TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GDPR compliance as a service

115 pointsby bmurray7jhuabout 7 years ago

28 comments

lillesvinabout 7 years ago
&gt; Simply paste our JavaScript snippet into your website&#x27;s code. We&#x27;ll check every visitor of your site and will block access to users located within the EU.<p>See, the problem here is that you actually have to send an HTTP request to the site that&#x27;s trying to block you, then you load it along with their JavaScript which <i>then</i> blocks you, but at that point the initial request(s) has already been logged and now they have to comply with the GDPR.<p>I refuse to believe this is not a joke.
评论 #16991472 未加载
评论 #16991516 未加载
评论 #16993528 未加载
评论 #16991592 未加载
tylermenezesabout 7 years ago
The idea that simply having an EU visitor load your site can subject you to a $2M fine is a recurring bit of FUD.<p>Directly from the EU:<p>&gt; Provided your company doesn&#x27;t specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.<p>(<a href="https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;reform&#x2F;rules-business-and-organisations&#x2F;enforcement-and-sanctions&#x2F;sanctions&#x2F;what-if-my-company-organisation-fails-comply-data-protection-rules_en" rel="nofollow">https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;refo...</a>)
评论 #16991573 未加载
评论 #16991702 未加载
评论 #16991596 未加载
评论 #16991547 未加载
esyaabout 7 years ago
niko001 &#x2F; Niklaus or whatever. This is extremely shady. You&#x27;ve copy pasted your whole terms and conditions from this page :<p><a href="https:&#x2F;&#x2F;buffer.com&#x2F;terms" rel="nofollow">https:&#x2F;&#x2F;buffer.com&#x2F;terms</a> VS: <a href="https:&#x2F;&#x2F;gdpr-shield.io&#x2F;terms" rel="nofollow">https:&#x2F;&#x2F;gdpr-shield.io&#x2F;terms</a> - Saved here <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20180504020320&#x2F;https:&#x2F;&#x2F;gdpr-shield.io&#x2F;terms" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20180504020320&#x2F;https:&#x2F;&#x2F;gdpr-shie...</a> for good measure<p>Which is illegal to begin with. You even forgot to replace the part that explains what the service does and left the part that says that gdpr shield &quot;provides a social media management tool&quot;.<p>You&#x27;re selling something that just basically does a geoip lookup, and then tries to block people from an entire continent, with pure JS, which can be easily avoided, by the way. I&#x27;m shooting buffer an email to let them know you&#x27;re infringing on their legal material.
评论 #16992193 未加载
评论 #16992284 未加载
jloughryabout 7 years ago
The privacy of EU persons coming in from a non-EU IP address still need to be protected under GDPR. This solution is a start but it&#x27;s not bulletproof.<p>Edit: I don&#x27;t want anyone to think I believe it&#x27;s a <i>good</i> start but it is a kind of solution. I wonder if lots of US companies, once they begin to realize GDPR is a problem for them, won&#x27;t decide to try one of two things:<p>1. This: block access from IP addresses believed to belong in Europe.<p>2. Lobby Congress for a law (or a quick Executive Order) saying that US companies don&#x27;t have to comply with GDPR.<p>A few weeks ago on Twitter [1], I speculated about #2. It was too early, I guess. Few people in USA seem to be aware of GDPR at the present time. That&#x27;ll change in a couple of weeks.<p>[1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;CnAdoctor&#x2F;status&#x2F;978849723808301057" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;CnAdoctor&#x2F;status&#x2F;978849723808301057</a>
评论 #16991452 未加载
评论 #16991460 未加载
评论 #16993086 未加载
评论 #16991450 未加载
评论 #16991310 未加载
quickthrower2about 7 years ago
I&#x27;m currently an EU-ish Citizen, not residing in the EU. Will it block me?<p>Also will it block JS-blocking EU Citizens residing in the EU?<p>Let&#x27;s not mention VPNs. Let&#x27;s not mention Tor.<p>This feels like a &quot;registry cleaner&quot; for GDPR<p>o. xkcd: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;1969&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;1969&#x2F;</a>
评论 #16991408 未加载
评论 #16992232 未加载
评论 #16991390 未加载
privacypollerabout 7 years ago
A &quot;GDPR Compliance&quot; service with a <i>6000</i> word terms of service including such gems as agreeing to binding arbitration, no class-action lawsuits, and royalty-free use of your logo and name, a privacy policy that allows them to use your personal information to promote &quot;new features and special offers&quot; and runs google analytics...<p>This is a joke, right? You&#x27;d have to be crazy to protect these guys with anything to do with personal information protection and privacy.
