36 ms·
GDPR for lazy people: Block all European users with Cloudflare Workers
- xxdesmus 8y ago"Page not found"
- jgrid007 8y agoMay be blocked because you are European ;-) It works for me now.
- logronoide 8y agoI don't understand how this post could reach HN just a few minutes after I published it... Whoever it did, thanks! I decided to make a little change in the URL (Europeans instead of EU) and that's why there was a short period of 404 errors before I created the redirect.
- xxdesmus 8y agoworking now. :)
- jakub_jo 8y agoSince there are IP addresses collected and sent to third parties without consent, it violates the GDPR.
- Psilidae 8y agoBy that logic, doesn't the entire Internet fundamentally violate GDPR?
- outside1234 8y agoTime to shut down DNS!
- deleted 8y ago[deleted]
- 794CD01 8y agoHope ICANN has 10 million euros.
- foobarchu 8y agoAn IP address is not regular PII, its 'linked PII'. It must be collected in conjunction with information that can identify a user to fall under GDPR, an ip on its own is worthless. If an IP address allows you to link information from HTTP logs with a user database that does have PII, then the ip address is part of the PII. If you aren't collecting any actual identifying information, then an ip is fine.
- weinzierl 8y agoI hate the GDPR hysteria as anyone but you might be approaching this topic a bit too casual. The GDPR doesn't speak of "regular PII" or "linked PII". Article 4.1 defines an identifiable natural person as one who can be identified, directly or indirectly, in particular by reference to for example an online identifier. IP addresses are specifically mentioned as online identifiers in recital 30: > Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags Only time will tell how this will be interpreted specifically but we have at least one court decision already [1]: > What makes a dynamic IP address personal data? > The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: > there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and > the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. [1] https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...
- merinowool 8y agoHow this checks if a user is European when using US VPN or being on holidays outside EU?
- repsilat 8y agoI suppose you have to use your TOS for that. (In fact, a banner that tells European users that they aren't allowed to use your site is probably the easiest way to insulate yourself -- if you collect their data because they used your service illegally, I'm not sure you can be blamed.)
- colek42 8y agoViolating TOS is not illegal...
- logronoide 8y agoIt doesn't. It just checks that somebody is connecting from an IP address geolocated in Europe. I tried to be sarcastic, but I think my English is not good enough :-)
- freedomben 8y agoI'm a native English speaker and I picked up on your sarcasm. You did great :-) That said, a constant source of miscommunication from native english to native english that is written, is missing sarcasm. Just a side effect of not having non-verbal communication cues.
- megaman22 8y agoIt uses its magic crystal ball, while simultaneously consulting a legion of captive demons to determine this and other similarly unknowable information.
- quickthrower2 8y agoUnknowable? It's can check your browser footprint and ask Facebook/Google if you are on holiday.
- DanBlake 8y agoConsidered this before, but it doesnt work. IIRC, the law applies to euro citizens both living in country and abroad. As such, geoip blocking is not a working strategy. (a french citizen who lives in japan still had GDPR rights) A better one would likely be a clickwrap agreement for all users stating "European citizens are not allowed on this service" which they have to click a "I am not european" tickbox to.
- logronoide 8y agoI'm the author of the post, and yes: blocking 500 million geolocated people is crazy. That's not the spirit of the law. I just wrote the post because if you want to overkill and you are lazy, you can follow our recipe to 'implement' GDPR. I just wanted to be sarcastic and also show how easy to implement Cloudworkers + Apility.io.
- jotaen 8y agoYou should consider making this a bit clearer in the beginning. There is already a lot confusion about GDPR lately and people could take your post seriously. As pointed out by others already, geo-blocking isn’t a proper way to become GDPR compliant.
- ryanwaggoner 8y agoBlocking 500 million geolocated people is crazy. That's not the spirit of the law. No crazier than thinking you have to comply if you have no connection to the EU.
- smallbigfish 8y agoIf you have no connection with EU why do you collect personal data from the EU citizens? If you don't collect why worry?
- AlfeG 8y agoWhat do "collect" mean. Its too broad to comply.
- jotaen 8y agoI think the most important part about the post is at the very end: > Please don’t take us seriously > This is an example of all the things you can do with Cloudflare Workes and our API. If you like it, please spread the word! But hey, don’t take us seriously. We just wanted to take the drama out from all the GDPR madness out there. Anyway: just for academic interest I’m curious how much this increases the overall request latency, as there would be one additional blocking HTTP call at the beginning. Do you have any benchmarks for that API call to check the blacklist?
- logronoide 8y agoYou can see the average latency here: https://status.apility.io https://status.apility.io But Cloudflare has servers very close to our endpoints around the world, so I guess < 50ms if you don't use SSL could be a good estimation. We are working hard to reduce the amount of time to establish the connection. It's about 80% of the time of the request.
- kentonv 8y agoIf you make sure that the response is cacheable, then Cloudflare will cache it at the edge and so only the first check for any particular IP will be slow. What makes a response cacheable is a little complicated. There's cache headers, but also some heuristics involved. However, you can override all of that from a Worker by passing an explicit cache TTL to fetch(): fetch(url, {cf: {cacheTtl: 86400}}) This will force Cloudflare to cache the response at the edge for one day regardless of anything else. (Note: The documentation currently claims this option is available to enterprise customers only, but as of this week, it actually works for everyone. Docs to be updated soon.)
- logronoide 8y agoYes, you should cache as much as you can to reduce the latency. We have some examples using NGINX and Lua to cache at the very edge and reduce roundtrips to our endpoints. Probably I will give it a try on Workers another Friday afternoon.
- 8y ago
- riantogo 8y agoThat works. YMMV but If you still want EU users here is what I did last night: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b
- jacquesm 8y agoI like it for being to the point and actionable. Thank you!
- LinuxBender 8y agoHow does CloudFlare know if someone is a citizen of the EU and traveling abroad? In haproxy, I redirect a few accept-language headers, but even this has its faults.
- sp332 8y agoYou're the third person to ask this and I'd like to ask you: is this idea coming from a specific source? The law, like any other EU law, obviously does not apply outside the EU. It applies to companies that do business in the EU (even if they are based outside), but it can't apply to companies that don't do business there. https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- LyndsySimon 8y agoIt actually isn't clear that it doesn't, as best I can tell. I don't have the text in question in front of me, but one of the questions I've asked and haven't gotten a solid answer on is - who is covered by GDPR? Is it only EU citizens residing in the EU, or EU citizens generally? If it's the latter, then someone with both US and German citizenship could be covered even if they've never been to the EU.
- Kalium 8y agoGDPR is written in terms of rights people in the EU have against companies operating in the EU. Which is to say your hypothetical dual citizen would have zero rights under GDPR in their dealings with purely US entities.
