Live data from Hacker News

Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

news.ycombinator.com

51–60 of 80 posts

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#51
post #3

Earlier quoted context omitted.

Although you're right, there are alternatives to Google Analytics, you really should work on your messaging. Snark isn't necessary when someone is (seemingly) genuinely asking for help. In any case, for the OP I would also recommend to use an alternative. I don't know about Plausible Analytics but I have heard good things about Simple Analytics [1]. I'm not sure about Google Fonts. In terms of GDPR compliance, just k…

There was no snark. It was just the shortest way that I could find to convey the message that "the best way to comply with laws that govern data collection and data processing is by not collecting data and not use third-party services that collect user data in the first place . It's the same thing with the cookie-banner law, by the way. I am running a service in Europe and I can proudly say that I have no cookie bann…

Maybe we have different definitions of snark then. When I read

> How about "Don't use Google Analytics and Google Fonts"?

> Like, at all?

It reads quite snarky to me and you could have conveyed your point differently.

I don't disagree with your points and I agree that the OP should ideally not use Google Analytics, but I do think there are better ways to express this.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#52
post #46

Until you are big enough to have lawyers look over everything for you, I think the only reasonable course of action is to exclude EU nationals from your service. There are a lot of armchair HN lawyers (including in this thread) who will say "just don't track, it's easy," but what the word "track" means to a normal person and what it means to GDPR enforcement are not the same. As a market, it's not worth the risk unti…

> As a market, it's not worth the risk until it's worth the legal advice. i think that is a calculation only op can make. the european union covers over 400 million people. making some early design decisions in what data you collect, how you store it, for a lot of people is an acceptable cost to open up to such a large quantity of people. in fact, it think advising a founder that is bootstrapping their business that…

> making some early design decisions in what data you collect, how you store it

This is exactly the kind of thing I'm talking about. "How you store it" very well may include "on any cloud server owned by a US company," including AWS, Google, and Azure. That's a pretty big issue for a solo founder with no legal advice beyond GDPR wishcasting on HN.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#54
post #46

Until you are big enough to have lawyers look over everything for you, I think the only reasonable course of action is to exclude EU nationals from your service. There are a lot of armchair HN lawyers (including in this thread) who will say "just don't track, it's easy," but what the word "track" means to a normal person and what it means to GDPR enforcement are not the same. As a market, it's not worth the risk unti…

> As a market, it's not worth the risk until it's worth the legal advice. i think that is a calculation only op can make. the european union covers over 400 million people. making some early design decisions in what data you collect, how you store it, for a lot of people is an acceptable cost to open up to such a large quantity of people. in fact, it think advising a founder that is bootstrapping their business that…

Design decisions don’t make you compliant, you have to hire experts whose job is to convince regulators you are remaining compliant over time.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#55
post #2

How about "Don't use Google Analytics and Google Fonts"? Like, at all ? There are self-hosted alternatives. Plausible Analytics is good. Find web fonts that you can host yourself. Not only you will reduce your risk exposure, you'll see that it is not that difficult to get rid of Google. Your users, European or not, will thank you later.

No, alternatives like you suggest increase your risk exposure. You don't want to self host this stuff from a risk POV. Your risk-based choices are to not collect it at all, or to use tier 1 services like GA.

Users don't actually care.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#56
post #22

Court rulings in the EU have found that US law is not compatible with GDPR: US lets law enforcement have unfettered access to the data of EU residents, with no restrictions or redress mechanisms that satisfy the EU court. This means that sending data from the EU to a US company is almost always a GDPR violation. There are a few nuances to this which are very important. - The US CLOUD Act gives US law enforcement acce…

> sending data from the EU to a US company

1. not data. Personal Data. of course if you know you know, but threads like these are rife with non informed readers.

2. nothing to do with the geo residency of the company. it's about sending the data to the US (or most non-EU countries). Even an EU company can't send the data to the US absent various agreements.

3.You are way overstating the violation part. It's very easy to be able to send the data and be compliant.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#58
post #57

Earlier quoted context omitted.

Could you elaborate?

You don't need to hire a separate person as DOO. It's recommended but not mandatory.

Every single official guidance on GDPR that I have seen, such as https://ico.org.uk/for-organisations/guide-to-dp/guide-to-th..., states that I would have conflict of interest serving as DPO because "Basically this means the DPO cannot hold a position within your organization that leads him or her to determine the purposes and the means of the processing of personal data."

The same document specifically points out that as I head marketing, I cannot also the the DPO.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#59
post #2

How about "Don't use Google Analytics and Google Fonts"? Like, at all ? There are self-hosted alternatives. Plausible Analytics is good. Find web fonts that you can host yourself. Not only you will reduce your risk exposure, you'll see that it is not that difficult to get rid of Google. Your users, European or not, will thank you later.

No, alternatives like you suggest increase your risk exposure. You don't want to self host this stuff from a risk POV. Your risk-based choices are to not collect it at all, or to use tier 1 services like GA. Users don't actually care.

> increase your risk exposure.

How? https://plausible.io/data-policy.

OP already said he is hosting the servers in the EU, so he is in the same situation as plausible's SaaS offering.

Re: Ask HN: GDPR in 2022 – What do I need to know as a solo founder?

#60
post #50

As a small, bootstrapped one person startup, the part of GDPR that seems impossible for me to comply with (I am not lawyer nor am I European, so maybe I am wrong, but everything I have read about it indicates I am right) is the appointment of a Data Protection Officer. I do the duties of the DPO myself, but from what I have read, this is not in compliance with GDPR, which requires the DPO to be "independent". See htt…

That link is about the DPO at EU institutions and bodies. It doesn't apply to your one person startup unless you meet the criteria for needing a DPO. The UK ICO describes when a company does and doesn't need a DPO, at least with the UK implementation of the GDPR: https://ico.org.uk/for-organisations/guide-to-data-protectio... The first question it addresses is "Do we need to appoint a Data Protection Officer?", for w…

The very document you link to does not say exactly when you have to hire a DPO or not, but it and other documents I have read seem to indicate that if my business is collecting personally information order to provide my service, I need a DPO. There is some question as to scale, but no where is that defined in anything approaching concrete terms. If I have 5 customers and all 5 of them have given me their name, email, and a brief biography that I store for the purposes of providing a my service- at least one guidance document from the the EU states that scale is relative to the size for the business, so I would need a DPO in this case. What about 50, or 500, or 5000? Any number I would pick is arbitrary. What if I collect birthdates or other information that is essentail to my service?

Its easy to say "I'm small and don't need a DPO"... but the law is nothing close to clear on this issue.

And the guidance clearly states that I cannot be the DPO while also holding all the other positions in the company.

"Basically this means the DPO cannot hold a position within your organization that leads him or her to determine the purposes and the means of the processing of personal data."

Post reply on HN