Earlier quoted context omitted.
The goal of GDPR is compliance not punishment. So long as you are eventually following the rules it’s all ok.
Yes, compliance is the goal. However, the rules are vague enough to be interpreted in other ways as well. If some authority decides to make an example of pesky local startups for whatever reason there is little that prevents them from doing so. Remember, both the actual implementation and the enforcement of the regulation lies with the EU member countries, which even might decide to further devolve that responsibilit…
Ask HN: How do you GDPR for your small side projects?
31–40 of 54 posts
Re: Ask HN: How do you GDPR for your small side projects?
#32Earlier quoted context omitted.
It's my understanding that an IP address is not personal info and that nobody can, say, make a GDPR request for information associated with an IP address. An IP address is not personally identifiable information.
Under GDPR's definition and recitals, IP addresses are most definitely personal data.
Re: Ask HN: How do you GDPR for your small side projects?
#33Earlier quoted context omitted.
Oh to have this problem. Let me guess, your side project is multi-cloud replicated, CDN fronted, data center backed?
This has nothing to do with over-engineered infrastructure. As soon as your side project processes and / or stores user data GDPR applies to you. Good luck with providing the requisite documentation and data processing agreements if authorities ask for them and you didn’t prepare those in time.
Re: Ask HN: How do you GDPR for your small side projects?
#34Earlier quoted context omitted.
This has nothing to do with over-engineered infrastructure. As soon as your side project processes and / or stores user data GDPR applies to you. Good luck with providing the requisite documentation and data processing agreements if authorities ask for them and you didn’t prepare those in time.
You live in EU? Sure. You live in US? Nope, it does not apply. There's no nexus. EU can go and pound sand.
Re: Ask HN: How do you GDPR for your small side projects?
#35Earlier quoted context omitted.
While I understand the sentiment this might be risky. Creating the required documentation after the fact should your project take off might not be possible in every case.
I wouldn’t bother about documentation, but I would bother about thinking about the basics: do I need all this personal information? On what legitame basis am I collecting it? Am I storing it safely? Do I explain to people clearly how I’m using it, how they can see it, amend it or delete it? Get the basics down, the documentation can follow. Get the basics wrong and it becomes painful.
However, the documentation still is required. You can create some of that later or just in case you're requested to do so but as soon as third parties (i.e. data processors) are involved that might not be possible anymore.
At the very least you'll be very busy for a few days because such requests by relevant authorities will come attached with a somewhat tight deadline ("Please supply these documents within 2 weeks or else ...").
Re: Ask HN: How do you GDPR for your small side projects?
#36Earlier quoted context omitted.
You live in EU? Sure. You live in US? Nope, it does not apply. There's no nexus. EU can go and pound sand.
That's not correct. As soon as you want to do business with someone currently located in the EU (doesn't even have to be an EU citizen), GDPR applies, no matter where your company is located.
Any hobby that gets to a point of making money in EU gets a nexus. Everything else is a FUD. Facebook, Google, Apple, etc all have nexus which is why it is applicable to them. JoeSchmoeLLC from Delaware does not.
Re: Ask HN: How do you GDPR for your small side projects?
#37Earlier quoted context omitted.
Yes, compliance is the goal. However, the rules are vague enough to be interpreted in other ways as well. If some authority decides to make an example of pesky local startups for whatever reason there is little that prevents them from doing so. Remember, both the actual implementation and the enforcement of the regulation lies with the EU member countries, which even might decide to further devolve that responsibilit…
Give me an example of an overly vague rule.
However, who will decide what the state of the art actually is at any given time? Politicians, lawyers, competitors, actual IT experts? The latter don’t commonly work for either EU or local authorities.
Because the laws are implemented by each EU member state that state of the art might even differ depending on whether you’re located in, say, France or Germany.
Re: Ask HN: How do you GDPR for your small side projects?
#38My very basic understanding is that countries set up SAs (supervisory authorities) to deal with complaints, and have the legal power to sanction and so forth.
So is it only the SA that can take action against you? If someone wanted to harass you, must they complain through the SA, or can they bring a civil suit based on the GDPR?
Re: Ask HN: How do you GDPR for your small side projects?
#39Re: Ask HN: How do you GDPR for your small side projects?
#40Earlier quoted context omitted.
That's not correct. As soon as you want to do business with someone currently located in the EU (doesn't even have to be an EU citizen), GDPR applies, no matter where your company is located.
EU can write any law it wants. It cannot enforce it on anyone who is not have a nexus to EU. Any hobby that gets to a point of making money in EU gets a nexus. Everything else is a FUD. Facebook, Google, Apple, etc all have nexus which is why it is applicable to them. JoeSchmoeLLC from Delaware does not.
A small company absolutely can get by with shoebox accounting, too, it's just not particularly advisable to do so.
The same applies to completely ignoring GDPR, whether it's enforceable or not.