- outside1234 8y agoThis is a very dangerous interpretation. Let me tell you why: this opens the door for someone, let's say China, to say that their laws apply to Chinese nationals outside of China. You know, censorship and the rest. While GDPR is a good idea, its legal impact can only be for business conducted within EU boundaries, or we are going to open up a Pandora's Box like this.
- logronoide 8y agoI'm the author of the post. My most stupid post is in HN! crazy! I just wanted to be sarcastic and make some laughs about people blocking all traffic from Europe, which is crazy! It's a Friday afternoon blog post to show how cool my product is with Cloudflare Workers and having fun at the same time!
- ultimoo 8y agoWell, it is well written and informational.
- matte_black 8y agoIt's no laughing matter for some companies. EU citizens have turned into pests overnight. There are businesses who don't make much money from the EU to justify compliance with the regulations.
- jacquesm 8y ago> EU citizens have turned into pests overnight. That's an excellent attitude to take towards your users.
- Kalium 8y agoLet's try another formulation. Valuable, dear, beloved users for which the business has boundless sympathy, empathy, and compassion are now awkwardly the source of compliance concerns for which the costs outstrip the reasonably expected revenues enabled by compliance. While compassion is unlimited, it is possible the budgets and time may not be. Better?
- jacquesm 8y agoMuch better. But I wonder what changed since last week because those compliance concerns were just as valid last week. Or do you mean to imply the company knowingly broke the law for a couple of years just because they could?
- spockz 8y agoIsn’t the IP address of a person/data which is subject to GDPR? So this form of blockade means that you need to disclose that you are using service X for checking the black list and that they might track/ store data.
- ThJ 8y agoI keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.
- logronoide 8y agoI wrote the blog post to show how Dilbert's boss would solve GDPR for his company. Don't take it seriously.
- foobarbazetc 8y agoIt’s disappointing, sure... but is it surprising? To a lot of US-ians the GDPR is just some EU bureaucrat stopping them from making more $. Nothing matters apart from being able to do whatever you want and make $. It’s just a different mindset.
- dogecoinbase 8y agoIf there's a successful business that blocks EU access due to GDPR, that's a huge immediate opportunity to enter that market in the EU (unless, of course, the business model is based on resale of personal information).
- briandear 8y agoWhich is exactly the point of the law — it’s a trade barrier.
- j605 8y agoEU companies also have to abide by it so I don't know how it is a trade barrier.
- reaperducer 8y agoOr unless the business model is location-based. The example from a previous HN article was the Chicago Tribune blocking EU access. Are you saying that there's a "huge immediate opportunity" for people in Europe to read local Chicago news? Not every business is global. In fact, 99%+ aren't.
- tener 8y agoI think GDPR applies to EU citizens no matter where they are? So while this will work for most cases, it doesn't really give you immunity?
- gnode 8y agoNo; it applies to EU residents, and they don't have to be citizens. From Article 3 (2): "This Regulation applies to the processing of personal data of data subjects who are in the Union"
- lima 8y agoSome notes: - This is insufficient for GDPR compliance. Besides the other points mentioned in this thread, you also need to delete any data about EU residents you have already collected. - CloudFlare sets a geolocation header, you can probably just use that without consulting a third party, without adding any latency!
- Exuma 8y agoWhy wouldn't you use the built in `request.headers.get("CF-IpCountry")`? This is a very weak and lame attempt at just getting people to use your service when it's already built in...
- apple4ever 8y agoOr even better, just use the Firewall to block by country. That's what we do to stop bots from countries we don't sell in.
- Exuma 8y agoId argue the web workers are better (although they are paid for), only because you have full control over what to do with them (like showing them a message that you're not GDPR compliant in their area yet, etc)
- Tharkun 8y agoI know plenty of people who block all of China, simply to be rid of its many botnes which run rampant and are hosted by network administrators who don't respond to abuse requests. I guess Europeans can now experience how it feels to have parts of the internet made unavailable by whimsical sysadmins.
- justherefortart 8y agoDoesn't china block itself?
- oldgun 8y agoSomeone should really make a tool: use Cloudflare to block your own trackers and user data collector and etc with one click :)
- shiado 8y agoI simply don't understand how or why a law that has scope in the EU is causing trouble for companies which conduct no business in the EU beyond responding to HTTP requests on a global decentralized telecommunications network. Why would an American internet business which conducts no operations in Europe and has no servers in Europe be subject to regulation that affects the EU? What is going to happen? Is the EU going to target American banks of American businesses and try to extract fines? Is the EU going to extradite owners of these businesses? Are EU courts going to issue default judgements on businesses and individuals?
- taf2 8y agoyup, maybe, probably not... we'll find out
- jacquesm 8y ago> Is the EU going to target American banks of American businesses and try to extract fines? You mean like America? That time when the USA decided to enforce their embargo against Cuba by intercepting a payment from one of the Nordics for a bunch of Cuban cigars? No, that's unlikely. > Is the EU going to extradite owners of these businesses? Extremely unlikely, besides that would require the cooperation of the other country. But - and this is interesting - the other countries typically expect the EU to cooperate with extraditions when the law is broken and we do. So who knows. > Are EU courts going to issue default judgements on businesses and individuals? Against individuals: Unlikely, but it could happen, against businesses, that's typically how things go when one party doesn't show up. But note that for that to happen you first have to ignore the regulators for long enough to get them really pissed off, an action I would recommend against.
- emodendroket 8y agoThere are plenty more examples of the US twisting Europe's arm. Currently it's looking like that is the plan for Iran.
- s2g 8y ago
- pleasecalllater 8y agoOr rather: block all EU users because you want to sell the users' data without informing them about it?
- Jeremy1026 8y agoKeep in mind, just blocking traffic out of the EU does not serve as GDPR compliance. EU citizens are covered by GDPR, not EU traffic. A EU citizen traveling to the US is still afforded all the protections of GDPR as they do back at home.
- rarec 8y agoGenuinely curious; how is that even remotely possible to enforce?
- bertolo1988 8y agoIt's not. If you have any legal disagreement with a company outside the EU they tell you to complain on that company origin. I experienced this myself. EU is absolutely powerless outside their borders.
- Kalium 8y agoI understand why you think this way. After all, GDPR is about human rights! In practice, GDPR is binding on businesses that operate within the EU. An EU citizen in the US doing business with a US-only company is not afforded any protections under GDPR.
- _rpd 8y ago> Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- nkkollaw 8y agoThe way things are going, we'll start whole services shutting down completely, just to avoid trying to handle people's data responsibly.
- azernik 8y agoThis is factually untrue.
