10 ms·
GDPR for side-projects? Blocking all EU traffic with Nginx in 3 simple steps
- salad77 8y agoBut for compliance many interpretations say it's EU /citizens/; I don't think there are 3 simple steps to block any EU citizen... I'm sure many Governments would love to be able to so simply identify what their citizens do online though.
- jiveturkey 8y agothose interpretations are wrong. but even so, blocking eu traffic by IP isn’t sufficient.
- silsha 8y ago> those interpretations are wrong. Source?
- icebraining 8y agoNot from a regulator, but: https://www.linkedin.com/pulse/gdpr-does-apply-eu-citizens-gregory-albertyn/ https://www.linkedin.com/pulse/gdpr-does-apply-eu-citizens-g...
- kevsim 8y agoNot a lawyer myself, but according to the regulation (https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...): "In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment" So if the users are in the Union and you're not, you're still on the hook. If the users aren't in the Union, you're free and clear. Also applies to EEA countries like Norway and Lichtenstein btw (source: am currently working on GDPR compliance in Norway).
- splintercell 8y agoHN crowd loves GDPR, so get ready for this never making to the front page.
- matthewmacleod 8y agoThe front page has had daily articles from mis-informed US tech startups collectively shitting themselves about GDPR for weeks.
- cft 8y agoHow many former US startups such as Google or eBay do you use in the UK? And how many former UK startups does an average US user use? There gotta be a reason for this disparity. And the reason is regulatory capture in the EU.
- matthewmacleod 8y agoNo it’s not. The reason is a much more friendly funding environment in the US.
- lovich 8y agoMan, I think that's the first time I've seen someone compare the EU to the US unfavorably on regulatory capture. They both have it, but the US has basically perfected it. Just look at the FCC and it's current chair
- fwdpropaganda 8y agoDo they? It's kind of a mixed bag. I see about 60% say "well, if your side project doesn't respect your users privacy, maybe you shouldn't have a side project.", and the remaining 40% saying "I'm too scared of the consequences from doing illegal stuff"
- imtringued 8y agoShutting down your side project in the fear that the EU will shutdown your side project seems like a premature reaction.
- olliej 8y agoIf you have a side project that siphons personal information from people for no reason, then maybe the gdpr isn’t the problem...
- itake 8y agoI don't have time to build user exporting, user deletion, user notifications, amongst other required features on top of the already big backlog of fearures to do. I use third party tools to help worth logging and error tracking. Its just not worth my time to support gdpr on a website that makes no money.
- fwdpropaganda 8y agoDon't worry, people will build those tools open-source the same way that they've built other tools for other purposes. I'm sure if a Django library for doing all those things doesn't already exist, it will very soon. It will become a popular project too, because at some point it will become the default. I meant, respecting the law has been a thing for many years, you know? GDPR isn't really different.
- deleted 8y ago[deleted]
- matthewmacleod 8y ago“I don’t have time to label and expire all the food I prepare on top of serving meals to customers” “I don’t have time to do all those structural calculations on top of all the properties I have to build” “I don’t have time for all this silly human safety testing on top of all the drugs I have to develop” Your statement is equivalent to the above. If you are unwilling to meet a relatively straightforward level or privacy and security for your users’ data, then personally I’m really glad that you’re going to prevent users from accessing it.
- orand 8y agoNice ridiculous examples. Now for some ridiculous examples on the other end of the spectrum: "If you refuse to document every ingredient and possible allergic reaction when inviting friends over for dinner, then I'm really glad if you don't have any friends." "If you don't create structural and safety calculations for your kids' tree fort, then I'm really glad when your kids fall out." The point is, people need to be able to start small and then scale up if/when that makes sense. If everything has to start "big" (relatively speaking), then we will simply have fewer things, to the detriment of all.
- LinuxBender 8y agoGeo IP blocking will not block the EU citizens that are not physically in the EU at the time. Just for fun, I would add server { # snip.... access_log off; error_log off; return 307 https://www.google.com/search?q=gdpr; } That should block anyone that might be a EU citizen. /s
- isbvhodnvemrwvn 8y agoNor ones who use VPNs located in other countries.
- hathathat 8y agoWhat would be a GDPR-compliant yet useful access_log setting?
- ummjackson 8y agoYou could just use a log format that excludes or obfuscates IP addresses, I believe.
- FabianBeiner 8y agoTruncate the IP, that's it.
- cpc26 8y agoUnless your side project is a Bot-Net this article seems very FUDDY...
- cpburns2009 8y agoWhile this sounds like an overreaction, I question the breadth of this method (unrelated to the reliability of IP address origin). > This tells nginx to assign the $allow_visit variable a 0 for any users the GeoIP database specifies as coming from the “EU” continent. Europe is the continent. The EU does not encompass all European countries. Doesn't this needlessly block non-EU European countries?
- ummjackson 8y agoGood point, it likely does. Alternatively, you could set up the rules using country and list out the 28 that make up the EU.
- lrpublic 8y agoThis seems to be flawed logic, many EU devices have IP addresses from non EU address blocks. Assuming there is any significant adoption of your proposed solution to avoid GDPR rules the likelyhood is EU citizens will use VPN or Proxy services to bypass the restrictions. I don’t think the use of a VPN would remove the GDPR obligations on the data controller or data processor.
- icebraining 8y agoIt pretty much does. Sites are not automatically subject to the GDPR, even if they happen to be accessible, there must be some evidence that they intend to be used by users in the EU. Blocking it seems pretty good evidence that they don't. See https://gdpr-info.eu/recitals/no-23/ https://gdpr-info.eu/recitals/no-23/
- ilovetux 8y agoAlong with the author, I am hesitant to needlessly follow regulations which only apply to a small portion of global population of which I am not a part. Especially since there are simple ways to sidestep the liability. This, however, does give me an idea. Does anyone have an interest in a web framework which provides user/data management in a gdpr compliant way?