Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

331–340 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#331
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

Do they have any opportunity now that they haven't always had?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#332

Earlier quoted context omitted.

Jacques - I love the effort you've put into explaining the GDPR to clueless and needlessly exasperated (mostly) americans here on HN. To be honest I used to think you were just a shameless self-promoter like almost everyone else, but in this case you've risen to the occasion. Bravo. I think you're now rating quite high in most people's "mental books of good people". Or at the very least, in the minds of people who ac…

>clueless and needlessly exasperated (mostly) americans I'd love to see the dataset you have access to backing up any of that statement. It must be fascinating.

> I'd love to see the dataset you have access to backing up any of that statement.

That would make you a sub-processor.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#333
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

I'm wondering this too actually, I run a small business, we collect only the bare minimum of information from our customers but we do have some European customers. I'm ignoring GDPR completely, is there any downside for me? Will they block customers from using my service? Will they sieze my European cloud servers? Or can I safely do nothing as I currently am because I don't reside or have a registered business in Eur…

You're probably fine.

If you have a lawful basis for collecting the information, you're only passing it along to others as necessary to provide your service to your customers, the customers have clearly consented, and you employ reasonable protection of that data... it's extremely unlikely that you're in violation.

And if you were, they'd come to you first with a warning (at least based on past behavior). They're not going to seize assets unless you seriously provoke them.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#334
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

The fact that the regulation is so vague around it in the first place is the whole problem. There are dozens of conflicting statements (from law firms, no less) about what exactly exposes you to GDPR.

You should be glad that it's so vague. The alternative is a law that lays out technical details of how you handle information, and no one wants that.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#335

Earlier quoted context omitted.

Isn't this pretty much what happened with the cookie law? It states that cookies necessary for the functioning of sites were ok, but everyone ended up putting up those warnings anyways and it greatly diluted any benefit of the rule and it ended up like Prop 65: warnings everywhere, even when they weren't useful. Overall, it just led to the law being ridiculed.

Wait what? Really? All the annoying "cookie" popups I've seen were them telling me the cookies were used for necessary function. I always thought it was due to some European law. Are you telling me it's not even required by the law?

What no one want to do was read the law. I actually had to do that, and how you dealt with it depended on your mindset. It was pretty clear that you could just disable all tracking and you'd be fine. If you wanted to use 3rd party tracking, using cookies, you'd need consent.

Because people wouldn't give up Google Analytics, targetted ads and "re-targetting" they opted of silly pop-ups, often delivered by a 3rd. party that will scan your site to keep track of all the data collectors your marketing department added without considering the users privacy.

The GDPR is written the way it is because companies refuse to accept the intentions of the cookie law, and choose to look for loopholes. At least that's my take.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#336
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

> Is the EU going to target American banks of American businesses and try to extract fines? You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely. > Is the EU going to extradite owners of these businesses? Extremely unlikely, besides that would require the cooperation of the other c…

> You mean like America?

I get the impression that a big part of the motivation for GDPR is this type of resentment against America.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#337
post #328

Earlier quoted context omitted.

No, it's not the same. The lack of proportionality is precisely why the UK/EU is such a hard place to conduct business. These rules don't stop anything about ads, they just make them less targeted. Not a big deal, but it will increase the costs of serving users and thus decrease the total amount of commercial projects started.

I find it funny to claim that the US could be more proportionate than the EU. Less targeted ads are exactly what we need. That's what the regulation aims for! Your argument is like claiming that unfortunately, due to car dafety regulations, we cannot enjoy as many fatal accidents as we once did. And to make my point of view clear: not all businesses deserve to exist. We as society decide which business models and beh…

This issue isnt about privacy...

Nobody reasonable is arguing that it's a bad idea to let customers control their data. The actual issue is that the rules are vague and thus create a lot of confusion and waste that affects all companies, while not providing any real protection against the massive conglomerates that abuse data in the first place.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#338

Earlier quoted context omitted.

Wait what? Really? All the annoying "cookie" popups I've seen were them telling me the cookies were used for necessary function. I always thought it was due to some European law. Are you telling me it's not even required by the law?

Correct. The “necessary” function was that the website and advertisers wanted to track you all over the web. Login cookies and the like don’t require notices so if you see a notice it was because they wanted to track you.

I didn't even know that - thank you :)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#339

Earlier quoted context omitted.

It's not about privacy, its about poorly written regulation that leaves too much vagueness because its based on principles rather than hard rules. Good intentions are not enough, there must be clear paths to implementation and verification. Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it. It will also do just about nothing in regards to the major companie…

As a French guy, these type of comments make me smile. The GDPR is basically just the implementation of the French law "Informatique et Liberté" into the European Level. (You can read on HN many Germans saying that it's actually the implementation of the Datenschutzgesetzt. The truth is: these two laws are extremely similar.) This law has been in application since 1978 [1]. And in 2018, we have adtech companies like…

Yes, none of this is new or surprising.

The irony here is that American users are so used to being endlessly surveiled without consequence that they are genuinely shocked that the rest of the world refuses to put up with this bullshit. This is completely normal to them.

The GDPR is just another step in a global fight by people all over the world to regain their data sovereignty and protect themselves from endless surveillance. The momentum at the international level is very clearly for data sovereignty. Russia and many Asian countries are following closely behind. And while everybody was freaking out about the GDPR nobody seemed to notice that China passed even stricter online privacy laws [1] earlier this month. Singapore [3] and Malaysia [4] are up to speed and even Thailand [2] will likely soon require minimum standards. (Edited to add more links.)

The end result is like so many other things: American companies will end up blocking everybody but American users who they know they can exploit without consequence. American users will celebrate their exploitation as freedom from Big Government. Everybody else will move on and just shake their heads.

[1] https://www.csis.org/analysis/new-china-data-privacy-standar...

[2] https://www.bangkokpost.com/business/news/1455534/new-data-l...

[3] https://www.pdpc.gov.sg/Legislation-and-Guidelines/Personal-...

[4] https://www.hg.org/article.asp?id=33273

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#340

Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that). A more effective way might be to ask on page load if the user is an EU citizen. You know, like some financial website askin…

> Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that).

I believe you have that the wrong way round. The territorial scope (as it applies to processors outside the EU) is defined as "processing of personal data of data subjects who are in the Union".

https://gdpr-info.eu/art-3-gdpr/

Post reply on HN