13 ms·
GDPR: Block EU Visitors with Cloudflare and .htaccess
- messe 8y agoThis is a massive overreaction. As somebody in the EU I hope this GPDR hysteria that the tech industry seems to be experiencing passes quickly.
- sidibe 8y agoIf someone's business is no longer profitable after complying with GDPR, this is a reasonable step to make. I know that to many that means you have a bad/scummy business model, but in any case if you are in this category it definitely makes sense to block EU visitors. I think there are probably a lot of sites in this category as targeted ads are ubiquitous and the source of income of lots of sites. We may see some that are complying now give up if enough people start opting out.
- labster 8y agoIt's more the level of risk. I help run a small nonprofit that uses no advertising and sells no data. If we fail to comply with the GDPR, we're subject to a €20M fine. If it was 4% of global revenue I'd just pay the $80, but no, it's the greater amount. It's a reasonable choice for someone not doing anything scummy to avoid the chance of an impossible debt.
- josteink 8y agoEither... 1. Be upfront about what user-data you collect and how you use it. 2. Or try to find ways to not seem like a scummy, unprofessional or unreliable business partner while randomly blocking customers from your site, because you cant account for their data. You’d think the choice be pretty fucking obvious, no?
- RobertRoberts 8y agoI can't afford the legal costs to prove my innocence against a foreign government anymore than I could afford a $20 million fine. (there's no limit to how many times they can attempt to fine you, even if you are innocent every time)
- mstolpm 8y agoYou only have to prove "innocence" if your users doubt your statements about PII handling, are so annoyed about your doing that they inform the supervisory authority and that authority has sufficient doubt that they open an investigation. It must be a tricky/dirty/spammy business you're in if you really fear that your users will call the authorities in droves about your procedures. Even for user requests the law states that the user must show that he has a valid reason to act, repeated requests just for the fun of it don't need to be honored and the user can charged for thus a behaviour. And to be honest: Blocking access casts more doubt than being open and ask for consent.
- RobertRoberts 8y agoYou are utterly and completely wrong. All it takes is court papers and a lawsuit for _any_ reason at all, and you are done. You seem to be claiming the GDPR dictates who is allowed to sue and what evidence they must provide, and it simply does not. Go look it up, it's a "guilty until proven innocent" system, which guarantees loss to the accused, guilty or not.
- hadrien01 8y agoYou obviously don't know how the EU works. If a Data Protection Agency comes to know your wrongdoings, they'll first try to resolve peacefully the matter, by telling you what you're doing wrong. Only if you persist multiple times you'll be in danger of being brought to court.
- dogma1138 8y ago
- deleted 8y ago[deleted]
- RobertRoberts 8y agoWhat do you recommend the small businesses in the US do that have no business presences in the EU, but have EU visitors to their sites? It's not hysteria if it's a legitimate legal threat that could destroy your ability to feed your family.
- mstolpm 8y agoTell your users what PII you collect about them and why, ask for consent and give an option to opt-out. There is not "legal threat" if you are open about your business model, keep the collected PII reasonable and safe and don't sell the data without consent. Honoring requests for information or deletion is still a problem for you if you served EU users in the past if you don't delete/anonymize that data - even if you block access. If you're not open about your data processing and handling and don't ask for consent, don't blame the GDPR for a business model that can't be honest to your users.
- RobertRoberts 8y agoYou are confirming that all it takes is a little slip up, and your entire life is ruined by legal fees. Or even just the "whiff" of potential slip up, not even a real one, but only a perceived slip up, and your life is over. I have been in court before, if you have not, perhaps that is why you are ignorant of the horrendous dangers this law puts on everyone.
- DanBC 8y agoNo. After one small slip up nothing would happen, unless someone notices it and reports it to the regulator. At that point they'd write you a letter and explain where they think you're going wrong, and point to best practice, and ask you to confirm what you're actually doing.
- RobertRoberts 8y agoYou mean like they did with Google and Facebook, on the FIRST day the law went into effect? http://money.cnn.com/2018/05/25/technology/gdpr-compliance-facebook-google/index.html http://money.cnn.com/2018/05/25/technology/gdpr-compliance-f...
- candiodari 8y agoThe net response EU media companies seem to agree on is that "do you accept cookies or refuse to read our site ?" has now become an EULA-sized agreement for reading their site. Everything else stayed the same. Technically you can say no, if you don't mind clicking on the no button every single screenfull.
- bitxbitxbitcoin 8y agoBlocking EU visitors doesn't actually make you GDPR compliant.
