Live data from Hacker News

Ask HN: How is GDPR affecting your business?

news.ycombinator.com

31–40 of 66 posts

Re: Ask HN: How is GDPR affecting your business?

#31
The only recent change for me was that I entered into a DPA with the bookkeeper and the payroll company everything else was already done (and long ago, not last week).

It helps that collecting data on individuals was never a part of our strategy to begin with.

Re: Ask HN: How is GDPR affecting your business?

#32
We've gone through a couple of audits from customers' GDPR-compliancy consultants.

As a result we have have been triggerered to perform some well-over-due security reviews, thinking about security processes and data compartmentalization, documenting some procedures etc. I think it's by far a net-good, even as relatively small company.

Re: Ask HN: How is GDPR affecting your business?

#33
post #24

My product collects limited number of personal information and in theory it has always been compliant. Only thing I have doubt about is AdSense. I have disabled personalized ads, but I have no idea if that is compliant. Also working on data portability, so users can export their data. (Never got a request for that though) If revenue from ads will go down I will be considering closing the business. I don't feel comfor…

Just curious, what does your business do?

Niche Reddit like site.

Re: Ask HN: How is GDPR affecting your business?

#35

Earlier quoted context omitted.

How does GDPR affect your business? You're not really responsible for anybody's data, presumably you inherit the policies of your customers.

First, I'm responsible for handling my clients' data, such as their email addresses or phone numbers. It doesn't matter that they're business customers rather than consumers. GDPR still applies. Secondly, though not always the case, I might have to process their respective customers' data in some way in order to do my job (by having access to a production database, for example). So, yes, GDPR absolutely does apply to…

So you're saying that you are asking consent to store the phone number and email address of a client? And you'll provide clients with the right to be forgotten, meaning that you're prepared to delete their contact information? This seems like overkill.

Re: Ask HN: How is GDPR affecting your business?

#36

I work for a major news media company and our GDPR compliance has been extremely difficult with our relatively small dev staff that manages many news outlets so we've opted to block access from all of Europe. It's gotten a lot of press, but it's an unfortunate reality. Most of our adtech and analytics vendors we use have put the burden on smaller companies like us -- ripe for disaster.

then stop using them, instapaper

Re: Ask HN: How is GDPR affecting your business?

#37

I work for a major news media company and our GDPR compliance has been extremely difficult with our relatively small dev staff that manages many news outlets so we've opted to block access from all of Europe. It's gotten a lot of press, but it's an unfortunate reality. Most of our adtech and analytics vendors we use have put the burden on smaller companies like us -- ripe for disaster.

That's an interesting way to broadcast your lack of technical/lateral thinking skills over there at latimes.com (see https://news.ycombinator.com/item?id=15604736). You could look at USA Today's way of temporarily handling this as an example of what could be done with a few hours of work.

You're saying that the GDPR is so taxing because your team is so small? Meanwhile you're recruiting data scientists to your existing team to fuck over your users' privacy even further? Come on!

This is just embarassing. Grow up. I suspect you're just upset that your role is suddenly at the risk of becoming a lot less relevant - you are worried that this attitude of government regulation of privacy aspects will actually spread so that it impacts you in a meaningfull way and you want to nip it in the bud.

Re: Ask HN: How is GDPR affecting your business?

#39
I work for an international education startup and while it was obnoxious to get the technical groundwork and auditing done: it doesn't affect the business very much. This shouldn't be too surprising; the GDPR is really only problematic to businesses who's primary purpose was identity and interest brokering. Most folks with actual products to sell aren't in such a bad spot.

Certainly, some folks have opted into some heroics getting all our microservices and datastores audited. But it's good to do that periodically anyways, so we made the audit a multi-purpose affair.

Re: Ask HN: How is GDPR affecting your business?

#40
I work for a business that designs, builds and supports learning management systems for corporate organisations. I also had the task of coordinating our GDPR readiness activities.

As we are a 'processor' for our clients, we reviewed and updated some of our existing infosec policies and procedures, and produced a very detailed set of 'GDPR' docs to satisfy customers asking for evidence of our compliance efforts, and to provide data mappings, impact and risk assessments etc. We already had most of this done internally anyway so we just needed to 'prettify' it and change the language/terms in our 'Electronic Information Security Policy' document to match the GDPR.

We also wrote up a DPIA document about our internal systems.

All of this work took time - perhaps about the equivalent of 2-3 weeks to plan, collate and draw the diagrams and workflows for things like our security incident response plan and how we would sub-process subject rights requests; like when a client receives a 'Right to erasure' request and asks for assistance.

Overall that work was not difficult and did not cause any headaches. What has been a pain has been responding to all the clients who send us various compliance 'questionnaires' (spreadsheets) expecting tailored responses - fortunately, in the main I was able to answer "see document ref xxxxxx, section nnn".

What I am seeing now is the late-arrivals throwing in (demanding) 'for compliance' every conceivable infosec feature they have read up about - one today insisted we must now implement in-memory encryption! Many of these recent demands are not mandated by the GDPR and so are being handled as contractual changes and new feature requests so the sales team are having discussions to explain our stance and see if the customer wants a quote to amend their service and contract!

Post reply on HN