Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

361–370 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#361
post #192

Earlier quoted context omitted.

As a developer I can understand this point of view, but as a consumer I say it's time to grow up. Internet startups have taken a "move fast and break things" approach that is analogous to early industrial revolution approaches to worker safety, product efficacy and safety, and environmental protection. You're working in the real world, with real consequences if you end up exposing people's personal data. The party is…

I feel that you're ignoring the situation of small startups with just a few founders. At this stage, it can really kill your business to spend a lot of your resources on making sure you're complying with GDPR. Usually the 'consumer' of those startups are OK to take some risk, heck a lot might even sign up with dummy emails. The Poland proposal [1] to limit GDPR compliance to only large businesses was trying to addres…

I feel like starting from scratch GDPR really isn't that hard to handle.

If your business is based around exploiting user data however it might be a lot harder, but then that's the point of GDPR, to prevent people exploiting user data.

GDPR exists because it turns out we can't trust companies to handle personal data with the care it deserves, and I don't see why any company should be excused that proper care.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#362

Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that). A more effective way might be to ask on page load if the user is an EU citizen. You know, like some financial website askin…

> I thought GDPR was applicable for all EU citizens regardless of where they physically are. Do you mean a company and its customer, both located outside the European union, would still fall under this law if the customer happens to be a citizen of a EU country?

That's how some US tax/banking codes already work, so it's not without precedent. I don't remember exactly what it's called. But allegedly it's a hassle for everyone involved, both banks and customers.

Ah, found it: "... is the Foreign Account Tax Compliance Act (FATCA), which was passed in 2010 and will go into effect in January of 2013. The act requires all foreign banks to identify and report on US citizens with accounts holding more than $50,000 in an effort to clamp down on tax evasion. If banks refuse to comply, they could face a punitive 30 percent withholding tax on all payments from the US."

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#363
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

> Is the EU going to target American banks of American businesses and try to extract fines? You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely. > Is the EU going to extradite owners of these businesses? Extremely unlikely, besides that would require the cooperation of the other c…

That makes me wonder: what about wechat? Surely Tencent has many overseas Chinese users in Europe, and I’m sure they play as or more aggressively as the American majors. Is Europe going to sanction Chinese companies for violations along with American ones?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#364
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

That's because GDPR is regulating and fining without representation to non-Europeans. Blocking Europeans is a defensive measure.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#365
post #288

Earlier quoted context omitted.

There are plenty more examples of the US twisting Europe's arm. Currently it's looking like that is the plan for Iran.

I hope not. They really need to tell the US to go to hell on that front. Pissing away a deal that is seemingly working because Trump got made fun of by Obama.

> They really need to tell the US to go to hell on that front.

Would be easier if Europe had a coherent voice. You got the former Eastern Bloc countries desperately clinging to the US (because they, rightfully, fear that Putin will screw them over), you got the UK which is trying to not fall apart due to Brexit, France is... France and Merkel is trying to prevent the worst of the shitshow, even though she's miserably failing at that (and under heavy pressure from the AfD nazis and her own sister party which is openly copying the nazis).

In addition, Europe is so damn far behind the US when it comes to military power - jeez, German army is practicing tank shooters with broomsticks as munition, the NH90 marine helicopters are not allowed to fly over water and we all know what a fuckfest the A400M is. No money, no competence, but it wasn't a problem since WW2 as the USA had always covered the EU... now that Trump is, well, being Trump the EU has yet another giant problem to tackle.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#366
post #344
post #141

Earlier quoted context omitted.

As long as you're just "responding to HTTP requests", there's nothing to worry about and the GDPR does not apply. It's when you start collecting personal data on EU residents, send their personal data to third parties for analytics/targeted advertising, and so on, that things get interesting.

I can't think of any web server that doesn't log ip addresses by default, and I think it's been established that satisfies the GDPR threshold test for personal data. So while what you say is true, I think you're being a little bit deceptive when you say 'As long as you're just "responding to HTTP requests"' because all practical and established means of doing that violate the GDPR by default.

So hash the IP before you log. Now it cant be traced to a user and you are GDPR compliant. Its really not that hard.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#367

Earlier quoted context omitted.

Consider this case, startup app in a niche market, only available on US app stores, and a one man dev team that needs to focus on app dev not compliance for some regulation that could never apply to their customers. Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list. That’s the startup I’m presently working on. We’ll expand beyond the US borders…

An admirable effort, but all the fans of this law seem to hear is "You're not 100% compliant with the GDPR? You're scummy and shady and don't care about my privacy. I hope you fail immediately because the world is better off without you." Meanwhile they'll be using VPNs to access your site anyway :)

This is interesting, an EU Activist thinks they can twist Facebook's and Google's arms into providing free service: (again, I'm not a fan of FB/Google invasive data mining driven advertising)

http://www.bbc.com/news/technology-44252327

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#368
post #135
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

Read up on FATCA ( https://en.m.wikipedia.org/wiki/Foreign_Account_Tax_Complian... ) before you argue further down that path. The US already has extraterritorial laws that have to be enforced by banks worldwide that don’t operate in the US.

FACTA is why banks refuse US citizen or PR customers.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#370
post #141
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

As long as you're just "responding to HTTP requests", there's nothing to worry about and the GDPR does not apply. It's when you start collecting personal data on EU residents, send their personal data to third parties for analytics/targeted advertising, and so on, that things get interesting.

My understanding was that an IP address is considered personal information under GDPR, which would put it in your class #2
Post reply on HN