- labster 8y agoYou would additionally have to ensure that you use no servers in the EU.
- sidibe 8y agoIf they were GDPR compliant they wouldn't block EU visitors. Blocking EU visitors does make GDPR not apply to you. There is no way if you are making a serious effort not to serve EU residents that they could enforce it on you
- icelion 8y agoTo block EU visitors, one probably uses IP geolocalisation. IP address is considered a personnal data (in the EU at least). The fun part is, forbidding access to a website according to IP geolocalisation might probably fall under GDPR law for automatic decision processing. So, either you block access to your website using non-personnal data, or you probably actually are non-compliant with GDPR.
- therealmarv 8y agoThat's not the goal of this link.
- RobertRoberts 8y agoI am not compliant with Chinese, British or German anti-free speech laws either. Why should anyone feel threatened by a foreign government's internal laws? The US is a sovereign nation (as are almost all others) and EU laws do not apply here.
- messe 8y agoThey certainly apply if you wish to do business in the EU.
- amriksohata 8y agoThis is almost spite from US companies that don't want to conform to EU regulations
- RobertRoberts 8y agoHow do you recommend any company that makes less than a million a year to live under the threat of accidental destruction at the whim of a foreign nation? Do you think we should comply with every countries laws? What happens when they conflict? (like US free speech laws vs China, or even Britain?)
- amriksohata 8y agoI never said I was pro or anti EU regulations, the EU need to learn they are not the only player in the market
- josteink 8y agoThis is a great canary to weed out shady businesses and websites which cannot account for how they treat their users data. Meanwhile other businesses which takes the GDPR seriously gets a massive boost in trust and reputation. Guess which ones are going to get meaningful new business and which ones will be deemed unreliable and untrustworthy?
- RobertRoberts 8y agoI think this was meant as a hammer on Facebook/Google cartel. I doubt even MS, Amazon, or other large companies will be as adversely affected. The GDPR targets the very business models of companies that collect data and sell it. For this I applaud it's effects, but it's a big nasty dragnet, and innocents are likely to get hurt.
- yehosef 8y agoI've seen this argument/fallacy said over and over again and it's time to speak up. This is called the "black and white" or "false dilemma" fallacy (https://yourlogicalfallacyis.com/black-or-white https://yourlogicalfallacyis.com/black-or-white). The premise is "Either you support the GDPR" or "you're running a shady PII sales scheme". The problem is that there is another option, you're not trying to abuse anyone's data but you don't have the time or interest to protect yourself against a vague legal document with Draconian fines and no track-record to know how it will be enforced. And some of the requirements sound good on paper but less good in front of a screen. Take the request to see my data or download it. I either need to build in a process to automate it or do it manually, both of which take effort. Deleting data is another sounds-simpler-than-it-is problem. What about deleting PII like username from log files? There are lots of people that are making this out like it's not that big of a deal - but it's not something I was expected to do until now and that most of the countries in the world require me to do. I'm not selling people's data or misuse it or them - why should I have to jump through these hoops if I don't need the EU audience or their threat of serious fines.
- therealmarv 8y agoAlthough I dislike this solution for 99% of websites out there, there are valid short term reasons to use this solution. Imagine e.g. a user survey on a US University which saves data not in a GDPR compliant format. Why should this very local small group website be GDPR compliant when it's almost 100% sure it's only used from the US? OK, but now I ask myself what happens if a Europe exchange student also participates...
- bjpbakker 8y ago> Why should this very local small group website be GDPR compliant when it's almost 100% sure it's only used from the US Because it’s the least one should do regarding privacy. When not mandated by law, doesn’t mean you don’t have to do the right thing. Many companies that sell your data are complaining at the moment because they have to come clean about their malpractice. Don’t let them distract you from the compnies that always did the right thing and were gdpr complient before the laws were written.
- RobertRoberts 8y agoIf a European exchange student participates, it does not automatically export their native laws to the US, and supersede them.
- tpetrina 8y agoIn Croatia you get fines for not having a valid fire extinguisher even though there is one in the corner right there. Why? Because "they went out of their office and cannot return empty handed, so let's write this small fine at least". Also, public companies (those owned partially by the state) are exempt from GDPR... That is why GDPR sucks, it is just another tool in almost despotic government.
- rudiv 8y agoRe: messe - the massive overreaction seems to be from Americans in this thread insisting that since their perception of government regulators is as inefficient, a drag on business, and intent on vindictively fining people contrary to the provisions of their enabling legislation. (To me) seems like hand-wavy alarmism about the threat of international law and supranationalism to perceived individual freedom.