Earlier quoted context omitted.
I can't think of any web server that doesn't log ip addresses by default, and I think it's been established that satisfies the GDPR threshold test for personal data. So while what you say is true, I think you're being a little bit deceptive when you say 'As long as you're just "responding to HTTP requests"' because all practical and established means of doing that violate the GDPR by default.
So hash the IP before you log. Now it cant be traced to a user and you are GDPR compliant. Its really not that hard.
GDPR for lazy people: Block all European users with Cloudflare Workers
391–400 of 1001 posts
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#392Earlier quoted context omitted.
I can't think of any web server that doesn't log ip addresses by default, and I think it's been established that satisfies the GDPR threshold test for personal data. So while what you say is true, I think you're being a little bit deceptive when you say 'As long as you're just "responding to HTTP requests"' because all practical and established means of doing that violate the GDPR by default.
So hash the IP before you log. Now it cant be traced to a user and you are GDPR compliant. Its really not that hard.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#393I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.
This makes it difficult, if not impossible, to find links to living individuals. A ton of people have done a ton of work to build a shared public tree, and some 50-100 years of it are getting chopped off the bottom.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#394Earlier quoted context omitted.
nah the law doesn't mention citizenship. it applies for "every user In the Union" and for all companies in the union.
So much this. So many people conflate citizenship and residency, and it leads to no end of confusion. GDPR applies to EU residents, accessing services from the EU, and some more edge cases. But not to EU citizens. (There are countries with up to 30% non-citizens, and there are plenty of multi citizens. The distinction is entirely relevant.)
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#395Earlier quoted context omitted.
There are plenty more examples of the US twisting Europe's arm. Currently it's looking like that is the plan for Iran.
I hope not. They really need to tell the US to go to hell on that front. Pissing away a deal that is seemingly working because Trump got made fun of by Obama.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#396Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#397I simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going…
I'm wondering this too actually, I run a small business, we collect only the bare minimum of information from our customers but we do have some European customers. I'm ignoring GDPR completely, is there any downside for me? Will they block customers from using my service? Will they sieze my European cloud servers? Or can I safely do nothing as I currently am because I don't reside or have a registered business in Eur…
People get used to accepting the stupid cookie law and it becomes a habit, and in a couple of years the law lost it's meaning (people blindly accept cookie law) and no-one cares about "the great privacy laws of the EU".
This is probably how GDPR will end up, no sane person would have the time to read all the privacy notices and the crappy opt-ins to just order food as fast as possible.
Hey I'm starving I need that food ordered now, here's my location so you can deliver food here, I don't give a rat's ass about your privacy statement and clickady clack are there any more opt-ins to check before I can finally order my food?
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#398Keep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#399Earlier quoted context omitted.
You have two solution: 1: ignore GDPR, you'll probably fly under. And if you dont, fine are scaled for business and people affected, as well as privacy infraction. Encrypt your backups, encrypt PII if you can do it effortlessly, and you're good. If you are not using emails except for checking double inscription, encrypt them too, the entropy is low BUT this is better than nothing . 2: If you have some time and money…
Is there some way they can fine me with me being in a country completely and totally unrelated to the EU?
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#400Earlier quoted context omitted.
You’re going to get downvoted for that comment, but you do raise a legitimate question of enforceability. Sure the EU can say any company in the world who has EU residents’ data should comply with GDPR. But... or what exactly? The EU doesn’t have the power to fine companies outside of their jurisdiction. I mean, they can try. But as far as I know there is no enforceability to ensure that the company actually pays the…
Corporate counsel, who actually went to many of the lead-up conferences for GDPR, said the data authorities from many member countries didn’t even hesitate before saying they would file civil lawsuits against non-EU companies. Such a suit could be ignored too, but it would certainly be a PITA for vacationing executives who get locked up in Italy for an outstanding summary judgement.
It's a good thing there are a lot of beautiful parts of the world other than Italy.