CorpOverreachabout 7 years ago
Maybe I&#x27;m missing something - but as a US citizen, with a US company, how can EU laws be enforced against me?<p>What&#x27;s the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov&#x27;t comply with levying fines due to some treaty&#x2F;agreement between the countries?
评论 #16991495 未加载
评论 #16991477 未加载
评论 #16991339 未加载
评论 #16991364 未加载
评论 #16997817 未加载
评论 #16991487 未加载
rjvabout 7 years ago
I have this eerie suspicion that GDPR cases will be a haven for trollish and&#x2F;or opportunist behavior. Instead of huge corporations having to shell out significant money to swallow up start-up competitors, they could much more cheaply pay EU citizens to exploit the huge burden of the law on small companies or even solo endeavors. I hope I can be convinced to be optimistic.
评论 #16991527 未加载
评论 #16991896 未加载
评论 #16991564 未加载
评论 #16997767 未加载
nightcrackerabout 7 years ago
From GDPR-shield&#x27;s terms and conditions (<a href="https:&#x2F;&#x2F;gdpr-shield.io&#x2F;terms" rel="nofollow">https:&#x2F;&#x2F;gdpr-shield.io&#x2F;terms</a>):<p>1. GDPR Shield Service Overview<p>The Service provides a social media management tool that enables users to customize the link preview window of websites under their control on social platforms, in addition to other analytics tools to help bolster users&#x27; social media content.<p>...what? Is this a botched copy&#x2F;paste job?
评论 #16991713 未加载
cddotdotslashabout 7 years ago
Put your site behind CloudFront, block EU countries. There, we&#x27;ve solved the problem without a shady SaaS.<p>Edit: which wasn&#x27;t even a problem to start with but if this is the route you want to go, the above is nearly fool proof and costs next to nothing.
评论 #16992217 未加载
threeseedabout 7 years ago
I can&#x27;t tell if this is a joke or not.<p>Don&#x27;t pay &quot;thousands&quot; for GPDR compliance work which will improve your product by providing basic privacy and security features.<p>Instead pay up to $79 a month for a service to block a large percentage of your traffic.
评论 #16991501 未加载
评论 #16991309 未加载
CLGrimesabout 7 years ago
I can&#x27;t tell if this is a fake service or not, but blocking users from EU IP address ranges (which I&#x27;m assuming how it works) will still not stop the EU from following a trail of data that could originate from your organization.<p>That&#x27;s the biggest thing from the EU&#x27;s GDPR rules - what is your organization&#x27;s data inventory, how does it map outside of your organization, and how are you securing PII?<p>If a complaint is made from someone who is an EU citizen, and another organization shows logs that they got this information from your web app or service, that will trigger an audit from the EU. Blocking access to a subset of IP ranges will do absolutely nothing to stop this, and will not stop the sharks once they have smelled blood.<p>In a sense, the EU has plain rules that you can protect against, unlike the FTC&#x2F;FDA (for HIPPA etc) who are vague and will not disclose how you can protect your own organization.
troydavisabout 7 years ago
Disclaimer: This is not legal advice.<p>Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source).<p>If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU country, GDPR still applies. Any site with more than trivial traffic will have some users with those characteristics.<p>Experts debate whether explicitly requiring users to confirm that they aren’t in the EU - say, a country dropdown - is even a solution. If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn&#x27;t have an EU presence).
