Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

711–720 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#711

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance. "W…

Yes, in fact I think I have eaten at literally hundreds of places like that all over the world.

Also: your equivalency is ridiculous. I have had a "food manager's card", which means that I am certified to oversee an entire restaurant of chefs and cooks who all presumably have their own "food handler's card". The certification took about an hour. Food handler's cards take even less time, and you'll be shocked to know that many people working in restaurants don't actually have them.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#712
post #703

Earlier quoted context omitted.

Hey, man, that's totally fine that you don't want those services. Which is why those services are responding by blocking all EU customers. Seems like a win win for everyone. Businesses don't have to deal with ounerous laws, and EU citizens don't get to use those services.

Plus it leaves the market open for other businesses who are actually compliant so they can capture a bigger slice of the market than the existing services. There really is a lot to win.

if a preexisting startup doesn't care for the market, its probably because it's too small to be worth it. This is not 1999, most ideas have been tried at least once. And experience shows that "extra privacy" is just not a selling point.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#713
post #573

Earlier quoted context omitted.

Merely setting a delete flag is not compliant with the GDPR, that's why a cascading delete is necessary. Any programmer worth their salt knows mass random deletes and updates are extremely inefficient.

Wouldn't it be possible to just delete the 'idetifiabel' parts in the database in order to be GDPR compliant? If you for instance save all the user data like user preferences under a random userId, and then delete the personal data (such as email address, name etc.) associated with the userId I would expect this to be GDPR complaint without having to do a cascading delete.

Anonymizing like that would be GDPR compliant yes, as long as the remaining information absolutely cannot be used to identity the original subject.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#714

Earlier quoted context omitted.

More GDPR strawmen. If a user requests deletion, assign anyYassociated entities (eg purchases, conversations etc) to an anonymous user. Or, keep the original user record and just blank all of the fields. You've had two years to think about these problems.

> It’s only a strawman if you assume that everybody knows the right way to do everything. There was nobody around when I did my start up to tell me how to do all of this stuff. lol Edit: Love (and expected) the downvotes. Where's that innovative entrepreneurial spirit? Part of creating a business is figuring out how to do things that won't get you sued into oblivion.

> Part of creating a business is figuring out how to do things that won't get you sued into oblivion.

The harder that gets, the fewer businesses there will be.

If you look at businesses that managed to exist, sure, you'll see stories of how they used their "innovative entrepreneurial spirit" to triumph over every obstacle. Hurrah! What you won't see are the companies that just barely weren't able to exist, the ones that didn't quite make it through every hoop -- and it is this unseen cost that should keep every regulator up at night.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#715

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

I'm kind of surprised by the number of people surprised that companies are thinking this way:

If GDRComplianceCost > EUVisitorProfitMargin Then BlockEUVisitors

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#716

Earlier quoted context omitted.

+1 to this. GDPR is just the personal data equivalent of the "don't be a dick" principle.

It's that, plus a whole lot of unreasonable demands. Just take the requirement to have an EU representative[0]...even a 1-person US startup that processes data now needs to hire someone in the EU and designate a qualified DPO, which they'll likely need to hire as well. That's way more than not being a dick, it's a huge jobs program that will cost companies millions. One estimate I saw indicated that they expected the…

Dumb question, but how is the EU going to come over here to the US and file charges against me?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#717

I run a simple personal blog. I make a meager $200 a year or so from targetted ads on that blog. I have Adsense and Analytics collecting what they collect. My stats have IP's, countries, browsers, OS's, list of pages a visitor looked at, etc. I look through the info on occassion to decide which random rambling I wrote that I should improve or update on the site. This is a hobby but it has expenses and income so it's…

You filthy person. You're violating people's human rights! Shut it down immediately or face the consequences! The world is better off without your dirty honey trap that tries to STEAL AND THEN SELL USER DATA!!!

/s, obviously

This is only slightly more hysterical and illogical than the typical fan of the GDPR on HN seems to be.

IANAL, but if I were in your shoes, I'd either block the EU if that's easy, or just ignore this entirely. They can't enforce anything.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#718
post #619

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

What is the fear about startups? If you look at the ones you actually use reliably for a decade, very few would have been stymied by GDPR. To add on to this, for every successful startups there seem to be many mostly replaceable ones. If anything, a reduction in the rate of new startups would indicate that perhaps the market is growing MORE rational, which corroborates the recognition of risk of PII that the GDPR man…

...or I can just not sell to Europe. Solved.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#719
post #610

Earlier quoted context omitted.

Here's a thought: regulation like this is, along with the heavy-handed ideology that lead to it, is the reason why the EU is still lagging regarding technical innovation. I think this attitude is the primary reason Silicon Valley took hold in the USA and that the EU has nothing comparable. If the EU wants to legislate itself out of the future they're more than welcome to do so -- and I applaud every site who makes th…

I'm not onboard with the idea that Silicon Valley holds a monopoly on technical innovation. Getting people to click on ads on smartphones doesn't capture the entire scope of technology. Europe's economy is roughly as large as that of the United States. Many world-leading companies from the car industry, to chemicals, to biotech reside in Europe. The US holds one dominating advantage in one subset of technology. Consu…

> Getting people to click on ads on smartphones

Clicking on ads is how they fund AI research. Not all tech is equally profitable but you need all kinds. Meanwhile EU is still debating whether it's worth getting into the AI game.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#720

Earlier quoted context omitted.

I don’t know GDPR inside and out, but I have worked at places (not military) where I could be held criminally liable for misuse or negligent disclosure of PII. The answer to “How do you handle...” is that you get your shit together. Separation of duties, build and configuration standards, no customer data on random laptops. When I was in high school, I worked at a sandwich/coffee shop. The precious commodity in that…

And if getting your "act together" is a substantial cost for small companies, no matter? The word choice almost presumes the conclusion, that data privacy rules are obvious, and cheap, and akin to just washing hands after using the toilet. Every regulation has costs and benefits. I also would love to have better worldwide privacy at no or little cost, but the fact that people are blocking the EU shows that some compa…

Data privacy isn’t trivial, but the core concepts are pretty straightforward. Like cash, data is both an asset and liability. The business model of tech insulates the investors completely from liability, so there is no incentive to self-police.

The contempt shown for us collectively as users and people is what triggered the regulatory backlash.

The 2016 electron demonstrated that better than anything why this is important.

Post reply on HN