- CameraSupra 8y agoI didn't get past the first paragraph. The site lobbed four interruptions my way: - Agree to cookie - Forced "Do you want our newsletter" prompt - Request to show notifications - Pop-up icon to subscribe to notifications ... and one non-intrusive top-of-page banner notification, " Awesome! Your IP is not in our blacklists of abuse...". This last item (when dismissed) may have triggered the 4th item above. Edit: fix list formatting
- donohoe 8y agoYou do not have to do that. Just use Content-Security-Policies to block your pages from loading anything but safe assets/services. You will need to politely ask those not using browsers that support CSPs to switch/upgrade.
- bertolo1988 8y agoNothing will happen to companies outside the EU. You can violate GDPR freely. There is no possible way they can enforce any law, fine or penalty outside their borders. They won't even try.
- freedomben 8y agoI heard one person say that they were worried about traveling to Europe to visit if they had any GDPR violations. Do you that's a valid concern?
- tathougies 8y agoThe EU or its member countries are free to arrest whoever they want whenever they want on their own soil, and not face any kind of externally enforceable sanctions. Best way to avoid being subject to arrest in a foreign country is to simply not go there.
- bloak 8y agoSlightly OTT: Does anyone know why May 25 was chosen as "GDPR day"? I asked a data protection specialist, a real expert on the legislation, but they couldn't answer that question for me.
- djhworld 8y agoJust a deadline. Two years ago (14 April 2016) the regulation was adopted, and a 2 year notice period was put in place so businesses could prepare That notice period ended today
- PeterStuer 8y agoJoking aside, I have yet to find a site that isn't using the whole dark patterns book and then some to trick users to consent. Realy disappointing.
- iraphael 8y agoI received an email from a website I don't remember signing up for, and have no clue what they do. After a few attempts I am able to log in. I go through menu after menu looking for the "permanently delete all my data" button only to find an FAQ that says "Q: How do I delete my account?" "A: Please get in touch with our Customer Services team if you have any worries or concerns. If something at {website} has troubled you, we'll be happy to help sort it out." To their credit, the support chat person was very efficient in complying with my request.
- belorn 8y agoJust curious, but what does the investors think when a company volentarly leaves the EU market because it is easier to simply ignore eu as a market then to comply to GDPR?
- reaperducer 8y agoIt all depends on your investors and who your company's target audience is. If I run a business putting up American flags on people's houses on patriotic holidays (an actual business in my neighborhood), then ignoring the EU market is an easy decision because I already was.
- belorn 8y agoAnd if you presented a nice growth graph over American customers with the implication for expansion over other regions such as EU, whats the possibility that some investors considered that potential when they invested? Like say a software service which I would assume is more common investment target here rather than flags.
- reaperducer 8y agoYour example is a different audience. As I pointed out, it depends on your target audience. Not every company wants or even needs to do business with the E.U. in order to be successful. I know that sounds strange to someone in Europe, and I've never been able to make my Austrian friends understand it, but it's true. There are millions of businesses from Australia to Alabama and beyond who don't care about the E.U. For all its noise and bluster about "500 million customers lost!" the European Union is still less than 7% of the world. I think most businesses would be happy to serve the other 93%.
- azernik 8y agoBut almost a quarter of world GDP.
- 8y ago
- heavymark 8y agoWhile I know they are not recommending, recommending this, for everyone who does, this doesn’t get you off the hook at all unless you are a new site who has never had EU visitors. Also of course all the EU citizens in the US, GDPR would presumably still apply.
- ATsch 8y agoRegarding the last point, I'm not sure why this point is still being parroted, despite so frequently being corrected: The GDPR applies to any residents of the EU, not EU citizens regardless of location.
- phyzome 8y agoMore like "GDPR for stupid people"
- zenovision 8y agoI plan to completely ignore GDPR laws and will not modify neither my privacy policy not my SaaS product, even if I have a lot of customers from the EU.
- Bud 8y agoWhy? You're opposed to privacy? And how do you plan to react when you get penalized?
- anf 8y agoBecause he's lazy and thinks he'll get away with it. He'll come into compliance after penalties outweigh the costs of changing the way he does business. This is probably the reaction of the vast majority of folks dealing with customer data, and not at all unexpected — they have a business to run, and costs to customer privacy are an externality being rolled into their costs via regulation.
- orwin 8y agoAlso, this is one of the sane solution if he know he has not that much user data. First fines will not be high or won't happen at all, and he will receive advice and even help from regulatory instances if he is ever reported. If every business owner commenting those GDPR post on HN could act the same and not like headless chicken, discussions would be more healthy.
- zenovision 8y agoI do care about privacy - I don't use Analytics on my website, don't show any ads, don't send marketing emails and don't sell customer data to anyone. However, I will not comply with that bureaucratic law, because the EU will not be able to enforce it in my country and I have much more important things to do to stay competitive on the market (I have a lot of competitors).
- mrtksn 8y agoThat's an important aspect. May I ask which country is that? I'm curious about your product too if you are comfortable enought to disclose it :)
- toweringgoat 8y agoYet another website doesn't know the difference between EU and Europe. I'm not in the EU. You don't need to block me.
- qop 8y agoCan American businesses actually be sued or anything over GDPR? What if all my servers are housed in america? If I have a user agreement that my users agree to, I don't particularly care what another country thinks about what kinds of privacy they think my users are entitled to. I would already have a legal agreement in that case.
- azernik 8y agoIf it is against the GDPR, then it is an illegal agreement in the EU. Non-enforceable contracts are a thing. You are not allowed to literally sign away your firstborn, sell yourself into slavery, or accept a job at less than minimum wage. Enforceability will generally be based on revenue streams coming from the EU (oh you want a credit card processed from an EU user? We'll be taking that money as a payment towards your fine.) If you're a particularly flagrant violator, they may arrest you if you ever dare set foot on European soil.
- CryptoPunk 8y ago>>You are not allowed to literally sign away your firstborn, sell yourself into slavery, or accept a job at less than minimum wage. The last item is nothing like the first two. The EU is now going to see the natural conclusion of a society based on its conception of contract rights. Digital technology magnifies the effect of everything by several orders of magnitude, so I suspect we'll see dramatic consequences flow from the law.
- azernik 8y agoFrom a legal perspective, the last is pretty close to the first two. If you sign a contract saying those things a court will throw it out. End of story. This is how contracts work in the US too. Same as how in California non-compete clauses are illegal.
- CryptoPunk 8y agoNo, it's nothing like the first two. Common law would disqualify the first two, while certaintly allowing the last. The last is only thrown out by courts because of statutory interference/intervention in contracts.
- rp36 8y agoI worked on the same script using CloudFlare workers just a while ago, if someone is interested: https://gist.github.com/botsplash/bf494ea9e95d945229a0a667a562b0e0 https://gist.github.com/botsplash/bf494ea9e95d945229a0a667a5...
