Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

321–330 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#321
Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that).

A more effective way might be to ask on page load if the user is an EU citizen. You know, like some financial website asking you if you are a US citizen on page load [0] (i remember marshall wace's old website doing it, it looks like they do not anymore).

And EU traffic being the "most malicious" ? Is this satire, irony, or something else ? Seriously, if I go on website W and they go through all the dark patterns possible to collect and share my data without me knowing about it and I'm the malicious one ? Better read that than being blind...

[0] https://www.quora.com/All-of-a-sudden-Bank-of-America-is-ask...

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#322
post #219

Earlier quoted context omitted.

Why? Bad press often makes for great business. Not parent commenter btw, just my two cents

Because when the EU catches on, they will have funds in the EU (including customer or advertiser payments) seized, they will probably not be able to travel to the EU without fear of arrest, etc.

>hey will probably not be able to travel to the EU without fear of arrest, etc

This is EU, not USA, Russia or China. At most his visa will be denied (and i'm not even sure immigration services will actually care)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#323
Assuming, and this is a big assumption, you can cookie (CDN level) or otherwise leave an indication client-side that the visitor is from the EU, then you can easily make the page GDPR compliant instead of blocking.

https://github.com/donohoe/simple-gdpr-lockdown/

This does NOT solve the problem, its just (IMHO) a better alternative to blocking.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#324
Even though this post is sarcastic, people forgot that your EU resident could still access you when in vacation or business trip outside of the EU and that they certainly already have plenty of data store fom EU resident, so blocking all european IPs does nothing to help them being compliant.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#325
post #307

Earlier quoted context omitted.

> really trying to annoy us users with GDPR updates Isn't that the law that required these updates, pop ups, and new consent forms? Not sure how the companies could be blamed for that.

No: the law wants you to not have to do this. The law wants you to stop collecting data for things that are not core to your business. The issue is that companies are trying to maintain the status quo as much as possible, and annoying users with these does that.

Personalized, targeted advertising is how many services make money. So what is meant by 'the law wants you to not have to do this'. The law wants these services to not make money to cover their expenses? Or scale back their operations?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#326

Even though this post is sarcastic, people forgot that your EU resident could still access you when in vacation or business trip outside of the EU and that they certainly already have plenty of data store fom EU resident, so blocking all european IPs does nothing to help them being compliant.

Just add to your terms and conditions - not available for EU residents.

Yeah you changed your EULA, but at least you don't need to completely review it for compliance.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#327
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> It's a foreign requirement that feels like a violation of sovereignty.

Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws.

EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local companies were forced to respect privacy. Respecting privacy is just not very competitive/profitable at the moment.

Your viewpoint pushed to the extreme (sorry if you don't recognize your original view): China selling counterfeit goods or unsafe toys to the US, and feeling like any push-back is messing with their sovereignty of lax copyright -, trademark -, and health laws.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#328
post #301

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. And why not? The result/harm is the same. It doesn't matter a bit whether a company's web site is handing its visitors' data over to Facebook or a "private site" does. The side project or the private site always have the option of not participating in the adtech frenzy. But of course they want to partici…

No, it's not the same. The lack of proportionality is precisely why the UK/EU is such a hard place to conduct business. These rules don't stop anything about ads, they just make them less targeted. Not a big deal, but it will increase the costs of serving users and thus decrease the total amount of commercial projects started.

I find it funny to claim that the US could be more proportionate than the EU.

Less targeted ads are exactly what we need. That's what the regulation aims for!

Your argument is like claiming that unfortunately, due to car dafety regulations, we cannot enjoy as many fatal accidents as we once did.

And to make my point of view clear: not all businesses deserve to exist. We as society decide which business models and behaviours are okay. "Decrease the total amount of commercial businesses started" cannot ever be a persuasive argument.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#329

Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that). A more effective way might be to ask on page load if the user is an EU citizen. You know, like some financial website askin…

> I thought GDPR was applicable for all EU citizens regardless of where they physically are.

Do you mean a company and its customer, both located outside the European union, would still fall under this law if the customer happens to be a citizen of a EU country?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#330

Earlier quoted context omitted.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

As a French guy, these type of comments make me smile. The GDPR is basically just the implementation of the French law "Informatique et Liberté" into the European Level. (You can read on HN many Germans saying that it's actually the implementation of the Datenschutzgesetzt. The truth is: these two laws are extremely similar.) This law has been in application since 1978 [1]. And in 2018, we have adtech companies like…

I looked up information on how to legally comply with GDPR and it's a lot more complicated than you're making it out to be. You have to show regulators the well-defined pipeline for any personal data, and justify to them why that data is being collected.

There are also extra procedures you have to follow that could be really complicated depending on the business. This is even worse for small businesses. I can definitely understand those people who want to just wash their hands of it, especially if they don't get much business from Europe.

Post reply on HN