Live data from Hacker News

Ask HN: How do you GDPR for your small side projects?

news.ycombinator.com

31–40 of 54 posts

Re: Ask HN: How do you GDPR for your small side projects?

#31
post #9

Earlier quoted context omitted.

The goal of GDPR is compliance not punishment. So long as you are eventually following the rules it’s all ok.

Yes, compliance is the goal. However, the rules are vague enough to be interpreted in other ways as well. If some authority decides to make an example of pesky local startups for whatever reason there is little that prevents them from doing so. Remember, both the actual implementation and the enforcement of the regulation lies with the EU member countries, which even might decide to further devolve that responsibilit…

Give me an example of an overly vague rule.

Re: Ask HN: How do you GDPR for your small side projects?

#32

Earlier quoted context omitted.

It's my understanding that an IP address is not personal info and that nobody can, say, make a GDPR request for information associated with an IP address. An IP address is not personally identifiable information.

Under GDPR's definition and recitals, IP addresses are most definitely personal data.

Only if linkable to other personal information. If your logs are collecting IP data that cannot be linked by you to a person you're fine.

Re: Ask HN: How do you GDPR for your small side projects?

#33

Earlier quoted context omitted.

Oh to have this problem. Let me guess, your side project is multi-cloud replicated, CDN fronted, data center backed?

This has nothing to do with over-engineered infrastructure. As soon as your side project processes and / or stores user data GDPR applies to you. Good luck with providing the requisite documentation and data processing agreements if authorities ask for them and you didn’t prepare those in time.

You live in EU? Sure. You live in US? Nope, it does not apply. There's no nexus. EU can go and pound sand.

Re: Ask HN: How do you GDPR for your small side projects?

#34

Earlier quoted context omitted.

This has nothing to do with over-engineered infrastructure. As soon as your side project processes and / or stores user data GDPR applies to you. Good luck with providing the requisite documentation and data processing agreements if authorities ask for them and you didn’t prepare those in time.

You live in EU? Sure. You live in US? Nope, it does not apply. There's no nexus. EU can go and pound sand.

That's not correct. As soon as you want to do business with someone currently located in the EU (doesn't even have to be an EU citizen), GDPR applies, no matter where your company is located.

Re: Ask HN: How do you GDPR for your small side projects?

#35
post #8

Earlier quoted context omitted.

While I understand the sentiment this might be risky. Creating the required documentation after the fact should your project take off might not be possible in every case.

I wouldn’t bother about documentation, but I would bother about thinking about the basics: do I need all this personal information? On what legitame basis am I collecting it? Am I storing it safely? Do I explain to people clearly how I’m using it, how they can see it, amend it or delete it? Get the basics down, the documentation can follow. Get the basics wrong and it becomes painful.

I agree in that the major benefit of GDPR for small companies is that you have to review and perhaps revise your processes accordingly.

However, the documentation still is required. You can create some of that later or just in case you're requested to do so but as soon as third parties (i.e. data processors) are involved that might not be possible anymore.

At the very least you'll be very busy for a few days because such requests by relevant authorities will come attached with a somewhat tight deadline ("Please supply these documents within 2 weeks or else ...").

Re: Ask HN: How do you GDPR for your small side projects?

#36

Earlier quoted context omitted.

You live in EU? Sure. You live in US? Nope, it does not apply. There's no nexus. EU can go and pound sand.

That's not correct. As soon as you want to do business with someone currently located in the EU (doesn't even have to be an EU citizen), GDPR applies, no matter where your company is located.

EU can write any law it wants. It cannot enforce it on anyone who is not have a nexus to EU.

Any hobby that gets to a point of making money in EU gets a nexus. Everything else is a FUD. Facebook, Google, Apple, etc all have nexus which is why it is applicable to them. JoeSchmoeLLC from Delaware does not.

Re: Ask HN: How do you GDPR for your small side projects?

#37

Earlier quoted context omitted.

Yes, compliance is the goal. However, the rules are vague enough to be interpreted in other ways as well. If some authority decides to make an example of pesky local startups for whatever reason there is little that prevents them from doing so. Remember, both the actual implementation and the enforcement of the regulation lies with the EU member countries, which even might decide to further devolve that responsibilit…

Give me an example of an overly vague rule.

GDPR requires companies to use “state-of-the-art measures” to protect personal data, which is intentionally vague because the state of the art obviously changes over time.

However, who will decide what the state of the art actually is at any given time? Politicians, lawyers, competitors, actual IT experts? The latter don’t commonly work for either EU or local authorities.

Because the laws are implemented by each EU member state that state of the art might even differ depending on whether you’re located in, say, France or Germany.

Re: Ask HN: How do you GDPR for your small side projects?

#38
Can someone clarify what exactly is the legal liability that comes from GDPR?

My very basic understanding is that countries set up SAs (supervisory authorities) to deal with complaints, and have the legal power to sanction and so forth.

So is it only the SA that can take action against you? If someone wanted to harass you, must they complain through the SA, or can they bring a civil suit based on the GDPR?

Re: Ask HN: How do you GDPR for your small side projects?

#40

Earlier quoted context omitted.

That's not correct. As soon as you want to do business with someone currently located in the EU (doesn't even have to be an EU citizen), GDPR applies, no matter where your company is located.

EU can write any law it wants. It cannot enforce it on anyone who is not have a nexus to EU. Any hobby that gets to a point of making money in EU gets a nexus. Everything else is a FUD. Facebook, Google, Apple, etc all have nexus which is why it is applicable to them. JoeSchmoeLLC from Delaware does not.

Just because something isn't easily enforceable it doesn't become legal or ethical.

A small company absolutely can get by with shoebox accounting, too, it's just not particularly advisable to do so.

The same applies to completely ignoring GDPR, whether it's enforceable or not.

Post reply on HN