- kadenshep 8y agoThe amount of dishonest conversation in this thread coming from supposed "hackers" is extremely aggravating. These laws have existed in various forms across several European countries for a few decades. It's now a standard across all of the EU. This is to say, that these have been tried, tested, found to be functional and useful; these regulations now have proper surface area coverage. This is good for both companies and users. It gives companies clear goals and policies for how to treat users, their data, and what their users want to do with their data. I think what we're seeing is a light shining brightly on some pretty scummy practices. It's understandable why developers who rely on user ignorance to make a profit/revenue would be bummed about this, because these regulations are correctly placing the burden on you, the developer, to be forthright and honest about what you're doing with people's personal and private information. To developers who don't want to do business in an open and honest manner, who rely on low brow tactics with user data, who didn't have the good sense to know what was coming and plan for it: Good riddance. Try again.
- deleted 8y ago[deleted]
- joshe 8y agoAny recommendations or resources for what micro internet sites should do? I'm thinking in scale from website with my picture and some software projects on it, to micro free webservice like uptime checker, to $1 seating chart maker. Block EU is totally reasonable for all these. Is it necessary?
- deleted 8y ago[deleted]
- olivierduval 8y agoNo, it shouldn't be necessary. Because: do you need personal informations from users? If yes: why? Payment & Accounting => allowed ("legitimate use") Technical Monitoring => allowed ("legitimate use") And if some user want to cancel its account: is it a problem (if he doesn't owe you anuthing)??? No? Well... then you'll have no problem
- joshe 8y agoYes but we aren't really sure are we? Like if the ip address gets stored in some open source logging software, it seems like you need to track it down and delete it on request. Or do you? No one seems to know.
- lsmarigo 8y agoTo offer a non-dev perspective on Hn, it feels like tech companies are really trying to annoy us users with GDPR updates in an effort to nurture opposition to similar proposed regulations in the future. I hope it doesn't work. I love GDPR, getting rid of the WHOIS database stuff alone is enough to make me a huge fan. The option to delete my data is also amazing.
- alternate24 8y ago>To offer a non-dev perspective on Hn, it feels like tech companies are really trying to annoy us users with GDPR updates in an effort to nurture opposition to similar proposed regulations in the future. I hope it doesn't work. You think businesses are that forward thinking? You think there is some grand conspiracy to annoy users so that they hate regulation?
- kadenshep 8y ago>You think there is some grand conspiracy to annoy users so that they hate regulation? Yeah? U.S. companies do this all the time. They did it with the cookie warnings and tried to act like they didn't know they were creating an absolutely terrible experience. Companies acting in bad faith against regulations is basically the default.
- Macha 8y agoSee also giant "install our app" banners on mobile sites, like Reddit
- tzakrajs 8y agoIn this case, the companies are following the prescribed rules of GDPR which requires them to not only publicize their privacy policy, but notify their users if it ever changes. This is a side-effect of a well intentioned law.
- lsmarigo 8y agoYou think businesses are that forward thinking? Definitely. Adhering to new regulations costs man hours and $, companies understandably would rather not be forced to comply. No grand conspiracy just long term bus dev.
- nkkollaw 8y agoWhy is everyone losing his mind over this!!? The law makes perfect sense, it's not that hard to be compliant, and businesses with good ethics will already be compliant!
- SadWebDeveloper 8y ago5 USD per month + 0.50 for every 1 million requests my site gets... that a lot of money being wasted on feature that could be solved in another way.
- BadassFractal 8y agoI thought GDPR applies for EU citizens outside of the EU as well?
- globuous 8y agoWait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that). A more effective way might be to ask on page load if the user is an EU citizen. You know, like some financial website asking you if you are a US citizen on page load [0] (i remember marshall wace's old website doing it, it looks like they do not anymore). And EU traffic being the "most malicious" ? Is this satire, irony, or something else ? Seriously, if I go on website W and they go through all the dark patterns possible to collect and share my data without me knowing about it and I'm the malicious one ? Better read that than being blind... [0] https://www.quora.com/All-of-a-sudden-Bank-of-America-is-asking-if-I-have-dual-citizenship-in-the-U-S-and-another-country-They-have-never-asked-that-before-Why-is-the-bank-doing-this https://www.quora.com/All-of-a-sudden-Bank-of-America-is-ask...
- Bromskloss 8y ago> I thought GDPR was applicable for all EU citizens regardless of where they physically are. Do you mean a company and its customer, both located outside the European union, would still fall under this law if the customer happens to be a citizen of a EU country?
- mickronome 8y agoThat's how some US tax/banking codes already work, so it's not without precedent. I don't remember exactly what it's called. But allegedly it's a hassle for everyone involved, both banks and customers. Ah, found it: "... is the Foreign Account Tax Compliance Act (FATCA), which was passed in 2010 and will go into effect in January of 2013. The act requires all foreign banks to identify and report on US citizens with accounts holding more than $50,000 in an effort to clamp down on tax evasion. If banks refuse to comply, they could face a punitive 30 percent withholding tax on all payments from the US."
- stordoff 8y ago> Wait, I don't understand, this is blocking traffic from EU continent. I thought GDPR was applicable for all EU citizens regardless of where they physically are. And I may be wrong, but I thought it did not apply to non-EU citizens surfing the web from the EU (although I may be wrong about that). I believe you have that the wrong way round. The territorial scope (as it applies to processors outside the EU) is defined as "processing of personal data of data subjects who are in the Union". https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/
- donohoe 8y agoAssuming, and this is a big assumption, you can cookie (CDN level) or otherwise leave an indication client-side that the visitor is from the EU, then you can easily make the page GDPR compliant instead of blocking. https://github.com/donohoe/simple-gdpr-lockdown/ https://github.com/donohoe/simple-gdpr-lockdown/ This does NOT solve the problem, its just (IMHO) a better alternative to blocking.
- allan_s 8y agoEven though this post is sarcastic, people forgot that your EU resident could still access you when in vacation or business trip outside of the EU and that they certainly already have plenty of data store fom EU resident, so blocking all european IPs does nothing to help them being compliant.
- penagwin 8y agoJust add to your terms and conditions - not available for EU residents. Yeah you changed your EULA, but at least you don't need to completely review it for compliance.
- snowwolf 8y agoThis is a common misunderstanding. GDPR makes no mention of citizens or residents. It just says “data subjects IN the union” https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/
- sschueller 8y agoGo ahead and block the EU. I will clone your business for the EU market and I don't have to worry about pesky US competition. /s
- bonsai80 8y agoYes, please do block all those customers. What a terrific business opportunity for new companies to enter markets previously full of strong competition!
- HumanDrivenDev 8y agoThe other option - if you have no business presence in Europe - is to ignore it. It's never concerned that I'm likely breaking the laws of North Korea every day, for example.
- l0b0 8y agoI for one love the fact that companies I dealt with once who knows how many years ago are begging me to click a link to "keep in touch." Good bloody riddance. This is possibly the best privacy news of the Internet age.
