Live data from Hacker News

GDPR compliance as a service

gdpr-shield.io

51–60 of 158 posts

Re: GDPR compliance as a service

#51
post #35
post #33

Earlier quoted context omitted.

Not a joke :). GDPR Shield as a product is GDPR compliant. Customers sign a data processor agreement with the service. It anonymizes IP addresses, they aren't transferred to any other third-party provider and aren't stored.

But like I mentioned on Indie Hackers, your customers still have their own logs that need to be GDPR-compliant, which defeats the whole purpose. The page that requests your JS still has to be sent by a server, which will likely log the EU citizen’s IP. And then there’s the case where the EU citizen is using a VPN server in the US...

Maybe, but it's clear that your company doesn't specifically target its services at individuals in the EU. Your company is actually using active measure to not do that.

Re: GDPR compliance as a service

#52
post #41

I have this eerie suspicion that GDPR cases will be a haven for trollish and/or opportunist behavior. Instead of huge corporations having to shell out significant money to swallow up start-up competitors, they could much more cheaply pay EU citizens to exploit the huge burden of the law on small companies or even solo endeavors. I hope I can be convinced to be optimistic.

Yes I remember reading about this thought here: https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/

Re: GDPR compliance as a service

#53

lol fqdn registered on 2018-04-24? gmafb

here:

Domain Name: GDPR-SHIELD.IO Registry Domain ID: D503300000096633167-LRMS Registrar WHOIS Server: Registrar URL: https://www.gandi.net/whois Updated Date: 2018-04-24T15:25:22Z Creation Date: 2018-04-24T15:25:19Z Registry Expiry Date: 2019-04-24T15:25:19Z Registrar Registration Expiration Date: Registrar: Gandi SAS Registrar IANA ID: 81 Registrar Abuse Contact Email: abuse@support.gandi.net Registrar Abuse Contact Phone: +33.170377661 Reseller: Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited Registrant Name: Nikolaus Fischer Registrant Organization: InnoWire UG (haftungsbeschrankt) Name Server: NS-86-B.GANDI.NET Name Server: NS-78-C.GANDI.NET Name Server: NS-61-A.GANDI.NET DNSSEC: unsigned URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/ >>> Last update of WHOIS database: 2018-05-04T01:38:30Z For more information on Whois status codes, please visit https://icann.org/epp

×××@@@@xxx The value for the Created field will show domain age. No serious offering was erected 1 month before open season begins. lmao.

Re: GDPR compliance as a service

#54

The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD. Directly from the EU: > Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ( https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

How a company "specifically targets its services at individuals in the EU" is not clearly defined within GDPR. Even if you just set your AdWords targeting to 'global', it might be enough to trigger this. GDPR Shield is a clear signal that you're not targeting EU users.

Re: GDPR compliance as a service

#56

> Simply paste our JavaScript snippet into your website's code. We'll check every visitor of your site and will block access to users located within the EU. See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have…

Check the terms and conditions. Their commitment to paying a portion of your legal fees if you’re sued is proof enough of their confidence.

Re: GDPR compliance as a service

#57

The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD. Directly from the EU: > Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ( https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

This is what you're trying to reference: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Re: GDPR compliance as a service

#59
post #33

Earlier quoted context omitted.

Not a joke :). GDPR Shield as a product is GDPR compliant. Customers sign a data processor agreement with the service. It anonymizes IP addresses, they aren't transferred to any other third-party provider and aren't stored.

But if your JavaScript is inserted into your customers site, then the initial request that loads their site the first time + your script will be logged on their servers just like any other HTTP request.

And if your site loads their Javascript to block anyone from the EU from visiting, then it's clear that you're not targeting customers in the EU.

Re: GDPR compliance as a service

#60

Earlier quoted context omitted.

If an EU citizen believes that their personally identifiable information was obtained without their consent, the EU GDPR allows firms to do an audit on the company. The citizen who filed the complaint would enlist help from a no-win-no-fee legal firm, meaning, if they don't win (with infractions being $10 million minimum), the citizen, who is now a client of the firm, would not be out any money. If they do win, most…

Wait! I was under the impression that fines due to GDPR are just that, fines. They are paid to the government, not individuals. At most, getting fined due to non-compliance can suggest that if individuals bring civil lawsuits against the company, they may win and be awarded damages, the amount of which depends on how much damages they can prove they have incurred as a result of misuse of their data, not statutory amo…

Yes, your understanding is completely correct. Only EU member states can levy fines under the GDPR, and it's likely few will have any interest in trying to fine small businesses. Lawsuits are possible, but only for damages, and good luck showing any damages from a minor technical violation by a small SaaS tool. And without any prospect of large damages from a deep-pocketed defendant, good luck finding a law firm willing to work on contingency.

The whole thing is FUD, although mad props to the people behind the linked service for making a play at profiting from it.

Post reply on HN