I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.
Consider this case, startup app in a niche market, only available on US app stores, and a one man dev team that needs to focus on app dev not compliance for some regulation that could never apply to their customers. Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list. That’s the startup I’m presently working on. We’ll expand beyond the US borders…
Do you inform your users what data you're collecting, why you're collecting it, and get their consent? Are you taking proper precautions with the expanded PII data (encrypting at rest for example)? You've basically covered the requirements.
> Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list.
What kind of FUD are people reading...if someone voluntarily gives you their email to sign up for a list that's fine. You just need to keep that they consented to receive what they agreed to. What you can't do is use that email for crap they didn't sign up to receive. Obviously normal unbsub rules apply, which in this case says forget that someone ever signed up.