Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

331–340 of 349 posts

Re: Shopify Is Illegal in Germany

#331

Earlier quoted context omitted.

How is GDPR ugly? It's easy to build websites, even interactive ones, that comply. If you build a mobile app, you are also supposed to only ask for permissions once you actually need them. Replace interactive embeds with a dumb replacement of the actual content and e.g., "we want to show you an embedded tweet here, [allow once] [allow always]". Don't use CDNs for delivering assets, they've long stopped being useful a…

> Don't use CDNs for delivering assets, they've long stopped being useful anyway. How do you handle large DDOS? Your provider won't, they'll nullroute your IP because they don't want to waste their bandwidth on your issues and impact all their other customers. Also, using a global CDN with edge caching speeds up loading your site significantly if the user isn't close to the DC. Regarding Hetzner: what's the verdict o…

Of course my provider will handle large DDoSes, as long as they're not hundreds of Gbps large. In which case there's not much anyone can do, frankly.

Regarding edge caching speed: we're in an age where your phone executing the shitty bloated JS is the bottleneck, not actual latency.

Re: Shopify Is Illegal in Germany

#332

Earlier quoted context omitted.

> the web being worse is not caused by the law being bad. It’s caused by it being badly enforced Because that's the truth > The fact is that the cookie pop ups would never be necessary if the GDPR hadn’t been passed. Show me exactly where GDPR mandates the use of cookie pop ups. (Hint: GDPR mandates: "ask the user for consent if you collect more data than is strictly necessary, and the opt-out must be as simple as op…

> Because that's the truth So the EU isn’t inept because they made a bad law. They are inept because they have no clue how to enforce it? > GDPR mandates: "ask the user for consent if you collect more data than is strictly necessary, and the opt-out must be as simple as opt-in". So the websites are asking the user - as the law dictates even if the buttons are the same size. > AppStore rule on tracking was more effect…

> So the EU isn’t inept because they made a bad law. They are inept because they have no clue how to enforce it?

The law isn't bad. The EU knows how to enforce it.

> So the websites are asking the user - as the law dictates even if the buttons are the same size.

No.

1. The sites are willingly breaking the law in the absiolute vast majority of the cases

2. The sites don't even have to ask any of this if they simply stopped siphoning user data

> So you’re cheering the government making a law that made the user experience worse that the government couldn’t enforce?

It wasn't the law that made the experience worse. Does the law require the sites to siphon and sell your data to the highest bidder? No. The law says: if you do that, you have to tell the users about that, and obtain their consent before doing that. It's the industry of greedy leeches which made the experience worse. And you've bought into this industry's reasoning that it's the law that makes them do this.

Re: Shopify Is Illegal in Germany

#333
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

> Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

Oh it was. I had this conversation sooo many times. Each time response was: everyone is doing it, we will just wait and see :facepalm:

Re: Shopify Is Illegal in Germany

#334
post #27
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

To clarify: Shopify is a Canadian company (edit: but as mentioned elsewhere in this thread: they send data to CloudFlare, CloudFront (Amazon) and Fastly, which are US companies.)

Luckily for Shopify they are in Ontario, not say, British Columbia. Not whole Canada is GDPR adequate.

https://iapp.org/news/a/schrems-ii-impact-on-data-flows-with...

Re: Shopify Is Illegal in Germany

#335
post #118
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Does it also mean I can't use AWS in Europe?

You cannot use AWS in Europe for processing Personal Data and remain GDPR compliant.

Re: Shopify Is Illegal in Germany

#336
post #31

Earlier quoted context omitted.

If this is required I would think Cloudflare would have some ready agreement for everyone to sign / agree to wouldn't they? This is one of those EU rules where if it is so universal everyone should have thi right? But rather I'm not sure how widespread it is... is anyone doing it or are they all just waiting out the situation?

Cloudflare themselves have a DPA in contract with their customers, however, it's unclear how/if this transfers from Shopify to shop owners. https://www.cloudflare.com/cloudflare-customer-dpa/

And using Cloudflare, which relies on SCCs it also GDPR no-no.

Re: Shopify Is Illegal in Germany

#337
That's why we host everything in the EU, with EU cloud.

Cloud: OVH. CDN: OVH. Email/support: HKN. ... and few other smaller ones.

You do not need AWS/GCP to be successful.

Just shop around. Solutions we picked, ended up being cheaper and friendlier (human support) than US counter parts.

https://wideangle.co/blog/saas-business-without-us-cloud

Re: Shopify Is Illegal in Germany

#339
post #183

Who decides what is legal and what is illegal? The politicians, the courts or agencies like the one that send letter to the author of this article. I would say it is the politicians. By making laws. Since the GDPR is the same in all EU countries, Shopify is either illegal in all EU countries or in none, right?

GDPR is same in whole EU. Ruling about country's specific laws is relegated to local Data Protection Authorities. That's why Facebook was able to get away with Irish DPA from ruling against it. There was even a suggestion of foul play.

In theory, a DPA in your country must make a ruling. That's why Google Analytics is officially "illegal" in certain, but not all EU countries.

That said, it would be weird if subsequent rulings were not in line with previous.

Re: Shopify Is Illegal in Germany

#340
post #250

Earlier quoted context omitted.

Oddly this argument feels familiar - like we've sparred in the past over GDPR on another hacker news article. I won't continue this as it seems like it's more a flame war where no side can convince the other. I'll say this, though: please imagine who I am who feels so passionately about this. Likely, I am a small business that has been affected personally by the GDPR though I am not in advertising or tracking. Maybe…

> Likely, I am a small business that has been affected personally by the GDPR though I am not in advertising or tracking. Maybe I'm just a small business owner trying to navigate the uncertain waters created by these rules. Hey, I was a small business owner and the GDPR was a complete non-issue. The website was hosted by a small service provider in my country. No CDN required (static files, not that much traffic). If…

> No CDN required (static files, not that much traffic).

Shops with actual traffic might need a CDN.

> If you're a small business owner you're either not affected by GDPR, or you're doing something shady.

Well, apparently I can't use Shopify despite having no interest in tracking, ads or any kind of analytics.

Post reply on HN