Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

701–710 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#701

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

HN has been overrun by MBAs a long time ago

I'm not sure whether you're agreeing or disagreeing with your parent comment, but I'm just tacking this on there because it feels right:

I think HN has just hit peak stupidity.

The amount of paranoia, misreading, misunderstanding, etc. about the GDPR is just insane (or intentional shilling, but let's not go all tin-foil-hatty prematurely).

Nobody who's doing anything even remotely above-board is panicking or anything of the sort. If you weren't already mostly complying with the GDPR (paperwork notwithstanding) your security practices and/or business practices were sloppy and/or dishonest and/or exploitative to begin with.

EDIT/Addendum: People who are not in the know are (somewhat understandably) a little bit nervous about "interpretation" and such, but there's a reason there's a "sliding scale" of potential penalties. Regulators don't tend to go for people/companies who are actually trying to do the right thing. They go for the people/companies who are the most egregious violators. (I hope I don't have to explain the reasoning behind this, but do ask if you're confused.)

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#702

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

In legal contracts "whereas" often expresses sentiment but it's really the actual terms that matter. Having drafted a number of contracts, I feel most contracts generally have a section that approximates "whereas everyone wants things to go well and everyone to benefit..."

That's great that your company works well with GDPR. I imagine many companies will. I'm also sure that the impact on your backups could have been had without the law if you so chose.

However, an organisation that works inside the UK (EU) serving many EU paying customers (presuming here) is very different from say, Instapaper, who pulled out of the EU today because they don't make very much money from EU customers.

If we pass a regulation that says everyone who is in New York for any amount of time must pass an annual 1 hour health exam (conducted by NY state), I imagine this to be totally acceptable to New Yorkers. It correlates with good public policy: you prevent communicable diseases, and can catch health problem before it gets big. However, if this rule were to be enforced strongly, someone who might stop by once or twice a year probably is better off never coming.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#703

Earlier quoted context omitted.

Tired of the eternal startup excuse to justify bad behaviour when it comes to protection of consumer privacy. If it is impossible for some startups to respect strong privacy practices maybe we simply don't need those startups. This 'startupism' is almost an ideology. No mechanical engineer would complain about safety regulation just because it means that they cannot start a business in their garage. In other industri…

Hey, man, that's totally fine that you don't want those services. Which is why those services are responding by blocking all EU customers. Seems like a win win for everyone. Businesses don't have to deal with ounerous laws, and EU citizens don't get to use those services.

Plus it leaves the market open for other businesses who are actually compliant so they can capture a bigger slice of the market than the existing services. There really is a lot to win.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#704

Earlier quoted context omitted.

Is it? Visit Germany sometime. Drive through the countryside. Most parts of the US look like a hollowed out shell by comparison.

> Drive through the countryside. Most parts of the US look like a hollowed out shell by comparison. In what way do you mean? Wind power?

Small and especially medium business is vaporized.

Textiles? Gone

Light industrial? Gone

Regional banks? Dying

Local banks? Dead

Small retail? Dead

Dairy agriculture? Dying

Family agriculture? Dead

I grew up in a small town. 20 operating farms circa 1990. 2 today. 3 agricultural/equipment dealers, today 0. 5 small/medium manufacturers... 1 today, because of a military contract. School enrollment? -25%.

I watched the beginning of decline when I was in high school. There is no anchor businesses that sustain local economies, and no access to capital. Without government spending, either indirect or direct transfer payments, a shockingly high number of US localities would be in a state of complete implosion.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#705

Earlier quoted context omitted.

> the requirement that you can permanently delete all of your information. Most early-stage startup use the best practice of “delete=1”. What's your system for dealing with COPPA then? You're required to have a way for permanently removing data of children.

COPPA only applies to sites that are directed towards children or have "actual knowledge" that they're collecting data from children. It's legally sufficient to ask for birthdays and refuse signups from anyone under 13.

Can companies do the same here?

“Are you in the EU? Y/N”

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#706

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance.

"We couldn't afford a lawyer and the amount of time for me (the only chef) to go through and read all the regulations and make all the requisite changes in the kitchen I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our restaurant. I say again: at an early stage restaurant with one chef, you cannot have that one chef spending two months on compliance."

Would you eat in a place like that?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#707
Compliance with GDPR for an existing small business might be tricky. But...

I’ve been in the “online payment processing” space for decades. When I first got involved, there were no central guidelines for handling sensitive credit card data. And to be honest, there was a lot of neglect within the industry as a result. As I share memories with my colleagues of what was done in the early days it is laughable and a horror at the same time. We were all learning on our feet.

When PCI was introduced in the mid-early 2000s, it was not easy to undo / redo things to be compliant. It took time and cost money. At the time I wished I was working on features rather than “compliance”. But we got there. It didn’t kill us, and in the end we had a better service because of it.

Fast forward a decade and I found myself working on another startup in the payments space. PCI compliance was in the very fabric from which we started - we designed things from the very beginning with PCI in mind. And that made PCI much easier overall because every decision contemplated PCI.

I feel GDPR will be similar. It will be a transitional burden because existing businesses will have to undo some practices and that is hard. But going forward startups will build services with GDPR in mind from day one, weaving compliance into the fabric of the product piece by piece, and everyone will be better off for it.

I’m sympathetic to small businesses that face a difficult transition. But I do feel that the burden is in the transition, and not something that will hang overhead forever.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#708
post #620
post #613

Earlier quoted context omitted.

> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every web…

If you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights The problem is not the work that the GDPR requires, the problem is the work I'll have to put into understanding the GDPR. I think it's mainly a difference in viewpoint: this is my data for me. Not yours. This is the part that…

> you don't have the right to come to me in five years and demand that I remove all mention of you from my diary at my own cost.

I hate to break it to you but yes I do: by doing business within the EU market you're accepting that. In fact you're accepting that the very same way that you're accepting that you can't store all your clients' credit card/cvv numbers that are used on your store.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#709

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance. "W…

Definitely. I’ve eaten at restaurants with out power floating on the river serving fresh crocs, ate right beside the meal.

Best donut I ever ate was done up in a metal bowl sitting on a cinder block with a hole chipped into it for the tiger torch.

It’s not rocket science to make a meal without killing people.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#710

Earlier quoted context omitted.

Also tired of people thinking that a company not wanting a rule means they were intending to do the exact the opposite of that rule, especially given said rule is incredibly vague and designed to be applied "on principle". Fortunately for all of us, safety regulation is actually very specific in requirements.

> especially given said rule is incredibly vague and designed to be applied "on principle". You know, I'm starting to feel that at least some of this contention is based on how Americans interpret the law vs. how Europeans do it. Somehow it seems that Americans (and the UK) has this huge legal corpus but everything has to be nitpicked to the letter, or the common law judges' interpretations may vary wildly, and some…

It's the opposite. "In-principle" creates lots of potential for interpretation, depending on who is doing the reading. The spirit of the law is also taken into account all the time in America.

It's really not as simple as you make it out to be and the EU has plenty of argumentative litigation.

Post reply on HN