- kevinr 8y agoThere's one very important problem with this approach: this blocks people from accessing your site who are doing so from the EU, whereas the GDPR applies to EU citizens, wherever they access the Internet from. In other words, an EU citizen residing in and accessing the Internet from the US has just as much right to invoke the GDPR with these sites as an EU citizen residing in and accessing the Internet from the EU. Blocking people accessing your site from the EU does not allow your site to not respond to such requests.
- Laforet 8y agoDo EU laws still apply when a person has physically left EU jurisdiction? I doubt it. After all, every egg sold in the US would be in violation of EU food safety laws (and vice versa).
- kevinr 8y agoIt depends on the law. In the case of the GDPR, it does apply despite the person not being physically in the EU.
- k__ 8y agoEither we get blocked and have the opportunity to build our own alternatives without legacy baggage. Or we get better privacy abroad. Seems a win-win.
- chrononaut 8y agoI think there are a number of comments being made throughout this whole thread that are conflating the effort required to comply with the best security practices to protect user data, compared to the effort required to comply with the language of GDPR. A general theme seems to be that if a company is afraid to do the latter, they must not be willing to do the former. Which brings up a question, is the complexity of building and offering a GDPR-compliant solution really any different than building a solution that conforms to best security practices? I wouldn't think there is much difference. What is the remaining overhead to comply with GDPR? I am sure just understanding it is a notable piece, but would the developers already be aware of all CWEs, BCPs, existing laws and standards for their components which would also be overhead?
- zerostar07 8y agoGDPR is not about security but about privacy and data access protection. In fact security is mostly on paper: requires that you document the data and procedures, but doesn't require you to upgrade your security. So the effort for the one has little to do with effort for the other.
- chrononaut 8y agoGood point; the sentiment in the original post did mean to include privacy in addition to security.
- Bizarro 8y agoClearly, the EU can't enforce or even make laws that apply globally. If you don't have a presence in the EU the GDPR does not apply to you, period. And the GDPR doesn't apply to EU citizens outside the EU, period. But this thread and others just show how people will continually lie when it comes to the politics of GDPR. And when they don't want to lie, they partake in whataboutism. Even EU bureaucrats seem to be willing to partake in at least promoting the idea that it's a global law for their political agenda, when they know it's not. I don't know why people continue to lie about the jurisdiction of this law, when everybody here knows it's not true.
- cabaalis 8y agoI have a couple of side projects I've been slowly working on toward launch. I hate to say it, but I am indeed very inclined to simply block EU users until I can prove the economic viability of the products. There is no personal data involved except their login credentials and what they type in, and that information certainly is not the planned source of income. But it simply isn't worth taking on the liability.
- anfogoat 8y agoMy biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then it should be possible. When you've made it prohibitive, then you've done something wrong IMO. My biggest _fear_ regarding GDPR is that, to me at least, it seems like a one-size-fits-all regulation for a world where only organisations are allowed to run services, and where all services are centralized. Which is not the world we live in (yet).
- gerdesj 8y agoThe processing of personal data should be designed to serve mankind. The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter as enshrined in the Treaties, in particular the respect for private and family life, home and communications, the protection of personal data, freedom of thought, conscience and religion, freedom of expression and information, freedom to conduct a business, the right to an effective remedy and to a fair trial, and cultural, religious and linguistic diversity. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679 http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... I suggest you read the rest of it before opining.
- manfredo 8y agoThis basically boils down to, "just hope that all current and future EU member nation agree with you on what is and isn't morally right." Good thing different societies and cultures have never disagreed on what is and isn't morally just, amirite?
- tomc1985 8y agoI don't think it applies to individuals and noncommercial activity, though I have heard anecdotal reports of european cops hassling people shooting pictures on mobile phones
- gorm 8y agoActually you are breaking GDPR rules because you are transfering personal information (the users IP) to cloudflare.
- ivanstame 8y agoReally guys? As a citizen of Europe I find these posts to be unacceptable. And they are making it to the front page? Really? I am very disappointed in all of you guys, just got one thing to say: FUCK YOU!!!
- brownbat 8y agoFunny that that site announces it's using cookies in a pop-up that blocks much of the text before a click, per another EU reg. Not that we got the best UX from that one, where I'm constantly reminded cookies are a thing, via a large blocking box requiring user interaction, like a pop-up ad for something I already know and can totally control on my end. There's a saying about how internet considers censorship damage and routes around it? Maybe better: the internet considers regulations information, and anycasts them, regardless of their quality. China's a bit of a counterexample. Maybe the firewall is bidirectional, keeps democracy out and censorship in? Maybe that's the endgame, balkanization. Some people will get to live under paternalistic maximalism, some under authoritarians hunting dissidents, some under anarchocapitalism, all dystopias in their own special way. And some of us will flee to Tor and .onion sites and encrypted signatures where we manage our own privacy and prevent third parties from auditing our communications. Edit, "brevity."
- hoppelhase 8y agoHopefully, these actions will spawn european competitors that will eventually take over the market. If you're ignorant and don't care about privacy, you do not deserve better.
- KempFood 8y agoEU laws can be ignored. Block 'em! Maybe someday they will learn?
- jeremyt 8y agoI’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-stage startups use the (in 2008, when I did mine) best practice of “delete=1”. Changing your whole database over to permanent cascade delete is only easy if you’re a very experienced programmer or who knows what he’s doing. And that sets aside the fact that even if you know what you’re doing technically, there are lots of business logic problems with just deleting things out of the database and anonymizing users is very tricky. I was not a great programmer when I started my first startup. I was learning as I went along. We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance. It’s just gotten to the point that there’s one comment after another responding to this regulation or that regulation or this situation or whatever with “well, just call HR“, or “I can’t believe you don’t have a company policy for that!” Or “well just ask your lawyers“. It ain’t that easy. Do you have any idea how much it would cost to have “your lawyers” go through the GDPR, tell you what you need to do, and deal with all of the edge cases and gray areas? $20k or $30k doesn’t seem too high. My biggest fear is that all of these complex bureaucratic laws are just raising the bar for doing a startup. Maybe the days of two people doing a startup in someone’s garage should be in the past? If so, that makes me kind of sad. Regardless it’s not obvious that GDPR is the right policy or that it’s well designed or clear.
- Barrin92 8y agoTired of the eternal startup excuse to justify bad behaviour when it comes to protection of consumer privacy. If it is impossible for some startups to respect strong privacy practices maybe we simply don't need those startups. This 'startupism' is almost an ideology. No mechanical engineer would complain about safety regulation just because it means that they cannot start a business in their garage. In other industries, strong safety standards and regards for customer privacy is simply the norm, not an annoyance.
- jsjohnst 8y agoI’m really getting sick of seeing IP filtering being mentioned in the context of blocking a specific nationality of person. Do people not understand a European citizen can travel? Use VPNs? Have an IP that is misreported to the wrong location?
