Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

161–170 of 710 posts

Re: How GDPR Will Change The Way You Develop

#161
post #157
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

[deleted]

Re: How GDPR Will Change The Way You Develop

#162
post #105

Earlier quoted context omitted.

> Then that part is worthless GDPR requires that the use cases be itemized, and the user can opt out of each one individually. So if the user opts out of receiving a mailing but not the store locator, you have to manage how much data you collect about that person. I agree that for the most part this will just be another click-through like the cookie law was, but companies will be required to accommodate those minorit…

Up to 4% or €20 million, whichever is greater .

[deleted]

Re: How GDPR Will Change The Way You Develop

#163
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

Arrest when you have a layover in the EU for some reason, on purpose or because of an emergency. And a default judgement.

Not a chance. The only country that has a history of such actions is the United States.

Re: How GDPR Will Change The Way You Develop

#164
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

Explicitly banning Eurozone citizens from using the service is the easiest solution I have thought of.

Re: How GDPR Will Change The Way You Develop

#165
Will the GDPR eventually make bitcoin or other immutable public distributed databases illegal in the EU? Do you have default judgements on thousands john doe node operators around the world? Will EU ISPs be required to censor any kind of blockchain node eventually when someone has a GDPR complaint for that network? Will we arrest teenagers for running ethereum miners on their gaming computers after all of this?

Re: How GDPR Will Change The Way You Develop

#166
post #81

Earlier quoted context omitted.

I thought that was needlessly snarky. I'm pretty sure other fields rely on lawyers to know the relevant legal landscape just like we do.

No. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.

[deleted]

Re: How GDPR Will Change The Way You Develop

#167
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

If you have a customer from the EU, you must comply with GPDR. Full stop.

Also, if any component of your cloud ecosystem(AWS, GCS, etc.) are based in the EU, you must comply with GPDR. Which in today's world means almost everyone is affected by this.

Make sure those "American" platforms you speak have every single component of their infrastructure based physically in America.

The whole thing may be difficult to enforce, but meh why risk it?

Re: How GDPR Will Change The Way You Develop

#168

Earlier quoted context omitted.

For the same reason that downloading a song is different than stealing with a CD. Digital stuff is innately different. You aren't doing business unless you're accepting payments/selling/shipping things to people in the EU. And as with any law, if you're sufficiently small fry the EU isn't going to care about you until you actually screw up. Don't accept euros as currency. Don't offer to ship to EU nations. Done. If y…

> You aren't doing business unless you're accepting payments/selling/shipping things to people in the EU. I wonder how ads play into all this. E.g. are people who watch an ad on YouTube considered YouTube customers? Are they considered customers of the ad company? My concern is that we will see more (non-EU) companies implement something where users "pay" for services/features by watching ads. I do also wonder how it…

The simple answer to that is that the advertisers pay you to show ads to EU users because they want to get money from EU users; so these advertisers are/have to be GDPR compliant, especially if they're using user information to target ads, and they'll have to be sure that this user information is legal for them to use.

The advertising networks are clearly doing business in EU as they're getting paid by these advertisers - so all the major advertising networks will have to be GDPR compliant. So in this regard, the ads (and user info used for these ads) shown to EU users will (in practice) have to be GDPR compliant even if your site doesn't care about it, because everyone who'd want to pay for these ads has to be compliant.

Re: How GDPR Will Change The Way You Develop

#169
post #79
post #41

Earlier quoted context omitted.

Everyone is freaking out. If GDPR is a success Americans may want it too. The same happened with Steam refunds.

But that is good, right?

For consumers yes. But I understand that Facebook might not like it since it goes against their business case.

Re: How GDPR Will Change The Way You Develop

#170
post #15

Earlier quoted context omitted.

If a business decides to opt-out of doing business with the EU as a result, what measures do they need to take? Would a banner asking "Are you an EU citizen? Yes/No" suffice? Or would we have to use some kind of Geo IP tool? How would that defend against EU citizens using a VPN or Tor, and what would a business's liability be in that case?

Not all organisations will need to be compliant with GDPR. By that I mean, if your organisation only do marketing in, for example, the US and Canada, only accepts USD/CAD and they are no legitimate appearance that you do/want to do business in Europe, you are not required to be GDPR compliant, even if an european customer goes on your website and purchases a product/service. If your website accepts Euros, has multipl…

Not quite. GDPR applies to you, a US entity, if you do business with an EU citizen trading in dollars living in the US.
Post reply on HN