Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

731–740 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#731

Earlier quoted context omitted.

I don’t know GDPR inside and out, but I have worked at places (not military) where I could be held criminally liable for misuse or negligent disclosure of PII. The answer to “How do you handle...” is that you get your shit together. Separation of duties, build and configuration standards, no customer data on random laptops. When I was in high school, I worked at a sandwich/coffee shop. The precious commodity in that…

And if getting your "act together" is a substantial cost for small companies, no matter? The word choice almost presumes the conclusion, that data privacy rules are obvious, and cheap, and akin to just washing hands after using the toilet. Every regulation has costs and benefits. I also would love to have better worldwide privacy at no or little cost, but the fact that people are blocking the EU shows that some compa…

The problem with carving out exceptions for small companies is that larger ones would simply subcontract out all their data handling.

Like encryption, data privacy is either all or nothing.

And personally? I'd rather live in a world without tracking-enabled Google and Facebook business models than the one we're currently in.

Holding personally identifiable data is a toxic externality: Experian simply exposed a clear case.

If you want to do so, you should have to bear that cost. Or design your business model differently so that you don't.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#732

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

There are literally hundreds of laws, some very large, that tech startups must comply with from day 1. Yet somehow we still have startups and small companies, and the world goes on, round and round. Why no complaints about these other big laws? None of them get the vitriol hurled at them quite like GDPR. I suspect this is because having to comply with big laws is not really the issue. The real issue is that GDPR hits Silicon Valley right in the soft spot where it hurts: Callous and unrestrained collection of user data. Everyone is complaining "I don't want to have to comply with big laws!" but what they are really thinking is "I don't want to get busted for the crazy amount of data we suck up (or want to suck up) and store!"

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#733

Earlier quoted context omitted.

GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes: I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required t…

> The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. (snip) That's their interpretation of GDPR. It doesn't matter whether it's right or wrong. This is the side-effect of GDPR. I understand it's frustrating on your side, because you have no control over the response of your customers. But understanding what GDP…

If you judge a law on what its effects should be rather than what they will actually be when applied to imperfect people, plenty of terrible laws will look good.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#734

Earlier quoted context omitted.

I'm a Brit. I am the MD of a small IT company. I have two partners and 20 employees. We started in 2000. We turn over about £1.5Mpa. We sell our services to people and organisations. Our backups are now smaller these days (thanks to GDPR). I understand that because you are outside the EU you might feel like a target but that is not the point of GDPR. There is no way on earth that the EU as a whole has looked on your…

In legal contracts "whereas" often expresses sentiment but it's really the actual terms that matter. Having drafted a number of contracts, I feel most contracts generally have a section that approximates "whereas everyone wants things to go well and everyone to benefit..." That's great that your company works well with GDPR. I imagine many companies will. I'm also sure that the impact on your backups could have been…

That’s the wrong analogy. How about “everyone who is in new york for any amount of time had to not be actively harming new yorkers”. Sure some people who want to actively harm new yorkers are going to go away and never come back... but they’ll all be better off for it - and really every other state should probably pass a similar law.

Edit: duely noted. Libertarian capitalists of hacker news do not agree.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#735

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

Thank you for saying this, another thing that is ridiculously difficult is to delete specific user from all your backups. This is made even worse if you have multi region backups and cold back ups. Even a one-year-old start up could have literally thousands of database dumps in different places if they followed best practice of triple redundant daily dumps.

The general recommendation is that if it's too difficult to purge specific users from your backups then:

* Have a clear data retention policy and make sure that all backups have an expiration date.

* Secure your backups with strong encryption to protect user data in the event of a leak.

* Explain it to the user when the account is deleted when the deletion will filter through your backups.

* Guarantee that if a restore is needed, their data will be immediately deleted from the restored system.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#736

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance. "W…

Yes. Shove perishables in a refrigerator/freezer, cook any meat thoughly, slap an allergy poster somewhere, and then allocate 30 minutes a night to cleaning and you're 95% of the way there

In contrast there's so much FUD surrounding this bill that you'll end up having to hire a lawyer to figure out how to clear up your EULA without accidentally leaving a loophole for the predatory lawyers on the American side that are partly the reason those EULAs are such a impenetrable wall in the first place

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#737
post #633

Earlier quoted context omitted.

It's reassuring to hear that the GDPR is not meant to target little startups and projects but I would like it a lot better if it said that in the actual law, rather than just trusting all current and future regulators to treat me kindly. If it's only meant to be used against big companies or extreme offenders, why doesn't it say so? It seems like the spirit of the law and the language of the law are not aligned and i…

"but I would like it a lot better if it said that in the actual law" Have you read the bloody law! http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... This is legislation designed to protect not only me (as an individual) but you as well (as a probable foreigner) from me!

In the history of laws, many of the ones designed with good intentions have been quite harmful.

And yes, I've read the law. It's typical of legislation in that it obviously wasn't written by people who knew what it looked like to perform that in a real life business.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#739

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance. "W…

>Would you eat in a place like that?

a vast majority of the food places in my home country were like that when I was growing up, and such places likely still make up a sizable portion of the food businesses down there now. I can't help but be a bit offended by this attitude, because it seems to not only be implying that these businesses are likely to be operating in bad faith, but that the world would legitimately be better off without them as well. It's great that you probably grew up and live in a situation where that might've been feasible, but I can't in good conscience defend those views having lived in places where such strictness is out of reach for most entrepreneurs.

The world isn't entirely comprised of Europe and North America.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#740

Earlier quoted context omitted.

> There is no way on earth that the EU as a whole has looked on your company/project or whatever and decided to screw you. The rules are enforced via third-party litigation. So its not the "EU", but some lawyer looking for a nice payday that you have to worry about.

While the GDPR allows for third party litigation, the violations are expected to be handled though relevant data protection authorities, and direct litigation is a last recourse if all else fails. If you haven't tried and failed to resolve your GDPR complaint through the relevant authorities, you'll be laughed out of the court, if you try to bring a GDPR case to it. Edit: any replies instead of just downvotes? Yes, i…

Even if true, how are small American companies supposed to know about any of that without investing in a lot in European lawyers? Easier to just not serve the market.
Post reply on HN