Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

421–430 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#422
post #387

Earlier quoted context omitted.

> It's a foreign requirement that feels like a violation of sovereignty. Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws. EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local…

What does it mean for a website to "cater" to just my home country? The internet doesn't know political boundaries and most sites cater to all visitors on some marginal level.

Most websites are products nowadays. If you have a simple blog without trackers and ads this is really not going to effect you that much.

> The internet doesn't know political boundaries

Tell that to this US law the whole world has to comply with to called DMCA.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#423
post #374

Earlier quoted context omitted.

I do care about privacy - I don't use Analytics on my website, don't show any ads, don't send marketing emails and don't sell customer data to anyone. However, I will not comply with that bureaucratic law, because the EU will not be able to enforce it in my country and I have much more important things to do to stay competitive on the market (I have a lot of competitors).

Do you send user data anywhere in a way users may not expect? If not there's probably nothing to comply with. It's really the opposite of bureaucratic law — the entire thing is quite readable and reasonable.

Its going to become cookie law v2 with more annoying opt-ins

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#424

Earlier quoted context omitted.

> Is the EU going to target American banks of American businesses and try to extract fines? You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely. > Is the EU going to extradite owners of these businesses? Extremely unlikely, besides that would require the cooperation of the other c…

> You mean like America? Yes, like America. This may shock you, but America isn't always right.

Exactly. It's possible to criticise what the EU are doing without thinking the United States does everything right - or even that it does it better.

Disappointing to see so many EU apologists defaulting to whataboutism.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#425
I think there are a number of comments being made throughout this whole thread that are conflating the effort required to comply with the best security practices to protect user data, compared to the effort required to comply with the language of GDPR. A general theme seems to be that if a company is afraid to do the latter, they must not be willing to do the former.

Which brings up a question, is the complexity of building and offering a GDPR-compliant solution really any different than building a solution that conforms to best security practices? I wouldn't think there is much difference. What is the remaining overhead to comply with GDPR? I am sure just understanding it is a notable piece, but would the developers already be aware of all CWEs, BCPs, existing laws and standards for their components which would also be overhead?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#426
post #414

There's one very important problem with this approach: this blocks people from accessing your site who are doing so from the EU, whereas the GDPR applies to EU citizens , wherever they access the Internet from. In other words, an EU citizen residing in and accessing the Internet from the US has just as much right to invoke the GDPR with these sites as an EU citizen residing in and accessing the Internet from the EU.…

Do EU laws still apply when a person has physically left EU jurisdiction? I doubt it. After all, every egg sold in the US would be in violation of EU food safety laws (and vice versa).

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#427
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> It's a foreign requirement that feels like a violation of sovereignty.

It must feel horrible, now that the US is on the receiving end of this for a change... ;)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#428
post #301

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. And why not? The result/harm is the same. It doesn't matter a bit whether a company's web site is handing its visitors' data over to Facebook or a "private site" does. The side project or the private site always have the option of not participating in the adtech frenzy. But of course they want to partici…

It's not the same. There're companies which intentionally collect and exploit private data. There're companies which are just behaving negligently with users data. There should be different penalty for intentional and negligent violation.

And there is! The law applies to all but fines/punishment are handled on a case by case basis.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#429
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> A College student working on a side project with no revenue are treated the same as some massive multi-national.

Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR.

If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information into that.

The treatment of privacy is one of issues where it's pretty much impossible for individual protect from, GDPR tilts the scale in favor of individuals.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#430
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

It's certainly a hindrance. I can't look at core dumps from code running in Europe now. It's a mess.
Post reply on HN