Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

481–490 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#481
post #429

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information int…

If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data, and build a system to get user consent, etc. I can easily see small websites just ignoring GDPR and hoping they fly under the radar. Or, using something like this Cloudflare configuration to block all EU users until they reach a size…

> If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data

No, because that website doesn’t collect personal information.

> and build a system to get user consent, etc.

You need user consent to send emails or do something with their personal information (i.e. nothing since you don’t hold that information).

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#482
post #429

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information int…

If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data, and build a system to get user consent, etc. I can easily see small websites just ignoring GDPR and hoping they fly under the radar. Or, using something like this Cloudflare configuration to block all EU users until they reach a size…

> they have to have a data protection officer

DPO is only needed in specific cases. Dank meme sites don't fit in any of: a) public authority b) monitoring subjects on large scale c) dealing with criminal conviction data.

> build a system to get user consent

It's called a checkbox. They likely use one to agree to TOS anyway. If you don't have that one, DMCA and COPA is what you should be worried about before GDPR. (If you're based on the US anyway)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#483

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#484

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> Most early-stage startup use the best practice of “delete=1”

Honestly that's a bad best practice if the data your collecting is sensitive, which PII is.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#485
post #481

Earlier quoted context omitted.

If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data, and build a system to get user consent, etc. I can easily see small websites just ignoring GDPR and hoping they fly under the radar. Or, using something like this Cloudflare configuration to block all EU users until they reach a size…

> If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data No, because that website doesn’t collect personal information. > and build a system to get user consent, etc. You need user consent to send emails or do something with their personal information (i.e. nothing since you don’t hold th…

> No, because that website doesn’t collect personal information.

Yes it does. It a least records an email address and password to create profiles. And any features like tagging memes, marking memes as favorites, etc. could be argued to constitue personal data.

> You need user consent to send emails or do something with their personal information (i.e. nothing since you don’t hold that information).

Again, I specified a meme generator site that has at least some user specific personalization.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#486
post #375

Earlier quoted context omitted.

> ban on EU IPs is both draconic and ineffective It doesn't matter it's ineffective. The block means they're complying with GDPR's requirement that they not target Europeans.

But they still process European user data if they do not block my IP. So they are not complying at all with GDPR's main requirement, just a poorly singled-out subclause.

Do EU laws protect you in China? I feel, partially, that going through a proxy means you are more under the discretion of the laws of the country with which the last proxy is operating under. Do you disagree? It's all very confusing

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#487
post #461

Earlier quoted context omitted.

1. when you open a restaurant nobody cares you're a collage student. You have to have all the checks and permits to serve people food. It's not because somebody hates small businesses, it's because the right not to be poisoned is more important than the right to do business hassle-free. Why should internet be different? 2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency world…

Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.

Most of the time there will be no poisoning. Most of the time they will only collect e-mail address.

The law is designed to cover pessimistic case. You can get sick because of food poisoning, you can be robbed because your identity was stolen.

I don't think my comparison was dishonest.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#488
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

You are speaking as if the European Union spit out this legal document and nothing else, when in fact loads of supplementary material have been released, for consumers as well as for enterprises. Of course, the actual act must be written in formal legal language.

EDIT: Example: https://ec.europa.eu/justice/smedataprotect/index_en.htm

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#489
post #461

Earlier quoted context omitted.

1. when you open a restaurant nobody cares you're a collage student. You have to have all the checks and permits to serve people food. It's not because somebody hates small businesses, it's because the right not to be poisoned is more important than the right to do business hassle-free. Why should internet be different? 2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency world…

Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.

> Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.

Nobody’s saying both are treated equally under the GDPR. The law stays the same, the way it’s enforced is adapted to the case, like any juridiction. Whatever the situation, you always get a warning before being fined.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#490
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> 1) A College student working on a side project with no revenue are treated the same as some massive multi-national.

I hear you, but the argument is that the data doesn't care who caused the leak. A college side project leaking an SSN does the same amount of damage as a multinational leaking an SSN, so the law is going to want them to treat them equally seriously.

Post reply on HN