GDPR: Block EU Visitors with Cloudflare and .htaccess
gist.github.com
gist.github.com
Also, public companies (those owned partially by the state) are exempt from GDPR...
That is why GDPR sucks, it is just another tool in almost despotic government.
Imagine e.g. a user survey on a US University which saves data not in a GDPR compliant format. Why should this very local small group website be GDPR compliant when it's almost 100% sure it's only used from the US?
OK, but now I ask myself what happens if a Europe exchange student also participates...
Because it’s the least one should do regarding privacy. When not mandated by law, doesn’t mean you don’t have to do the right thing.
Many companies that sell your data are complaining at the moment because they have to come clean about their malpractice. Don’t let them distract you from the compnies that always did the right thing and were gdpr complient before the laws were written.
1. Be upfront about what user-data you collect and how you use it.
2. Or try to find ways to not seem like a scummy, unprofessional or unreliable business partner while randomly blocking customers from your site, because you cant account for their data.
You’d think the choice be pretty fucking obvious, no?
Even for user requests the law states that the user must show that he has a valid reason to act, repeated requests just for the fun of it don't need to be honored and the user can charged for thus a behaviour.
And to be honest: Blocking access casts more doubt than being open and ask for consent.
You seem to be claiming the GDPR dictates who is allowed to sue and what evidence they must provide, and it simply does not. Go look it up, it's a "guilty until proven innocent" system, which guarantees loss to the accused, guilty or not.
E.g. from the Bavarian DPA (german doc: https://www.lda.bayern.de/media/baylda_report_07.pdf, page 151):
in the years 2015-2016 they had 173 proceedings that could involved potential fines. 52 of those resulted in fines. 34 of those fines were <1k€, 13 were <10k€.
http://money.cnn.com/2018/05/25/technology/gdpr-compliance-f...
>"The suit against Google alleges that users of the company's Android software are forced to turn over personal data to use an Android-powered mobile device.
The lawsuit alleges this "forced consent" amounts to a violation of GDPR, which guarantees individuals the right to consent when companies want to collect and process their personal data."
It most likely will become a lawsuit in the next days/weeks, yes. But just because an investigation got started doesnt necessarily mean that it'll end in an lawsuit. This is exactly was the original post was talking about. The investigator will contact the company, look at how the company processes the data and finally - if they're willfully ignoring gdpr - open an actual case.
more likely however is that the company already tried to comply and will just get a few reports of things they have to change/improve.
as google probably doesn't have interest in actually upholding gdpr, the investigators will probably soon-ish open an actual suit.
Do I _really_ need to link to all the other news companies saying the same thing? There are lawsuits started already.
The source of the news are always the four complaints by noyb.eu, just as hadrien01 pointed out earlier.
Most non-sensationalist news pointed out that the nonprofit noyb.eu was probably created in the spirit of patent trolls.
>I can't afford the legal costs to prove my innocence against a foreign government anymore than I could afford a $20 million fine. (there's no limit to how many times they can attempt to fine you, even if you are innocent every time)
This is just _one_ person/entity suing these companies (not even the government). Unless they want a default judgement against them, they have to pay lawyers to defend these suits.
They are being sued under the GDPR, the complaints linked on noyb.eu are not "misleading" they are legal documents that have been submitted to the courts. That's what a lawsuit is. It doesn't matter who initiated it or why.
I'm not a lawyer though, so I might've misunderstood the wording.
Yes, it literally does do this. Please can you point to the bit that allows anyone to sue?
> Go look it up, it's a "guilty until proven innocent" system, which guarantees loss to the accused, guilty or not.
Completely untrue. That would be incompatible with human rights and European law.
You're scared about stuff that isn't in GDPR or that cannot happen under EU law.
I think have way too of a rosy outlook on how laws are enforced in the EU much of the enforcement is contradictory to the ideals you hold in such high regard.
Charities are one of the most common targets of data protection enforcement in the EU even before the GDPR, in the UK they are collectively the sector that gets hit the most by the ICO and the picture isn’t much different on the continent and one of the main reasons for that is that they are easy targets (this does not mean they didnt do anything wrong but they are easy targets nonetheless).
