←back to thread

341 points hlandau | 1 comments | | HN request time: 0.226s | source
Show context
manxman ◴[] No.37963542[source]
A quick warning on hetzner. I needed a personal bare metal machine so signed up.

I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server?

Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email containing the same.

I refused reminding them of GDPR and that email is at best opportunistically encrypted and at worst open to interception.

They replied stating they believed they were GDPR compliant because all they do is use the passport to verify the account and delete the document. They also said I could hide anything sensitive other than my name and date of birth!!

I suggested the process is not GDPR compliant as anyone could intercept unencrypted emails and that they should talk to a lawyer if they did not believe my assertion.

Within a short time the server was approved and online. I queried if they would revise their process in light of our interaction. They did not address the question.

replies(8): >>37963761 #>>37964297 #>>37964364 #>>37964823 #>>37965391 #>>37968710 #>>37970183 #>>37974389 #
1. chatmasta ◴[] No.37968710[source]
I absolutely hate any process that requires uploading my passport or other identity documents. I always redact as much as possible and then cover the photo with red text saying "FOR $BUSINESS IDENTITY VERIFICATION ONLY." Sometimes they push back on it, but usually it's acceptable. The worst is when their automated system rejects it.