Earlier quoted context omitted.
Last night I fired up my laptop to go shut down my side project. But I came up with a band-aid solution that might hold up for now: https://medium.com/@riantogo/gdpr-band-aid-b619d0b17e5b I don’t need email addresses any more than, say, Pinterest. But now it is one more barrier to entry for side projects. It is definitely not easy to be compliant as many here suggest.
You can collect email addresses still, so long as you have a legitimate reason to, you seek consent, you store them securely and remove them if consent is withdrawn. These are things that you should be doing anyway! Even if it's an open source side project.
GDPR: US news sites unavailable to EU users over data protection rules
281–290 of 680 posts
Re: GDPR: US news sites unavailable to EU users over data protection rules
#282Business don't comply with regulations because it is easy, but because it's needed to do business. If a service didn't had a big user base in Europe, most countries don't speak English, it may be cheaper to remove the service. The New York Times or The New Yorker that even have physical copies available in Europe work as usual. I work in a gambling company and this is our day to day business. To enter a new market me…
Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.
Except in Europe where it has done the exact opposite for telecom, especially compared to the unregulated US.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#283Earlier quoted context omitted.
So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.
Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…
From the site:
> Under the GDPR, you must appoint a DPO if:
> * you are a public authority (except for courts acting in their judicial capacity);
> * your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or
> * your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.
So as far as I can see, yes, for small companies or side projects (i.e. not a public authorities, not working with large scale monitoring of individuals, not dealing with criminal convictions) you don't need a DPO.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#284Honest hypothetical question... my website is in the US, my servers in the US, why would I care about the GDPR?
Honest hypothetical question... my file hosting website is in New Zealand, my servers are in New Zealand. Why would I care about US laws? Asking for a friend.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#285Earlier quoted context omitted.
If it’s your right to use an adblocker under the theory that you should control what requests your browser makes from your device, then which requests it makes are also your responsibility. Regardless, whether you intended to send my server a request is your problem. The fact is that you did, and that hardly gives full control of my business to whatever legal jurisdictions claim you as their subject.
Well, as it turns out, it's your problem. Like, literally :) Anyway, don't be too upset about all this. The law is not banning you from collecting my data, you just need to be explicit and informative about it so that I can decide if I am going to send a request to your servers. I'm often disturbed by the mindset that people are some business' god given a right to exploitation. It's the other way around really, that…
Only if the EU can enforce it, which they can’t. I don’t pay attention to laws from other countries that don’t apply to me and have no teeth, and I’ll ignore this one as well, until there’s some enforcement mechanism. At that point I’ll evaluate. I’d probably just block the EU though; not worth the hassle.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#286Earlier quoted context omitted.
> clear signal they don't care Or, it could mean they hadn't realised how much work it'd take to be GDPR compliant, and decided to temporarily use geographical blocking until they can be compliant.
It took them 2 years to realise that? That’s the same as not caring.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#287Earlier quoted context omitted.
So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.
Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…
"Does my organisation need a data protection officer (DPO)?"
https://ico.org.uk/for-organisations/does-my-organisation-ne...
1. Are you a public authority? (not sure what this is)
2. Do your organisation's core activities involve tracking and monitoring people's behaviour (for example on the internet, or on CCTV) on a large scale?
3. Do your organisation's core activities involve processing on a large scale 'special categories' of personal data, or large scale criminal convictions or offences data?
(By 'special categories' we mean personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, data concerning health or data about a person's sex life or sexual orientation, or genetic or biometric data where it woiuld [sic] identify a living person.)
Re: GDPR: US news sites unavailable to EU users over data protection rules
#288Earlier quoted context omitted.
Regulations tend to favor incumbents, decreasing competition, and thereby increase monopoly and creating central hubs of systemic risk. There is no free lunch with one-size-fits-all rule making. Unfortunately regulators think there is.
I was thinking about getting in to the car market but all these pesky requirements that I sell a car with airbags and seatbelts and fuel efficiency compliance are just there to protect existing incumbents.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#289Earlier quoted context omitted.
So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.
Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…
Re: GDPR: US news sites unavailable to EU users over data protection rules
#290Earlier quoted context omitted.
Not every claim on HN needs a backup. This one makes total sense to me. In this case, the article itself shows that regulation is definitely decreasing alternatives, which in turn can lead to monopolies
Glad you can tell how regulation affects a market after less than one day of being active law, and zero enforcement actions or cases suggesting how courts/regulators are going to interpret the rules.