Right now, GDPR is like a bet, where if you win you make a small amount of money, and if you lose you lose €20 million, and no one knows what the odds are. In a year's time, you will probably see people drift back into the European market, as we'll have a better idea what the enforcement regime will actually look like.
As a small actor, chances of getting fined in an initial grace-period where things are sorted out is literally zero.
Why do you insist in a sum of €20 million, even if the law states that the fines (if applicable) should be reasonable and take into consideration if the non-compliance was intentional, repeated and massive?
But it _is_ intentional if you block EU users you had in the past, continue to store/process/sell their collected PII without their consent and deny them a way to get information about the scope of your doing or a way to request deletion.
It's not hysteria if it's a legitimate legal threat that could destroy your ability to feed your family.
There is not "legal threat" if you are open about your business model, keep the collected PII reasonable and safe and don't sell the data without consent. Honoring requests for information or deletion is still a problem for you if you served EU users in the past if you don't delete/anonymize that data - even if you block access. If you're not open about your data processing and handling and don't ask for consent, don't blame the GDPR for a business model that can't be honest to your users.
I have been in court before, if you have not, perhaps that is why you are ignorant of the horrendous dangers this law puts on everyone.
http://money.cnn.com/2018/05/25/technology/gdpr-compliance-f...
I "believe" this law was intended to be a big hammer on the data brokers of the world, but the little fish often get the focus after the big fish are all caught. Even if they aren't the original target.
If you haven't looked up the law, you should do so. It states emphatically and clearly, you having a business presence in the EU is irrelevant to this law.
"Any woman driving anywhere in the world can be stoned to death", I'm sure there's quite a few islamic clerics dreaming of the day it happens.
The thing to see is that this law, enforced internationally, has about the same level of realism that those clerics have.
And more importantly, this is a total fiasco. I have dozens of emails from all kinds of providers telling me about updates to their privacy policies or otherwise. And there's been talk and warning for month from Wordpress plugin devs and blogs.
Can you name a single other foreign law in the past 20 years that has had this effect on US businesses?
Everything else stayed the same. Technically you can say no, if you don't mind clicking on the no button every single screenfull.
Meanwhile other businesses which takes the GDPR seriously gets a massive boost in trust and reputation.
Guess which ones are going to get meaningful new business and which ones will be deemed unreliable and untrustworthy?
The GDPR targets the very business models of companies that collect data and sell it. For this I applaud it's effects, but it's a big nasty dragnet, and innocents are likely to get hurt.
So, either you block access to your website using non-personnal data, or you probably actually are non-compliant with GDPR.
The GDPR _explicitly_ states that it's irrelevant if you want to do business there or not. It claims global authority over all nations and businesses that interact with it's "citizens", NOT "do business in the EU".
This is an unprecedented legal overreach. Just because we want the hammer brought down on the FB/Google beast, doesn't mean we should chop off our own hands to accomplish it.
This one doesn't apply, because the controller or processor is outside the union.
> This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
> the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
This one does apply, and look, it mentions services, but also...
> the monitoring of their behaviour as far as their behaviour takes place within the Union.
...this applies too. You're monitoring the behaviour of EU citizens; those people have protections.
Or am I misunderstanding how you are justifying the GDPR?
Same thing when it became clear 2 years ago that sending large amounts of opiates through the mail into Germany is not actually a problem.
So theoretically, you are allowed to sell that art, because those laws don't apply to you. In theory it should be stopped at the border, and your customer may get arrested for buying it.
In practice, you are allowed to sell that art, and nothing is stopping you.
Needless to say, Germany is crying foul ! We make rules, and don't enforce them, and others don't automatically enforce them for us ! Evil capitalist data-selling election-stealing swine !
(note, I fully support the spirit of this law, and am happy they are shutting down the data cartels abuses)
Do you think we should comply with every countries laws? What happens when they conflict? (like US free speech laws vs China, or even Britain?)