The privacy of EU persons coming in from a non-EU IP address still need to be protected under GDPR. This solution is a start but it's not bulletproof. Edit: I don't want anyone to think I believe it's a good start but it is a kind of solution. I wonder if lots of US companies, once they begin to realize GDPR is a problem for them, won't decide to try one of two things: 1. This: block access from IP addresses believed…
GDPR compliance as a service
31–40 of 158 posts
Re: GDPR compliance as a service
#32See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have to comply with the GDPR.
I refuse to believe this is not a joke.
Re: GDPR compliance as a service
#33> Simply paste our JavaScript snippet into your website's code. We'll check every visitor of your site and will block access to users located within the EU. See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have…
Re: GDPR compliance as a service
#34Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?
Re: GDPR compliance as a service
#35> Simply paste our JavaScript snippet into your website's code. We'll check every visitor of your site and will block access to users located within the EU. See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have…
Not a joke :). GDPR Shield as a product is GDPR compliant. Customers sign a data processor agreement with the service. It anonymizes IP addresses, they aren't transferred to any other third-party provider and aren't stored.
Re: GDPR compliance as a service
#36> Simply paste our JavaScript snippet into your website's code. We'll check every visitor of your site and will block access to users located within the EU. See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have…
Not a joke :). GDPR Shield as a product is GDPR compliant. Customers sign a data processor agreement with the service. It anonymizes IP addresses, they aren't transferred to any other third-party provider and aren't stored.
Re: GDPR compliance as a service
#37Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?
As an EU citizen, "cheap" wourkarounds like these ones will definitely not solve the problem, might actually make it worse.It's like an anti-adblocker, it won't work on the long run,people who are tech literate enough will just start using a VPN
Re: GDPR compliance as a service
#38Maybe I'm missing something - but as a US citizen, with a US company, how can EU laws be enforced against me? What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?
However, a lot of it is covered by:
1- US companies with a physical presence in the EU. They can fine that entity directly.
2- US companies will find they can't sell to EU businesses (B2B), as that means the EU company is carrying the can in terms of non-compliance.
3- The EU Member State could go via the International Courts. Or via some kind of bilateral agreement (e.g. Privacy Shield).
I expect #3 will need to egregious to really make sense.
However, I also expect a significant amount is already hovered up by #1 or #2. Certainly many of the cases that GDPR wants to target.
Additionally, the EU may cut deals with other states to bring in enforcement powers (fines).
Re: GDPR compliance as a service
#39Earlier quoted context omitted.
The most likely solution is the same way the US enforces US laws (e.g. Megaupload case) in other countries: Seizing their assets (through cooperation with banks) and then asking for extradition.
Frightening to think something as innoculus as making a website of chocolate chip recipes and logging visitor IPs could provoke that.
Re: GDPR compliance as a service
#40I can't tell if this is a joke or not. Don't pay "thousands" for GPDR compliance work which will improve your product by providing basic privacy and security features. Instead pay up to $79 a month for a service to block a large percentage of your traffic.
If you get a quote from an experienced data protection lawyer for GDPR compliance, this will be an order of magnitude cheaper in the long run. There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy.