. [2] I have one of my best friend who started his adtech startup in France. Everything is good.

There's is a lot of implicit contracts (you filled up our sign up form? Well, then you chose to give us your data. ...) The only things you have to do: know which data you collect and give the ability to people to update/delete their data. That's all.

I don't understand the fear. I don't understand what is "vague" about it. It's so simple and low barrier that Microsoft decided to make it the rule for all of their users. But thanks to the hysteria, they made a PR stunt out of it.

--

[1] https://en.wikipedia.org/w/index.php?title=Data_ownership&ol...

[2] https://en.wikipedia.org/wiki/Criteo

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#219

I plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.

You better hope you fly under the radar then.

Why? Bad press often makes for great business.

Not parent commenter btw, just my two cents

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#220

I plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.

I think you're just grandstanding, since I hope anyone with a sufficiently large business would understand who and where their customers are and what laws would affect their revenue streams.

Smells like another right+ forward from grandma.

Post reply on HN