Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

201–210 of 710 posts

Re: How GDPR Will Change The Way You Develop

#201
post #164

Earlier quoted context omitted.

Explicitly banning Eurozone citizens from using the service is the easiest solution I have thought of.

The collective economic effect of that will be massive. Please do. And realize that you are ceding the single largest market to your competition.

> single largest market

The EU really isn't a single large market though for most practical purposes. For the purposes of complying with regulations and accepting payment it is, but for every other practical consideration that matters to a company doing business there, it's a few dozen separate markets.

Re: How GDPR Will Change The Way You Develop

#202
post #86
post #17

I will show you another case, company that isnt "bitching" over laws that are good for all humans not just EU and does the right thing, you know backblaze, right? "The changes that are being made by companies such as Backblaze to comply with GDPR will almost certainly apply to customers from all countries. And that’s a good thing. The protections afforded to EU citizens by GDPR are something all users of our service…

So nice to see progress in privacy but please someone explains how GDPR will help EU startups! GDPR is inevitably going to hinder any new company forced to abide by it. So the next Uber/Wechat will first flourish in US/China/Russia and then come to the EU, not the other way around. Entrepreneurs / investors also want their time & money to be used to build value first rather than solve yet another accidental complexit…

Let's say you're a business in the EU that needs a sales management system. In it, you store personal data of your clients. You are considered a "controller"; the SaaS sales management system (that will store this data for you) is considered a "processor."

GDPR states that to remain compliant, Controllers must only use GDPR-compliant Processors.[1]

Assuming that EU startups will take GDPR more seriously than non-EU companies (a safe assumption judging from the posts here on HN), non-tech EU companies (Controllers) will tend to gravitate towards EU tech companies (Processors) to ensure they remain compliant.

It is non-EU (primarily US) tech companies' game to lose. If US tech companies get a reputation for not caring about GDPR, there could be a real sea-change in EU buying behavior.

[1] Article 28, paragraph 1: "Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."

Re: How GDPR Will Change The Way You Develop

#203

Earlier quoted context omitted.

In the typical web/e-commerce context someone whose IP address geolocates to an EU based end point or someone who lists their delivery address as inside the union.

The problem is that the law applies to them even if they use a proxy. If they report/sue you afterwards, you might be looking at a huge amount of trouble.

Yes, but like with all this stuff: Your intent to comply with the law carries a lot more weight than actual compliance in edge cases.

Re: How GDPR Will Change The Way You Develop

#204
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

No one is forcing you to follow it, but I suspect this is just the begining, GDPR is comming from EU due to history reasons, Europe has a lot of bad memories about keeping lists and tracking users. From Nazis to Stasi, USSR and so on and on. What is today done by google, fb, twitter is a light years ahead of that. Try to understand that GDPR is not something bad, it is rasing credibility for your bussiness and is doing something right. I bet a lot of, lets say, USA cityzens will value text "we are GDPR compliant for whole world" on web site. It is oportunity that Backblaze grabbed and soon sites that don't follow it will be on fishy side of the internet. And I also believe, a lot of non EU contries will adapt similar laws, the attack on privacy has gone too far, don't blame EU, blame ggl and fb.

Re: How GDPR Will Change The Way You Develop

#205
I have been through a number of GDPR resources and seminars and I am still of the opinion that there is nothing in it to worry people who are acting in good faith with their customers data. The organisations fined under existing laws seem to have been breathtakingly negligent or just deliberately callous.

Re: How GDPR Will Change The Way You Develop

#206
While this article is interesting, I strongly encourage anyone - from CEOs, to managers, to individual developers - to actually read the text of the GDPR.

This is not written in unintelligible legal-ese. It is very approachable, understandable by a layman, and organized such that relevant Articles are easy to find.

It might take an hour or two, yet may have a fundamental impact on how you approach your job for the foreseeable future. Time very well spent.

Here is an accessible version of it: https://gdpr-info.eu/

EDIT: for clarity, that site is accessible from an organizational point of view (i.e., broken out by articles, not one long string of text). I do not know if it is accessible by screen readers or alternate input devices.

Re: How GDPR Will Change The Way You Develop

#207

Earlier quoted context omitted.

I suspect it will be the norm. For any greenfield development, why would we develop it twice? We have to solve every business problem we have for the EU; why would we solve it differently, to address the same problems, elsewhere? For non-greenfield development, why would we keep two codebases and sets of infrastructure around that we have to support? Better to consolidate. Especially given the positive word of mouth…

And remember that GDPR applies to EU citizens outside the EU too, so you’d need to confirm with the user upfront that they aren’t an EU citizen before capturing the information.

I don't think it does.

"This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union..."

(Ch 1, art 3, para 2)

Re: How GDPR Will Change The Way You Develop

#208
post #170

Earlier quoted context omitted.

Not all organisations will need to be compliant with GDPR. By that I mean, if your organisation only do marketing in, for example, the US and Canada, only accepts USD/CAD and they are no legitimate appearance that you do/want to do business in Europe, you are not required to be GDPR compliant, even if an european customer goes on your website and purchases a product/service. If your website accepts Euros, has multipl…

Not quite. GDPR applies to you, a US entity, if you do business with an EU citizen trading in dollars living in the US.

"[...]Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."

Quote from GDPR, page 5, recital 23 (http://www.privacy-regulation.eu/en/recital-23-GDPR.htm). I'm no lawyer, but that's the way I'm understanding it.

Re: How GDPR Will Change The Way You Develop

#210
Funnily, one of the common fears our clients (https://gdpr-tools.eu) have with regards to GDPR is not about the general public. It comes from disgruntled employees ratting on the company.

Employees know best where personal data is stored (and often no one else in the company does), so they can really do some surgical damage by reporting their employer to the "authorities". GDPR introduces a whole new dynamic.

Post reply on HN