Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

381–390 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#382
post #198
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

> Nothing has been learned. I don't know about you, but I have learned a great deal! I've mostly learned that Eurocrats can't actually write useful regulation. Blah blah blah human rights blah blah reasonable measures. Next chapter. Blah blah envisage blah blah reasonable measures. Blah blah blah inter-government communications protocols blah blah codes of conduct. What's a reasonable measure? How do I know if I'm co…

Can you think of any good technical regulations that do lay out requirements & obligations in a useful manner without being massively outdated, trivially bypassable, or some sort of hugely onerous 'one size swamps all'?

I mostly agree that the lack of concrete measures makes it horrible from a compliance view, but I'm not sure you can have both things, especially in a relatively immature area of law.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#383
post #336

Earlier quoted context omitted.

> You mean like America? I get the impression that a big part of the motivation for GDPR is this type of resentment against America.

The companies that are most guilty of mishandling personal user data are American companies. If it could not apply to them in protection of EU citizens any regulation would be useless.

Thats because the EU has no tech giants.

If Facebook was german there's no way that GDPR would of passed.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#384

Earlier quoted context omitted.

Playing Devil's advocate, there are 193 countries in the UN; is it reasonable to ask site owners to keep abreast of the Internet laws passed in each one, and spend a couple of days for each, even if you just serve your compatriots? I'm biased for the GDPR, since I think every site should follow its principles regardless of legal obligation, but I don't think the rationale you're proposing is scalable.

Laws are made with physical borders in mind. Digital world doesn't have those borders. But it seems that politicians are expecting those borders to work. I'm not even sure about sane way to map IP address to country. There are some geolocation services, but I doubt that they are 100% precise and probably paid. Also if I'm using geolocation service passing IP of the incoming request, does that mean that I'm already vi…

It should be noted that I'm talking about the previous poster's proposal. The GDPR doesn't demand that; it specifically says that simply being available in the EU does not automatically make it fall under the regulation.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#385

The amount of dishonest conversation in this thread coming from supposed "hackers" is extremely aggravating. These laws have existed in various forms across several European countries for a few decades. It's now a standard across all of the EU. This is to say, that these have been tried, tested, found to be functional and useful; these regulations now have proper surface area coverage. This is good for both companies…

[deleted]

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#386

Earlier quoted context omitted.

Yes, this is the way the law, prosecution and judgement works. If you violate GDPR and the EU prosecutes you and you don't even show up to court and there is judgement against you and you are fined, the EU can try to get paid from your bank. That's how law, prosecution and judgement work in America too. How else would it work? Why would anyone obey any regulation or ever show up to court otherwise? That being said, t…

Playing Devil's advocate, there are 193 countries in the UN; is it reasonable to ask site owners to keep abreast of the Internet laws passed in each one, and spend a couple of days for each, even if you just serve your compatriots? I'm biased for the GDPR, since I think every site should follow its principles regardless of legal obligation, but I don't think the rationale you're proposing is scalable.

Hello mere mortals,

Its your favorite dictator, the leader of Crazystan and from 29th of May 2018 I ask that from that date, for every site accessed by citizens of my country I require the hosting company to send one employee to be sacrificed to our mighty gods.

Failure to comply will attract a fine of 50 Gazillion dollars.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#387
post #244

Earlier quoted context omitted.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> It's a foreign requirement that feels like a violation of sovereignty. Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws. EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local…

What does it mean for a website to "cater" to just my home country? The internet doesn't know political boundaries and most sites cater to all visitors on some marginal level.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#388
post #197

Earlier quoted context omitted.

And yet, multiple companies that do all kinds of crazy things with your data ( https://www.google.com/search?q=gdpr+shutdown ) have shut down already as a result of GDPR. You could argue that wasn't the goal but I'm pretty sure it was part of it and seems to be effective in that way at least.

Like what exactly? The vast majority of them don't do anything that crazy other than storing an email or running some ads on the site, which is completely insignificant compared to the detailed profiles that Facebook and Google have and will continue to maintain. And it doesn't even touch the ISPs, credit unions, medical companies or other deep databanks. Right now there are billions of people around the world clicki…

> Meanwhile there are also plenty of people creating havoc by filing lawsuits against every company they can, adding up to billions demanded on just the first day.

No, the EU is not the US, no lawsuits have been filed. Some individuals have reported some companies to their local data protection agencies, just like the GDPR says you should. No money has been "added up to billions", because the DPAs don't sue for damages, the levy fines to ensure compliance.

Huge difference. If you're going to critique the GDPR, please understand how the legal and regulatory systems of Europe work first.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#389
post #113

I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…

I'm wondering this too actually, I run a small business, we collect only the bare minimum of information from our customers but we do have some European customers. I'm ignoring GDPR completely, is there any downside for me? Will they block customers from using my service? Will they sieze my European cloud servers? Or can I safely do nothing as I currently am because I don't reside or have a registered business in Eur…

"but we do have some european customers"

The entire point is, NO you can't just ignore GDPR. Your lack of action toward compliance is negligent.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#390
post #344
post #141

Earlier quoted context omitted.

As long as you're just "responding to HTTP requests", there's nothing to worry about and the GDPR does not apply. It's when you start collecting personal data on EU residents, send their personal data to third parties for analytics/targeted advertising, and so on, that things get interesting.

I can't think of any web server that doesn't log ip addresses by default, and I think it's been established that satisfies the GDPR threshold test for personal data. So while what you say is true, I think you're being a little bit deceptive when you say 'As long as you're just "responding to HTTP requests"' because all practical and established means of doing that violate the GDPR by default.

If you log for security purposes that is a "legitimate interest" which would allow you to keep doing that, provided:

- You make a note that this data is being logged.

- You state for how long this is logged (6 months is reasonable), and justify that time frame.

- You state who else has access to these logs.

- You state what steps you have taken to try to minimize unauthorized access to these logs.

- In a register (these statements should be delivered on request of a law supervisor) you also provide your personal details, which users are affected by this data processing, and your goal (which should be something along the lines of: "fraud prevention and intrusion mitigation" to have legitimate interest. Expect big companies with law firms to push this "security interest"-angle hard, as they try to justify their data processing).

Pretty reasonable, no? It would be nice if the large web logging softwares provide standard options to automatically limit disclosure of PII web logs.

Post reply on HN