评论 #17006515 未加载
emddudleyabout 7 years ago
This is GDPR <i>non</i>compliance as a service...
评论 #16991655 未加载
esyaabout 7 years ago
The more I look into this, the shadier it seems.<p>They&#x27;re selling at a whooping $79&#x2F;month, a single php script that does not even check any sort of authentication or API key, and only does a dumb lookup against a GeoIP database : <a href="https:&#x2F;&#x2F;gdpr-shield.io&#x2F;check.php" rel="nofollow">https:&#x2F;&#x2F;gdpr-shield.io&#x2F;check.php</a><p>And this is called by this tiny javascript script <a href="https:&#x2F;&#x2F;code.gdpr-shield.io&#x2F;script.js" rel="nofollow">https:&#x2F;&#x2F;code.gdpr-shield.io&#x2F;script.js</a> that just.. displays an overlay div when you&#x27;re in the EU. Smells like scam when you&#x27;re willing to sell a whole product that can be coded in 20 minutes for up to $1000 a year.
评论 #16992137 未加载
sbukabout 7 years ago
<i>&quot;The European Union&#x27;s new GDPR (General Data Protection Regulation), which takes effect on 25th May 2018, creates uncertainty and risk for website owners. It applies to businesses world-wide, because it protects all users accessing your site from the EU, regardless of where your business is located. GDPR threatens website owners with fines of 4% of turnover or €20 million (whichever is higher). If you don&#x27;t have an in-house legal team, complying with the law requires you to consult with a lawyer specializing in data protection law. In addition, you&#x27;re at risk of vindictive reporting from no-win-no-fee legal firms.&quot;</i><p>Total, unmitigated FUD.
judge2020about 7 years ago
Thought this was a joke SaaS offering, but inputting google.com as the domain and a burner card, it&#x27;s real [0].<p>[0] <a href="https:&#x2F;&#x2F;judge.sh&#x2F;3Bc2E0GR.png" rel="nofollow">https:&#x2F;&#x2F;judge.sh&#x2F;3Bc2E0GR.png</a>
评论 #16991362 未加载
vemvabout 7 years ago
Anyone can expand on what &quot;vindictive reporting from no-win-no-fee legal firms&quot; would exactly consist of?
评论 #16991397 未加载
评论 #16991370 未加载
hartatorabout 7 years ago
I wonder if you can do something like this directly in Cloudflare.
评论 #16991799 未加载
coroboabout 7 years ago
Another site going with the light grey on white text theme. What happened to the accessibility binge everyone was on a few years back :(
cdancetteabout 7 years ago
I think this is actually good for privacy. We will know that companies using this service don&#x27;t care about privacy, even for non-european users.<p>We could then can design a tool detecting the use of this service and notifying the user &quot;this service doesn&#x27;t care about your personal data&quot;.
kruhftabout 7 years ago
&quot;God Damn Protection Racket&quot;
pietroglyphabout 7 years ago
This appears to be Javscript based... Assuming then that it works on the client side, I wonder how long it will take for someone to release a browser plugin to bypass it.
评论 #16992118 未加载
drivingmenutsabout 7 years ago
Argh. Just sent a note to a game company I did some work for that they need to be aware of this.<p>Might have to shut off access to the game for the EU.<p>Dammit.
shiadoabout 7 years ago
Are European TOR users protected under GDPR? What about VPN users? Seems like IP-based services might be tricky.
tscs37about 7 years ago
Is there some example page I can look at to see if this even works?
rdiddlyabout 7 years ago
You spelled &quot;avoidance&quot; wrong...
asn1parseabout 7 years ago
lol fqdn registered on 2018-04-24? gmafb
评论 #16991571 未加载
评论 #16991598 未加载