GDPR protection for the uninformed

GDPR protection for the uninformed

This morning I stumbled upon this beauty in a Reddit post: GDPR shield. User Greatbytes, whom I suspect to be the owner, advertises the GDPR shield 'solution' as follows:

"While I love the EU's new data privacy regulation from a user's perspective, it's a nightmare for businesses to achieve compliance, because of the (sometimes intentionally) vague language of the law. And even if you pay an experienced lawyer to draft the policies and procedures required by GDPR, there's a very real residual risk of predatory law firms collecting penalties from mass-mailed cease-and-desist letters based on technicalities. Even if your business isn't located within the EU, you are required to comply with GDPR because the location of the user matters.

I've built a tool that blocks users who are trying to access your website from within the EU as a short-cut to compliance, which makes sense if your business isn't reliant on EU users and you don't want to spend thousands in legal fees to achieve GDPR compliance."

This scam, for that's what it is, preys on the fear, uncertainty and doubt that the GDPR instills in people that trust hearsay instead of their own intelligence. The GDPR is not aimed at websites that accidentally attract people from the EU, but at organisations explicitly targeting their activities to EU territory. And I suspect the German owner of the GDPR Shield website, a learned Doctor from Düsseldorf, knows this very well, considering the first paragraph on the site contains the following sentence:

If you aren't targeting EU users, simply use GDPR Shield to block all traffic from the EU.

The simple fact is, that if you aren't targeting EU users, you don't need GDPR Shield. And if you are, you don't want GDPR Shield. GDPR Shield is a solution to a problem nobody has. Plans start at $9 a month.


Richard Kranendonk的更多文章

  • Finding Hidden Risks

    Finding Hidden Risks

    Work processes are full of hidden risks, that only come to the attention of the CISO or DPO in case of incidents or…

  • Compliance requires knowledge of IT

    Compliance requires knowledge of IT

    You’ve probably never heard of them, but chances are Spanish service provider Prestige Software has exposed your…

    2 条评论
  • AP: We Gaan De Cowboys Aanpakken!

    AP: We Gaan De Cowboys Aanpakken!

    In een toespraak voor het Nederlands Genootschap voor Functionarissen Gegevensbescherming heeft Munish Ramlal, Hoofd…

  • So you thought there was only one GDPR?

    So you thought there was only one GDPR?

    Before the first proposal for a new European privacy law was brought to the EC in the beginning of 2012, the intention…

  • Targeted advertising companies receive GDPR notices

    Targeted advertising companies receive GDPR notices

    French privacy authority CNIL (Commission nationale de l'informatique et des libertés) has taken aim at four companies…

  • Handhaving AVG: welke organisaties zijn als eerste aan de beurt?

    Handhaving AVG: welke organisaties zijn als eerste aan de beurt?

    De Autoriteit Persoonsgegevens (AP) geeft op haar site verschillende criteria en lijsten van verwerkingen waarvoor het…

    4 条评论
  • AVG: recht op inzage kan leiden tot datalek

    AVG: recht op inzage kan leiden tot datalek

    Als je een verzoek om inzage onterecht honoreert, veroorzaak je een datalek. Maar vraag je teveel van de indiener om…

    7 条评论
  • De AVG is bewust vaag – hoe ga je daar mee om?

    De AVG is bewust vaag – hoe ga je daar mee om?

    In het kader van de AVG hebben organisaties behoefte aan concrete richtlijnen: wat moeten we precies doen, wat mag wel,…

    1 条评论
  • Handhaving AVG: interessante uitspraken van directeur AP

    Handhaving AVG: interessante uitspraken van directeur AP

    Directeur Cecile Schut van de Autoriteit Persoonsgegevens heeft op de ledenvergadering van het Nederlands Genootschap…

    45 条评论
  • A very interesting LinkedIn scam

    A very interesting LinkedIn scam

    A couple of days ago, we got mail: "Nice website. I’m the systems manager at a company that just acquired 2 sites in…

    3 条评论