- castis 8y agoYeah this is basically the equivalent of sticking your fingers in your ears and going "LALALALALALALALA"
- zyngaro 8y agoSeems like nobody got the point of gdpr. A it's core a move to break the US companies (the GAFAs) Monopoly in Europe and to potentially fine them with huge amounts of money. The fact that GDPR is actually a good thing for the users is subordinate.
- gerdesj 8y agoThe discussion here is getting quite heated. I'm sure no one has missed that this is a bit of a light hearted piss take. I was going to go to town on it until I did a quick pre-emptive search but I had no idea about this being a thing: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/451 https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/451 - 451 Unavailable For Legal Reasons I'll assume that 451 is designed to be available if a canary might be required at short notice.
- jedberg 8y agoBut this wouldn't even work, because it applies to all EU citizens, regardless of geography.
- genericone 8y agoThis is a great point actually... the GDPR law specifically applies to holders of EU passports. If your website clearly disallows EU citizens, ie: a popup stating "You are not authorized to access this website if you are, or plan to become within the next 2 years, an EU citizen", are you being compliant with GDPR? Or is there simply no way to be GDPR compliant if you store any personally identifiable data? I won't get into intentions, but it seems like the law is so broad that it just allows any EU government to selectively enforce the law and collect fines from any company they choose...
- jedberg 8y agoIf you don't do any business in the EU, while you may technically fall under the law, it would be nearly impossible to prosecute you for it. But the moment you try to access the EU market....
- codazoda 8y agoI run a simple personal blog. I make a meager $200 a year or so from targetted ads on that blog. I have Adsense and Analytics collecting what they collect. My stats have IP's, countries, browsers, OS's, list of pages a visitor looked at, etc. I look through the info on occassion to decide which random rambling I wrote that I should improve or update on the site. This is a hobby but it has expenses and income so it's effectively a business. At $200 a year there's no point spending even a few hours to figure out if I need to ensure GDPR compliance in the first place much less to do so. No point in figureing out how to erase users if I should ever be asked to, etc. Last night I tried to log into AdSense and turn off targetted ads because I figure that handles most of my risk and is one of the evils people seem to be trying to kill. I couldn't find the option, only found old articles about it "coming soon" on Google, and got nowhere in a half hour or so. Are there any limits to the sizes of companies that have to deal with this? Blocking EU might be the only real option I have (although some say that's not even enough).
- ryanwaggoner 8y agoYou filthy person. You're violating people's human rights! Shut it down immediately or face the consequences! The world is better off without your dirty honey trap that tries to STEAL AND THEN SELL USER DATA!!! /s, obviously This is only slightly more hysterical and illogical than the typical fan of the GDPR on HN seems to be. IANAL, but if I were in your shoes, I'd either block the EU if that's easy, or just ignore this entirely. They can't enforce anything.
- phyzome 8y agoYes, I believe Google is still working on this. Looks like their drop-in thing won't be ready for a couple months: https://support.google.com/adsense/answer/9031649?hl=en https://support.google.com/adsense/answer/9031649?hl=en You can just turn off ads for a while and then turn them on again when Google has gotten their shit sorted out, or leave them on because honestly you're very unlikely to come to the attention of the regulators -- especially since they're not yet fully staffed and funded for this. :-) Blocking EU users doesn't actually protect you, and will just piss people off -- not to mention look shady, and thereby increase the chances of you coming to the attention of regulators!
- doesnt_know 8y agoPlenty of other countries have similar, or even stronger consumer privacy protection laws. It's not too much of a stretch to imagine the US eventually becoming the outlier to the point they have a sort of self imposed "great firewall". The rest of the world will continue on without them, especially as the ~middle class~ population explodes in countries where there previously wasn't one. The US is really only the "center of the Internet" for primarily English speaking countries, as the others have regional variants of popular US based services. There is no real reason why things wouldn't just split out to Europe and Oceania even more.
- abiox 8y agoso, say i'm outside the EU, and put a project up online, awesome.com. it's accessible from anywhere (or rather, it doesn't filter traffic), except from a eu ip. i don't explicitly "target" anyone. does the gdpr suggest that, if a "data subject" in the eu accesses my website without my consent, the eu will view me as subject to it's legal system?
- johnrichardson 8y agoA trend I've noticed from lurking and browsing these comments: commenters who have experience taking risk and operating under existential conditions in stressful, budget constrained companies (AKA, startup founders) tend to be critical of the GDPR. Commenters who work as 9-5 employees or have never started a company (or at least, don't mention as having done so in their profiles) tend to be more supportive of the GDPR. Funny how that works..
- casefields 8y agoIt's easier to ask for forgiveness than permission. It's the Facebook Way™ and the dream for all those soon to be failed startups. Funny how that works...
- scarlac 8y agoA little nuance to your stats: I've spend the majority of my career in startups, mostly my own, many times struggling to survive. Never worked in a comfy big corp. I currently work in a startup and my hours are far from 9-5. I support GDPR. It's the first reasonable solution to privacy I've seen. And I hated the cookie alerts. The transition is tough and we're fighting to figure it out at the moment. But the basic principles in GDPR are solid.
- 8bitsrule 8y agoI'm glad see that the EU has created a potent reason for US internet services to take a hard look at their tracking/privacy feeding-frenzy. When my ad-blocker tells me that 50 to 200 trackers are interested in me reading some innocuous, unparsable word-blob, or watching some throwaway video, I see that as a symptom of thoughtless hoarding and unreasonable prying. This is not gathering intelligence: quite the opposite. Were there some demonstrable, substantial benefit to all this for the end-user it might make a bit more sense. But there are no upsides to seeing shark fins at the beach. When I guesstimate the costs -- just those of energy usage, bandwidth and man-hours, not to mention the rest -- and compare that to the supposed results (only imaginary to me, the end-user)? Sorry, it looks like madness.
- manigandham 8y ago> I see that as a symptom of thoughtless hoarding and unreasonable prying It's a symptom of people not paying for content and news. Also the fact that publishers want to provide equal and easy access to everyone regardless of affordability. > demonstrable, substantial benefit to all this for the end-user it might make a bit more sense. The content you're consuming.
- 8bitsrule 8y agoGuess what sir/madam? when I started using the net, there was plenty of great content on bulletin boards and on usenet. And when the WWW started up, there was plenty more great content. SHARED. Eminently affordable. And very, very social. People talking to people, with no overseer/exploiter in between. > publishers want to provide equal and easy access What they want is money. 'Content' is what they've got to sell. And they hire pros to jazz it up and fluff it up, never mind reality or reason. You're never going to convince me that the commercialization and infiltration of interpersonal communications is an improvement. (Except for snoopers and exploiters.) And I'm very sure that I'm in the majority on that one. If it were up to me I'd limit all the advertisers to one TLD: .stripmall . And then avoiding all the B.S. would be REAL easy. All the 'news' websites that scrape their content would be there.
