Live data from Hacker News

Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

news.ycombinator.com

31–40 of 80 posts

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#31

Someone should build GDPR-compliance-as-a-service.

GDPR compliance is trivial if you build it from the start. Those who can comply can easily do so themselves.

The problem is that a lot of businesses (or careers) just won't be possible without breaching the GDPR, and that's not something a "compliance-as-a-service" company would fix. A honest company would tell you to close your business or severely downsize your marketing team, a dishonest one would just take your money and give you a false sense of security.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#32
post #24

Someone should build GDPR-compliance-as-a-service.

We are building one such service and I agree (to name a few services doing GDPRaaS : soveren.io, ethyca.com, securiti.ai, datagrail.com, alias.dev) .this is so much needed as there is almost no legally valid answer on the whole comment section! I started to write an article on all the points above… should get back in 2 hours and post it here

In bullet points : - GDPR is a risk management policy about personal data protection more than a privacy regulation

- for any personal data (PII) all companies must declare the following :

  - purpose of the collection and the treatment of the specific data

  — legal base of the treatment (6 available, they are the field card in Magic the gathering, they define a context of what is possible to do)

  - data category (what type of data you are collecting i.e if you declare collecting delivery shipping information for a purpose, you limit yourself to data that correspond to that category )

  - data retention duration (how long you declare storing the data in production and then in archive)

  - list of recipients (all the 3rd party companies who will access the data)

  - security measures (what is the level of security for keeping that data safe from breaches)

  - some infos about the company, the data controller (who is responsible) etc…
So all companies must do a internal data mapping to know and declare where is the data and where it flows in production and write for every PII a ROPA (record of processing activity) You can find an open source specification UROPA here)

https://github.com/uropa-project/uropa

- consent is just one of the 6 legal bases to collect and treat data. The comment above that everything is possible with consent is wrong.

- below 250 employees you don’t need officially a DPO

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#33
Until you are big enough to have lawyers look over everything for you, I think the only reasonable course of action is to exclude EU nationals from your service. There are a lot of armchair HN lawyers (including in this thread) who will say "just don't track, it's easy," but what the word "track" means to a normal person and what it means to GDPR enforcement are not the same. As a market, it's not worth the risk until it's worth the legal advice.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#34
post #23

I looked into this issue over the last weeks and made a list of other solo founders and how they handle it. You can find many, many of them when you search Twitter for "buildinpublic". The sad truth is that most successful solo founders these days: 1) Make it very hard to figure out where the service they provide is located. 2) When you find out, it is usually registered in a country outside of the EU. Crunchbase oft…

I‘m pretty sure that’s not accurate. Not sure where they scraped that from but I think I remember it being incorporated in Singapore. Which makes a lot more sense if you follow where Pieter is usually located.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#35
post #6

Got a relevant question myself: What bothers me the most for solo founders with GDPR is that you can't analyse individual user journeys without some kind of consent. I don't care who you are, but I care how you use my product so I can improve it. Aggregated / backend analytics will give me only the most basic insights. Am I right in that? Is it possible to work around that? I don't track to sell or analyse personal d…

So ask your users for consent. It really is that simple.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#36
post #3

Earlier quoted context omitted.

Although you're right, there are alternatives to Google Analytics, you really should work on your messaging. Snark isn't necessary when someone is (seemingly) genuinely asking for help. In any case, for the OP I would also recommend to use an alternative. I don't know about Plausible Analytics but I have heard good things about Simple Analytics [1]. I'm not sure about Google Fonts. In terms of GDPR compliance, just k…

There was no snark. It was just the shortest way that I could find to convey the message that "the best way to comply with laws that govern data collection and data processing is by not collecting data and not use third-party services that collect user data in the first place . It's the same thing with the cookie-banner law, by the way. I am running a service in Europe and I can proudly say that I have no cookie bann…

> I am running a service in Europe and I can proudly say that I have no cookie banner on my site. You know why? Because I don't have any tracking cookies on my site in the first place.

Exactly! I do the same thing and as strange as it might sound: I'm also proud on the fact that I don't serve cookie banners. As in, literally experiencing the feeling of pride for something others might find banal and innocent.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#37
post #34
post #23

I looked into this issue over the last weeks and made a list of other solo founders and how they handle it. You can find many, many of them when you search Twitter for "buildinpublic". The sad truth is that most successful solo founders these days: 1) Make it very hard to figure out where the service they provide is located. 2) When you find out, it is usually registered in a country outside of the EU. Crunchbase oft…

I‘m pretty sure that’s not accurate. Not sure where they scraped that from but I think I remember it being incorporated in Singapore. Which makes a lot more sense if you follow where Pieter is usually located.

Do you confuse Nomadlist with RemoteOK?

RemoteOK is in Singapore.

I added it to the comment now.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#38

If I was starting a startup today. I'd probably just block Europe and focus on other markets initially. Loop back on Europe once you have product market fit and the resources to deal with GDPR.

you'd have to block california too because CCPA is essentially the same thing

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#39
post #28

As a small, bootstrapped one person startup, the part of GDPR that seems impossible for me to comply with (I am not lawyer nor am I European, so maybe I am wrong, but everything I have read about it indicates I am right) is the appointment of a Data Protection Officer. I do the duties of the DPO myself, but from what I have read, this is not in compliance with GDPR, which requires the DPO to be "independent". See htt…

No, that's not true at all.

Could you elaborate?
Post reply on HN