Hacker News new | ask | show | jobs
by mandevil 8 days ago
This would be true if they were working from a baremetal Apache server. But they seem to be using a vendor, Cloudflare, for their CDN. And so I strongly suspect that they used their existing Cloudflare account to do it. Just type the countries you want to block into a field in the Cloudflare UI and you're done. I've used that UI myself (not for GPDR reasons but for compliance with my countries sanctions). Significantly easier than controlling the cookies and data retention and getting an audit to certify compliance, which I've also done.
1 comments

You don't need to get an Audit for Compliance with GDPR.

Whoever told you that was scamming you

When you don't know what you're talking about, an option you always have is to be silent. I suggest that you exercise that option next time.

At the time I was doing this, it was part of a very large company that quarterly ran audits of all their own systems for security and legal compliance, and they did GPDR as one of their things to audit against.

So we were not scammed, we had our internal employees do their job.