- 8y ago
- deleted 8y ago[deleted]
- ChaseHall 8y agoim so surprised companies are doing this, but also not at the same time. shocker.
- deleted 8y ago[deleted]
- drngdds 8y agoProtip: you can ignore the GDPR and get away with it if your business is located somewhere that the GDPR has a snowball's chance in hell of being enforced. For example, America
- partycoder 8y agoDoes not work. If you already have information on EU users, you may be violating GDPR anyways.
- rsuelzer 8y agoOn the plus side, the USA Today in Europe is completely ad free now.
- davidgh 8y agoCompliance with GDPR for an existing small business might be tricky. But... I’ve been in the “online payment processing” space for decades. When I first got involved, there were no central guidelines for handling sensitive credit card data. And to be honest, there was a lot of neglect within the industry as a result. As I share memories with my colleagues of what was done in the early days it is laughable and a horror at the same time. We were all learning on our feet. When PCI was introduced in the mid-early 2000s, it was not easy to undo / redo things to be compliant. It took time and cost money. At the time I wished I was working on features rather than “compliance”. But we got there. It didn’t kill us, and in the end we had a better service because of it. Fast forward a decade and I found myself working on another startup in the payments space. PCI compliance was in the very fabric from which we started - we designed things from the very beginning with PCI in mind. And that made PCI much easier overall because every decision contemplated PCI. I feel GDPR will be similar. It will be a transitional burden because existing businesses will have to undo some practices and that is hard. But going forward startups will build services with GDPR in mind from day one, weaving compliance into the fabric of the product piece by piece, and everyone will be better off for it. I’m sympathetic to small businesses that face a difficult transition. But I do feel that the burden is in the transition, and not something that will hang overhead forever.
- marcodave 8y agoThat's a very good approach and mindset. Now the tide has passed, let's wait until waters calm down
- marcrosoft 8y agoWhy are people empowering the EU as a one world government by legitimizing their world wide law? This is flat out dangerous.
- kerng 8y agoThis won't protect you by the way.
- fanzhang 8y agoHas anyone noticed that this is brilliant content marketing by apility.io? Generate a controversial headline, news-jack a current event topic, and then disclaim at the end to prevent the serious backlash.
- ajtulloch 8y agohttps://en.m.wikipedia.org/wiki/Capital_strike https://en.m.wikipedia.org/wiki/Capital_strike
- wjn0 8y agoI think some people are missing a real opportunity here. It seems GDPR is here to stay. A simple, straightforward guide to GDPR compliance for small-medium size websites who otherwise would have difficulty complying, including FOS well-executed software extensions that make it even easier: * Backup compliance * Database deletion performance improvements * Legal explanations à la tldrlegal [1] Haven't done general population-facing web dev for a while, but it seems fairly straightforward. How to monetize it, if at all, I'm not entirely sure. Maybe charge a reasonable fee for short consultations which consist of essentially running down a checklist? [1] https://tldrlegal.com https://tldrlegal.com
- CryptoPunk 8y agoWhat an utter shame. All of the services that people in the EU now will not get to use, all because Big Brother doesn't think people are responsible enough to decide for themselves what data to share with websites.
- gwbas1c 8y agoThe GDPR comes across as a consequence of businesses not self -reguating themselves well enough. If businesses weren't so lacksidasical with personal information; and aggressive with marketing, we wouldn't need it!
- ic4l 8y agoYou do not need Apility to accomplish this. Here is a example of blocking all EU country codes without using any external API's. https://gist.github.com/icodeforlove/9d22e44d0f227cb2740fd3db4d88af3f https://gist.github.com/icodeforlove/9d22e44d0f227cb2740fd3d...
- toweringgoat 8y agoYour geographic knowledge is poor, and you should feel bad. There are a bunch of European countries now blocked that aren't in the EU. (Some of the more famous blocked websites are similarly misinformed, e.g. the chicago tribune tries to tell me I'm in the EU and blocks me.)
- wierd0 8y agoAll of a sudden HN has divided into EU vs US on basic human rights? This seems odd. I don't think you guys really think there is anything wrong with GDPR, not in its implementation nor in its sentiment. I really don't. The reason you are whining like crazy though is because you are in a project where the deadline/budget did not take into account this new EU law. Hey, blame the ones who planned your project, not the EU.
- sequoia 8y agoCrocodile tears. After facebook, google, cambridge analytica etc. screwing us all six ways to Sunday, nothing makes me happier than to see greedy inconsiderate techie "entrepreneurs" kick and scream and cry at regulators (read: voters) bringing the hammer down. If you didn't want regulators involved, maybe don't treat users like human garbage? You/we brought this on ourselves. There is a new Constable in town. Now put on your big girl/boy panties and deal with it. Or is handling user data responsibly one of the new "three greatest challenges in computer science"?
- blockchain-help 8y agoBlockchain technology is revolutionizing the way in which information is stored and shared. It facilitates the creation of a distributed public ledger of transactions that is transparent, secure, self-validating, and cannot be forged. Tampering or tinkering with the data is impossible as a copy exists with every user or participating nodes. With diverse applications in numerous industry sectors from maintaining land records, establishing identity, banking industry, making academic credentials universally recognizable and verifiable, real estate, voting, Internet of Things, healthcare and many more, blockchain technology is disrupting the existing practices across various industry verticals. TO KNOW MORE, PLEASE CHECK OUR SITE:- http://www.blockchainhelp.pro http://www.blockchainhelp.pro
- kworker 8y agoSadly it's not humorous for many people.
- ernesth 8y agoIs it supposed to be enough to be compliant with the GDPR? If you have harvested data from Europe, you are not allowed to sell/transmit it without informing the concerned party. I feel that to become GDPR compliant this way, you also have to delete all data that may have come from european residents.
- sepin4 8y agoAs a person on both sides of this regulation I have to say I'm not conflicted at all were I stand. On a professional level this will have a huge impact on the firm that I've been employed for more than 5 years because of the legacy practices used in the software. This has been the proverbial "clusterfuck" at work. This might even have serious implications to the future of the firm as most of our customers reside in EU. Nevertheless on a personal level I'm so happy and relieved that finally something is being done to protect information. In fact I believe that the tighter the screw on the regulation the better. If some businesses have to stop entirely in order to reevaluate what has been done, why it shouldn't be done this way(I like the analogy about slavery I read in the comments here) and start from scratch if possible at all, then so be it. Even if it threatens my job security(and I just bought myself an apartment) I'd still be in favour of this. In fact I believe that in a few years if this sticks it would be much easier if not trivial to deal with GDPR regulations and then my only regret would be that this was not implemented sooner.
