Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

971–980 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#971

Earlier quoted context omitted.

This might be a bit of a weird question, but how do you remember which information needs to be deleted when you're at the point where you need to use backups?

How long are you keeping backups in cold storage for - usually you'd want maybe 6 months there, but no more, otherwise it's just going to grow unbounded and become a financial burden.

That's certainly a valid point, but it still doesn't solve the problem of having to remember to delete something in the event of data loss.

As far as I can tell to comply with a deletion request with absolute certainty requires infallible storage (which would remove the need for backups) or modifying backups (which contradicts the concept of a backup). Maybe you can claim 'force majeure' at some point, but perfect compliance seems impossible.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#972

Compliance with GDPR for an existing small business might be tricky. But... I’ve been in the “online payment processing” space for decades. When I first got involved, there were no central guidelines for handling sensitive credit card data. And to be honest, there was a lot of neglect within the industry as a result. As I share memories with my colleagues of what was done in the early days it is laughable and a horro…

That's a very good approach and mindset. Now the tide has passed, let's wait until waters calm down

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#973

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

who says it must be possible or easy to run a 1 man company that handles user data? I rather not have my data handled by a company who can’t handle GDPR

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#974
say you are a small or medium sized business based for example in the US, can the EU even do anything to you if you don't comply with GDPR? I agree 100% with people being in charge of their personal data but the US isn't part of the EU.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#975
post #947
post #909

Earlier quoted context omitted.

> I think the things that bother me is: > > 1) A College student working on a side project with no revenue are treated the same as some massive multi-national. That's false. The GDPR repeatedly refers to evaluating the risk with regards to various decisions. The ICO even has separate guidance for small businesses and big businesses. > 2) It's a foreign requirement that feels like a violation of sovereignty. Most busi…

"You're violating our laws that protect our citizens. Why would we possibly have any sympathy for that?" No one forced your citizens to come to my website.

And in the situation that it’s no more complicated than a EU citizen visiting a website that doesn’t sell to European businesses, that’s probably fine.

But when you want to trade with Europe, you have to abide by our standards for human rights.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#976

Earlier quoted context omitted.

That’s the wrong analogy. How about “everyone who is in new york for any amount of time had to not be actively harming new yorkers”. Sure some people who want to actively harm new yorkers are going to go away and never come back... but they’ll all be better off for it - and really every other state should probably pass a similar law. Edit: duely noted. Libertarian capitalists of hacker news do not agree.

I find it amazing that you came up with the most one-sided argument you could think of ("not actively harming") and still didn't realize how badly it can misfire. Here's a hint: my dentist is actively harming me when taking out a tooth.

> my dentist is actively harming me when taking out a tooth.

if that was true you wouldn't pay them to do it. They are causing you pain in the short term, yes. That's not the same as harm.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#977

Earlier quoted context omitted.

That’s the wrong analogy. How about “everyone who is in new york for any amount of time had to not be actively harming new yorkers”. Sure some people who want to actively harm new yorkers are going to go away and never come back... but they’ll all be better off for it - and really every other state should probably pass a similar law. Edit: duely noted. Libertarian capitalists of hacker news do not agree.

This comment is personal data about you, specifically your political views. It's now in my browser cache. If you were to ask me to clear it, I'd probably say no. Am I actively harming you?

I shared my political views publicly. I happened to also use a psuedo-anonymous account to do it. If I suspected my government was cracking down on vaguely anti libertarian-capitalist viewpoints I would probably ask hacker news to remove the extra metadata they might have on their machines that could be used to de-anonymize the comment.

I'm not too worried about your browser cache, but it could under the right circumstances give you some small power to harm me, yes.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#978

Earlier quoted context omitted.

"but we do have some european customers" The entire point is, NO you can't just ignore GDPR. Your lack of action toward compliance is negligent.

Why can't I ignore it? I have european customers but they chose to sign up with a business in a foreign jurisdiction where their laws don't apply. If it's a problem, the EU can feel free to block my sites, but I can't see how it's negligent to not comply with laws that don't apply in my country. I don't comply with laws from many other jurisdictions either. Should I start applying censorship laws for China and Saudi…

I answered your question the first time. The answer is no. If you really had to ask this, just google "does gdpr apply to non eu companies?"

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#979

I'm glad see that the EU has created a potent reason for US internet services to take a hard look at their tracking/privacy feeding-frenzy. When my ad-blocker tells me that 50 to 200 trackers are interested in me reading some innocuous, unparsable word-blob, or watching some throwaway video, I see that as a symptom of thoughtless hoarding and unreasonable prying. This is not gathering intelligence: quite the opposite…

> I see that as a symptom of thoughtless hoarding and unreasonable prying It's a symptom of people not paying for content and news. Also the fact that publishers want to provide equal and easy access to everyone regardless of affordability. > demonstrable, substantial benefit to all this for the end-user it might make a bit more sense. The content you're consuming.

Guess what sir/madam? when I started using the net, there was plenty of great content on bulletin boards and on usenet. And when the WWW started up, there was plenty more great content. SHARED. Eminently affordable. And very, very social. People talking to people, with no overseer/exploiter in between.

> publishers want to provide equal and easy access

What they want is money. 'Content' is what they've got to sell. And they hire pros to jazz it up and fluff it up, never mind reality or reason.

You're never going to convince me that the commercialization and infiltration of interpersonal communications is an improvement. (Except for snoopers and exploiters.) And I'm very sure that I'm in the majority on that one.

If it were up to me I'd limit all the advertisers to one TLD: .stripmall . And then avoiding all the B.S. would be REAL easy. All the 'news' websites that scrape their content would be there.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#980
post #895

I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…

> Most early-stage startups use the (in 2008, when I did mine) best practice of “delete=1”. Changing your whole database over to permanent cascade delete is only easy if you’re a very experienced programmer or who knows what he’s doing. HAHAHAHAHAHAHAHAHAHAHAHAHAHAAHA How did you get upvoted so much

Please don't.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN