GDPR compliance as a service
gdpr-shield.io
gdpr-shield.io
See, the problem here is that you actually have to send an HTTP request to the site that's trying to block you, then you load it along with their JavaScript which then blocks you, but at that point the initial request(s) has already been logged and now they have to comply with the GDPR.
I refuse to believe this is not a joke.
This service isn't blocking requests to your site, it's just showing the visitors different content after the fact.
If it helps, I use AppEngine for my App which already provides geolocation information in the IP and my app blocks it the moment it receives the request. Users will only see a re-direction to a notice relating to GDPR and what they'll need to do if they still want to access the site.
Are you referring to the IP address, which is personal data?
Directly from the EU:
> Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.
(https://ec.europa.eu/info/law/law-topic/data-protection/refo...)
Do you have to provide proof that your site doesn't specifically target its services at individuals in the EU?
Does that mean that (e.g.) German bloggers are not bound to the GDPR when they just add "made for the Swiss" to their header?
If someone is gathering and storing email addresses and ip addresses it seems reasonable to ask them to take industry standard measures to protect that data, and to let users know that the data is being collected.
According to the GDPR, they are. https://eugdprcompliant.com/personal-data/
"The conclusion is that the GDPR does consider it as such."
The main problem overall is that the EU appears to consider information about someone as being owned by that person. That is quite foreign from a US individual perspective and having some blogs. I don't see how the learning I have acquired about people places and things, which I acquired without any promise of confidentiality, can be owned by anyone but me. Are libraries and newspapers required to scrub their shelves and archives? And if not, what is the limiting principle?
But indeed that can go both ways - the website of a newspaper might be required upon request to remove a 20-year-old crime blotter item reporting a single petty theft conviction for an otherwise law-abiding non-celebrity; they wouldn't be required to do that for a 2-year-old murder conviction.
One requirement, imho, is quite ridiculous, however. That is the need for entities which need to abide by the GDPR but do not have a presence in the EU to assign a representative in the EU.
This part definitely needs some relaxation. Just complying with the regulation ought to be enough as the first step, especially for start-ups.
It is enough; most start-ups won't need a representative.
That requirement only applies to large-scale processing of special categories ( i.e. sensitive ) of data or that relating to criminal convictions and offences.
Article 27 applies: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
It's basically to prevent big data processors from claiming 'we don't have an EU presence so you can't fine us'.
https://buffer.com/terms VS: https://gdpr-shield.io/terms - Saved here https://web.archive.org/web/20180504020320/https://gdpr-shie... for good measure
Which is illegal to begin with. You even forgot to replace the part that explains what the service does and left the part that says that gdpr shield "provides a social media management tool".
You're selling something that just basically does a geoip lookup, and then tries to block people from an entire continent, with pure JS, which can be easily avoided, by the way. I'm shooting buffer an email to let them know you're infringing on their legal material.
http://pub.bna.com/ptcj/1051462Jan11.pdf
GDPR-shield's original T&C was actually copied from ShareKit, which is another product from the same company:
But going paragraph by paragraph down the terms, you get this list of companies, all with the same language:
https://www.google.com/search?q=%22Except+for+certain+kinds+...
https://www.google.com/search?q=%22You+must+be+at+least+%5B1...
https://www.google.com/search?q=%22To+access+most+features+o...
https://www.google.com/search?q=%22The+Service+will+require+...
https://www.google.com/search?q=%22may+seek+pre-authorizatio...
https://www.google.com/search?q=%22The+Service+may+include+a...
https://www.google.com/search?q=%22may%20suspend%20or%20term...
That's only through section 4, but so far every clause is legal boilerplate except for the first paragraph of section 4, which is unique to ShareKit (and ThreadRadar, another product by the same entrepreneur).
Edit: I don't want anyone to think I believe it's a good start but it is a kind of solution. I wonder if lots of US companies, once they begin to realize GDPR is a problem for them, won't decide to try one of two things:
1. This: block access from IP addresses believed to belong in Europe.
2. Lobby Congress for a law (or a quick Executive Order) saying that US companies don't have to comply with GDPR.
A few weeks ago on Twitter [1], I speculated about #2. It was too early, I guess. Few people in USA seem to be aware of GDPR at the present time. That'll change in a couple of weeks.
The only foolproof solution is just to block all IP addresses.
"This won't apply to every U.S. business — just the ones that are knowingly, and actively, conducting business in the EU. In this vein, EU courts have the discretionary ability to determine if a U.S. company was purposely collecting EU resident data and subverting GDPR compliance. So, in some cases, the inadvertent collection of personal data will be forgiven if it is found to have been occasional and "unlikely to result in a risk to the rights and freedoms of natural persons."
(from https://community.spiceworks.com/topic/2007530-how-the-eu-ca... )
Also will it block JS-blocking EU Citizens residing in the EU?
Let's not mention VPNs. Let's not mention Tor.
This feels like a "registry cleaner" for GDPR
o. xkcd: https://xkcd.com/1969/
Probably. It seems like a quick "let's make some money" scheme to milk the GDPR panic.
> It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location.
"This won't apply to every U.S. business — just the ones that are knowingly, and actively, conducting business in the EU. In this vein, EU courts have the discretionary ability to determine if a U.S. company was purposely collecting EU resident data and subverting GDPR compliance. So, in some cases, the inadvertent collection of personal data will be forgiven if it is found to have been occasional and "unlikely to result in a risk to the rights and freedoms of natural persons."
(from https://community.spiceworks.com/topic/2007530-how-the-eu-ca... )
This is a joke, right? You'd have to be crazy to protect these guys with anything to do with personal information protection and privacy.
What's the legal channel here? Do they plan on arresting me if I decide to vacation to an EU country? Will the US gov't comply with levying fines due to some treaty/agreement between the countries?
Some things are very deliberate, but others are the consequence of decisions far removed from those of site operators.
I go through and toggle all the settings the internet tells me to, even though I don't know their meaning or effect. Am I GDPR compliant?
I install a Wordpress plugin that sets up a Really Simple Chocolate Chip Syndication server, or RSCCS. That plugin logs IPs. If I was GDPR compliant previously, now I'm not, and how would I ever know?
I know plenty of people with a get rich quick scheme to sell widgets, but who don't know the difference between WordPress and Microsoft Word.
Expecting them to know that starting a website with a plug and play webserver could collect sensitive information on their behalf is pushing it a bit. Expecting them to know they have to comply with a law passed by a governing body they've never come within 1k miles of...
If you're not an expert, you have to get one. Same reason why you cannot just go and plan a non-trivial building by yourself when you're not a architect or civil engineer.
I've never hired a Wumbologist because I don't know what Wumbology is or where it applies.
This attitude is really sad to me. It was and is one of the greatest things about the internet, that pretty much anyone anywhere could publish something. If you now need an "expert" to do that, we've lost something.
Anywhere you want one newline in your output, you have to use two.
And then -- what if you finally have confirmation? You were attempting to avoid it, but now you cannot. If your attempt is to avoid it at all costs, you're effectively required to validate whether users are EU citizens much earlier in the process than before GDPR, which means GDPR already has had a big impact despite efforts to avoid its umbrella.
UK is not part of the EU.
> assign personal liability
Citation needed? If CEO decides to ignore privacy law, everyone else is accountable?
However, a lot of it is covered by:
1- US companies with a physical presence in the EU. They can fine that entity directly.
2- US companies will find they can't sell to EU businesses (B2B), as that means the EU company is carrying the can in terms of non-compliance.
3- The EU Member State could go via the International Courts. Or via some kind of bilateral agreement (e.g. Privacy Shield).
I expect #3 will need to egregious to really make sense.
However, I also expect a significant amount is already hovered up by #1 or #2. Certainly many of the cases that GDPR wants to target.
Additionally, the EU may cut deals with other states to bring in enforcement powers (fines).
I'm kinda hoping my pessimism becomes justified. At that point, I can then only hope that an epiphany is reached and other approaches used without resorting to large sweeping legislation (which, among many other things could include more timid and actually enforced legislation at first). However, regardless of which side of the Atlantic I look on, it seems legislators only double down when their desired effect is not achieved. They only know one direction.
1. GDPR Shield Service Overview
The Service provides a social media management tool that enables users to customize the link preview window of websites under their control on social platforms, in addition to other analytics tools to help bolster users' social media content.
...what? Is this a botched copy/paste job?
He's running a really shady business.
Edit: which wasn't even a problem to start with but if this is the route you want to go, the above is nearly fool proof and costs next to nothing.
Don't pay "thousands" for GPDR compliance work which will improve your product by providing basic privacy and security features.
Instead pay up to $79 a month for a service to block a large percentage of your traffic.
If you get a quote from an experienced data protection lawyer for GDPR compliance, this will be an order of magnitude cheaper in the long run. There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy.
No there isn't.
When the GPDR fines are 2% of revenue there isn't the incentive for lawyers to go after businesses earning less than a million a year in revenue.
That's the biggest thing from the EU's GDPR rules - what is your organization's data inventory, how does it map outside of your organization, and how are you securing PII?
If a complaint is made from someone who is an EU citizen, and another organization shows logs that they got this information from your web app or service, that will trigger an audit from the EU. Blocking access to a subset of IP ranges will do absolutely nothing to stop this, and will not stop the sharks once they have smelled blood.
In a sense, the EU has plain rules that you can protect against, unlike the FTC/FDA (for HIPPA etc) who are vague and will not disclose how you can protect your own organization.
Blocking EU visitors by IP doesn’t eliminate the need to comply with GDPR, because GDPR jurisdiction isn’t based on where the service thinks think the user is (whether from IP geocoding or another source).
If an EU resident is using a VPN, or using an IP that incorrectly geocodes to a non-EU country, or behind a private corporate network and NAT that egresses traffic in a non-EU country, GDPR still applies. Any site with more than trivial traffic will have some users with those characteristics.
Experts debate whether explicitly requiring users to confirm that they aren’t in the EU - say, a country dropdown - is even a solution. If an EU resident visitor lies, they may well still be protected by GDPR (and the EU is large enough for enforcement to matter even if a site doesn't have an EU presence).
What's your basis for this statement? If it's true, then literally everyone in the world is covered by the GDPR, because they might be from the EU and lying. That seems (a) absurd--you think an American court is going to enforce a judgment against an American company that accidentally violated the GDPR because an EU resident lied to it?--and (b) inconsistent with the statements of Facebook et al. that they will comply with the GDPR only for those subject to it.
Good question. An American court won’t enforce it, but any decent-sized entity is, for all practical purposes, subject to decisions by ECJ (and potentially by individual EU countries).
If an EU resident case is brought to ECJ, they’ll almost certainly have jurisdiction, so the question is what ECJ would rule. I wouldn’t bet my compliance strategy on the ECJ deciding that an EU resident opted out of GDPR by misstating their residency (intentionally or not). One can reasonably assume that ECJ would see requiring users to explicitly state their location as a mitigating factor, but not that it would eliminate the need to comply, nor the opportunity for EU litigation claiming the same.
Again, this is not legal advice, but I’ve actually read the GDPR and and been part of a large company working through how to comply with it.
And how do you reconcile this with Facebook's public statement that they won't comply for those not covered? They obviously make money doing stuff that the GDPR prohibits; but they're target #1 and they even have EU presence, much more exposed than our hypothetical.
Yes, the lack of assets and revenue would make it difficult to collect. Exposure could include a staff member wanting to visit an EU country, the company trying to hire an EU-based remote contractor, or trying to get credit in the US.
That said, the reasoning is simpler: even if there's literally zero interaction with or exposure to the EU, by the time a complaint gets to litigation, the company's approach to GDPR has already failed. erely being party to a case in any court (let alone losing one) isn't a trivial matter -- it means at least consulting an attorney and thinking through the implications (like perhaps not being able to obtain an EU visa). A GDPR strategy which gets to that point, and relies on the inability to collect a judgment, has failed.
Facebook - really, FANG and a handful of other name-brand, global, consumer-facing companies - differ from most businesses in 2 ways:
1. They expect litigation, complaints, and article 17 erasure requests. There's no way to avoid it, just plan around it and minimize the impact. Their goal isn't no impact, it's no catastrophic impact.
2. They have teams of attorneys analyzing the risk and benefit of every decision. If they've decided (not) to do something, it's because they've accepted that the risks are worth the benefits, not necessarily because they think it's risk-free. Even most mid-market businesses don't have that luxury.
Note also that my original comment said that experts debate whether user-submitted location is sufficient. I explicitly didn't and don't claim that there's any certainty. There's no case law at all right now, so anyone who claims certainty about edge cases is making stuff up.
What is close to certain is that IP-based geocoding (ie, what this vendor provides) doesn't eliminate anywhere near all visitors from the EU, and thus doesn't eliminate the need to consider GDPR. Perhaps they decide to also add a user-submitted location dropdown to their signup form and accept the risks I just described, or decide to do nothing else and accept the risk of litigation from EU visitors who the geocoding doesn't identify. My core point is that the geocoding service pitches "Just block EU IPs and you're done," and that's not the case at all.
I think we're past the point where HN comments are adding value, so this will be my last comment in this thread.
The Americans that you interact with--here or otherwise--are a disproportionately cosmopolitan sample, simply by the fact that they're talking to you. A lot of people in this country have no desire to do business in the EU. They have no desire to visit. Any regulatory action against them would reconfirm all their worst thoughts about "foreigners", and otherwise not change their lives. If they read what you wrote above, then they'd take away nothing, beyond maybe that your legal system is so terrible that no one knows what the laws are.
And really, does this kind of extraterritoriality feel like a good idea to you? Roughly two hundred countries exist. Can you imagine a world where each of them tried to enforce rules of similar complexity to the GDPR against every human alive (because remember, I might be a lying North Korean)? Would you comply with every country's rules? Or would you decide what set of countries mattered to you, and write the rest off as enemy territory? I'm pretty sure the answer is the latter. I expect that many Americans will do the same here, and that their set will not include the EU.
I agree with the high-level goals of the GDPR, and with increased privacy regulation in general. I'm disturbed to see how quickly people will take the position that "every website is subject to the laws of every country" when it serves an end goal they agree with. Do you think the UK could export its super-injunctions (court orders enforcing censorship) by the same mechanism? If not, on what legal basis?
I understand that you don't intend to comment further. I'm interested to discuss with anyone who thinks this kind of extraterritoriality is a good idea, and to understand what countries and what laws you think this should extend to.
Lying does not necessarily waive rights. E.g. purgery does not waive 5th amendment rights. Hence "may well still". If you know this _not_ to be case here, do share.
> If it's true, then literally everyone in the world is covered by the GDPR
You mean GDPR is a massive overreach where one organization is trying to regulate effectively the entire internet? Yeah, that about sums it up.
1. To within some threshold of certainty, it is not yet possible to determine whether blocking EU visitors by IP, asking the remainder if they are subject to the GDPR, and blocking them if they say yes complies.
2. To within that same threshold, I can determine that some other plan (e.g., whatever troydavis is implementing) complies.
For anyone who thinks both of these can be true: Are you sure that you're basing those statements on the law? Or do you mean that the regulators will view (1) unfavorably and go after you, but they'll treat (2) as a good-faith effort and be nice?
The latter is probably true, but it's not the rule of law. Are you okay with that? How sure are you that all those regulators (and courts) will always behave in the way that you predict, or a way that you personally consider right?
I am disturbed by how willing most commenters are here to abandon the rule of law when it gets them something they want. Selective enforcement of regulations on business is a routine tactic of unfree states--remember the guy with the leopard-print fabric in Russia? I don't think it's a good idea to create powerful new tools for that, just because Europe--a continent that within living memory harbored some of the worst dictators of modern history--is well-governed right now.
They're selling at a whooping $79/month, a single php script that does not even check any sort of authentication or API key, and only does a dumb lookup against a GeoIP database : https://gdpr-shield.io/check.php
And this is called by this tiny javascript script https://code.gdpr-shield.io/script.js that just.. displays an overlay div when you're in the EU. Smells like scam when you're willing to sell a whole product that can be coded in 20 minutes for up to $1000 a year.
If you get a quote from an experienced data protection lawyer for GDPR compliance, GDPR Shield will be an order of magnitude cheaper in the long run. There's a real risk of getting sued / getting cease and desist letters from predatory law firms who aim to collect fees for small mistakes in your privacy policy.
You're making assumptions about how the service works, which happen to be wrong. Even if they were true, the time it takes to develop something isn't a measure of the value it provides.
What do you base that assesment on? GDPR mostly just consolidates multiple privacy laws into one.
I get that you're trying to sell your 'service', but that's just pure FUD.
What exactly could 'predatory law firms' sue you for? Not complying with the letter of the GDPR? The GDPR is for EU authorities to take action where deemed necessary - not law firms.
Total, unmitigated FUD.
It's enforced by a regulator. The fines are fines, not compensation, and the fines go to the regulator.
There's no route for a private citizen to hire a lawyer and sue.
Or are your suggesting that some patriotic legal firms would do all the legwork for free so that the government treasury would get a boost?
GDPR will give them new ammunition on a European scale.
The whole thing is FUD, although mad props to the people behind the linked service for making a play at profiting from it.
But it's irrelevant here, because the law isn't based on damages.
Stop talking nonsense. It is up to $10 million or 2% of revenue.
https://www.gdpreu.org/compliance/fines-and-penalties/
And so for most websites the fine would be significantly smaller than what lawyers typically earn to litigate.
Hence your entire "no win no fee" premise falls completely apart.
FFS, this is a maximum, not minimum.
> if they don't win (with infractions being $10 million minimum
But all of the numbers you give are the maximum possible fines. The actual fines imposed by the regulators will always bee smaller than that.
You also said:
> The citizen who filed the complaint would enlist help from a no-win-no-fee legal firm,
That's not how the fines work. They're fines, paid to the regulator. They're not compensation paid to the victim. There's no payout for no-win-no-fee solicitors, and so they're not going to get involved.
IPs may be personal data but if you don't store it there is no problem.
We could then can design a tool detecting the use of this service and notifying the user "this service doesn't care about your personal data".
(from https://community.spiceworks.com/topic/2007530-how-the-eu-ca... )
Might have to shut off access to the game for the EU.
Dammit.
Domain Name: GDPR-SHIELD.IO Registry Domain ID: D503300000096633167-LRMS Registrar WHOIS Server: Registrar URL: https://www.gandi.net/whois Updated Date: 2018-04-24T15:25:22Z Creation Date: 2018-04-24T15:25:19Z Registry Expiry Date: 2019-04-24T15:25:19Z Registrar Registration Expiration Date: Registrar: Gandi SAS Registrar IANA ID: 81 Registrar Abuse Contact Email: abuse@support.gandi.net Registrar Abuse Contact Phone: +33.170377661 Reseller: Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited Registrant Name: Nikolaus Fischer Registrant Organization: InnoWire UG (haftungsbeschrankt) Name Server: NS-86-B.GANDI.NET Name Server: NS-78-C.GANDI.NET Name Server: NS-61-A.GANDI.NET DNSSEC: unsigned URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/ >>> Last update of WHOIS database: 2018-05-04T01:38:30Z <<<
For more information on Whois status codes, please visit https://icann.org/epp
×××@@@@xxx The value for the Created field will show domain age. No serious offering was erected 1 month before open season begins. lmao.