- _pmf_ 8y agoDoing this would be a huge boost to Europe's economy by weaning us off the teat of Silicon Valley's robber barons. Do it!
- cynwoody 8y agoHoly crap! 1123 comments and the damned article link doesn't work! Might someone have something to hide? http://webcache.googleusercontent.com/search?q=cache:xrEsOXE4eakJ:https://apility.io/2018/05/25/gdpr-lazy-block-european-users-cloudflare-workers/&num=1&hl=en&gl=us&strip=1&vwsrc= http://webcache.googleusercontent.com/search?q=cache:xrEsOXE... Judge for yourself!
- xstartup 8y agoGDPR is set to destroy American tech/media companies along with those from developing nations. Europe has got most of its wealth through imperialism back in time robbing countries of Africa and South Asian countries. This is the primary reason countries of South Asia/Africa so poor today. Before imperialism, most of Europe was poor while countries like China and India were way richer. India is just 70 years old by comparison which is not long enough to make back the lost wealth due to its sheer size and diversity. Now, American companies are able to an extract huge amount of money from European nations using mostly legal (maybe unethical?) using companies like Google and Facebook. They are set to make this illegal. It's nothing more than a wealth preservation strategy. European nations can't compete against America and rising nations (India, China etc...) due to their aging population in near future. So, they are going to shut off the market by making unreasonably harsh laws which are quite difficult to comply with. You are finding compliance difficult because it's intentionally part of their design. Keep an eye open and expect more unreasonable laws coming out of EU in near future. They are not going to stop here.
- xstartup 8y agoCare to explain downvotes? I would love to know why would anyone disagree with me.
- erebrus 8y agoThis might be a silly question, but I'll take the chance to ask it anyway. What constitutes personal data? More precisely, using FB as example, does it apply to things like: 1. where have you been? 2. what have you liked? 3. photos you've shared? 4. comments and posts you've made? Or is it really just identification details like name, address, etc.?
- onetimemanytime 8y agoIt may make sense. If 4% - 5% come from EU why go through all the hassle and risk fines? Block them. Unfair to users? Oh well...
- bengale 8y agoGreat, lets hope European companies move quickly to provide services for these users.
- deleted 8y ago[deleted]
- jakeogh 8y agoWhy bother? If you are not in the EU, and you don't have assets in the EU to seize, it does not apply to you. The EU does not get to make laws for other countries.
- jakeogh 8y agoHN Meta: Is it really necessary to split 1k comments into 5 pages? Many sites serve a homepage much larger than every comment here on a single page.
- teddyh 8y agoIt isn’t just to limit page size, it also works as a damper on heated discussions, as most people won’t read more than the first page, but comparatively few people stop reading in the middle of a page, regardless of length.
- jakeogh 8y agoI figured that, but I didn't want to make such an embarrassing assumption about what purports to be a reliable tech discussion site. Especially when I noticed new comments automatically went to page >1. Sad, but hey, it's HN's property.
- mamon 8y agoAlternative approach by USA today: add and tracking free site for EU users :) https://eu.usatoday.com/EU-learn-more/ https://eu.usatoday.com/EU-learn-more/
- Fnoord 8y agoHow does this make you compliant for the data you _currently_ own?
- herbst 8y agoI hope people realize that there is a difference between Europe and EU...
- sriku 8y agoEncouraging this attitude is childish. GDPR (which has been around for 2 years now) is a way for people to say "ok now grow up guys, we know you like to tinker, but we're getting screwed in ways we don't like and we've given you enough rope". This post is saying "so just don't sell soylent in the US because we're too good to bother passing FDA". No serious and earnest would/should consider this. Your work affects lives. Period.
- amerkhalid 8y agoI agree it is raising a bar for starting a new business but I think this is a good thing in this case. As a victim of identity theft, I say that burden should be on entrepreneurs to learn and write good code. I have written a lot of bad code myself but back then everyone was writing bad code to get to market as fast as possible. People who wrote good code and followed best practices for their users’ privacy and security were at disadvantage. This regulation evens out the playing field, so now good guys/gals can compete too. Also this is not hard if you were already following the best practices for security and user privacy. Sure there is some new stuff like real deletes instead of soft deletes. I can tell you from my experience that the people who are the most stressed about GDPR are those who are working at the companies where they had very bad dev practices. One of my friend who works at a decent-sized ecommerce shop, had to finally get rid of CC numbers in their logs. That guys had been pushing for better security and dev practices but would get overridden by managers and team leads. I am glad that GDPR is finally forcing higher ups to finally improve their dev and security practices.
- skunkwerk 8y agoYou need a legal basis for automated decision-making, such as doing geolocation on a user's IP address (which can be considered PII, as per EU legal rulings from last year). Which means you cannot block them without first getting that legal basis (i.e. consent). Therefore, you're in a catch 22.
- segmondy 8y agoRubbish, folks block Africa and China all the time
- smooc 8y agoI don’t see a lot of comments looking at the practical side of things. I am implementing GDPR and here are some suggestions: 1. Collect only what is necessary for providing your service 2. Make clear what you store and for what reason 3. Ask consent and give the opportunity to retract this consent as easily Deletion: 1. PII means information that makes a person identifiable. This is the type of information that you need to remove 2. So if you are storing PII information for the use of profiling you will need to disconnect the profile from the PII information. E.g. you could use user table where you would overwrite the PII information with generic information. You can still use the now stale profile withou PII information (for example in statistics, aggregations etc), but you cannot tie it to a single person anymore. Ie. You should not be able to reconnect the person to profile you have stored. 3. As technical possibilities evolve you need to improve the disconnection over time. There are legitimate business reasons to store some PII information. E.g. for security reasons, other laws etc. So IP addresses don’t need to be deleted from your web logs, but if not given consent you cannot use them for ads, sell them etc. The required clarity that GDPR will bring to your data is actually going to benefit you. Your data scientists will love it, because the tooling that helps with Gdpr also helps with discoverability, data quality etc. Enjoy GdPR, there is a lot of business opportunity in it.
- solotronics 8y agosay you are a small or medium sized business based for example in the US, can the EU even do anything to you if you don't comply with GDPR? I agree 100% with people being in charge of their personal data but the US isn't part of the EU.
- acou_nPlusOne_t 8y agoMan, i miss those days before this industry got jumped by all those hijackers. Imagine if the law was layered, as in - below a certain size, you could get away with unintentional mischief.
- jaakl 8y agoIt is not just Europe and GDPR. You should block users from every single country where you are not ready to take responsibility to comply with the local laws. By providing service/content in international scale you are doing business with real physical people there, regardless of your own or your server's location. Seriously. So Cloudflare (and all other CDN/web service providers) should really have country-based opt-in instead of opt-out, so you at least think a second before clicking the tick.
- estevaovix 8y agoNot that simple. It doesn’t matter where the connection is coming from, what really matters is if the person is european.