Live data from Hacker News

What does the GDPR actually mean for startups?

hackernoon.com

11–20 of 56 posts

Re: What does the GDPR actually mean for startups?

#11
post #2

>> The scope of this protection extends to any natural person in the EU which can mean users, employees, vendors, partners, customers or even members of the general public. I hadn’t considered GDPR from the perspective of a company collecting/maintaining data about employees (as opposed to clients, prospects, website visitors etc.). Do the same rules apply inside a company for an employee as they do for a user of a w…

Yes. You can request a copy of any personal information held by any company. This is a pre-GDPR right too.

I was not aware of this - thanks for the reply.

Re: What does the GDPR actually mean for startups?

#12
post #6

Earlier quoted context omitted.

Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.

If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…

Well, for example, one of the mentioned points is about sending PII to a 3rd party where the startup didn't read the 3rd party's privacy policy. So how would the startup be able to accurately present me with information on how my data will be used if they don't even know? I think having an accurate and updated privacy policy is common sense handling of data, wouldn't you agree?

Re: What does the GDPR actually mean for startups?

#13

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

If it helps any, I read that a DPO is only needed for companies larger than X number of employees. I think X was like 50 or 100. And that the DPO "role" could be fulfilled by anyone.

Which is why I think the OP is spreading a load of FUD.

Re: What does the GDPR actually mean for startups?

#14
post #6

Earlier quoted context omitted.

Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.

If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…

[deleted]

Re: What does the GDPR actually mean for startups?

#15
post #6

Earlier quoted context omitted.

Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.

If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…

You don't have to hire a DPO. You do have to appoint someone within your company to be resposible for data protection, which seems like good practice anyway.

You don't have to hire an expensive company to go through your systems. There is no such thing as GDPR "compliant" it is a series of steps for which a company can self-certify based upon the data they collect and the way that data is used. These steps are again good practice e.g. only collect the data you really need, database encryption, access controls and so on.

In terms of "nightmare letters" - your company should have a privacy policy which answers a user's generic concerns, again this is good practice. If a user requests a copy of their data or to have data removed this is a simple reapeatable process that you should design into your system from day one. Remember, the key premise of GDPR is "privacy by design". If you take that into consideration when designing and building your solution, you are 90% of the way there.

You don't have to constantly monitor 3rd parties privacy policies and update your own. Your privacy policy, which I think we all agree every company which collects personal data should have, can link to the privacy policies of the companies you send data to.

Re: What does the GDPR actually mean for startups?

#16

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

My opinion is that the GDPR over the long term, will hamper the ability of EU companies to do business on the world stage, even more than currently. But that's a completely different topic for another time.

I would argue the opposite. Most of the laws laid out in the GDPR were already laws in EU countries such as Germany and the Netherlands. Creating a single EU law should reduce the effort needed to launch a company that is compliant in multiple countries within the EU.

Also, you wont need a DPO if you don't process large quantities of PII. (https://gdpr-info.eu/art-37-gdpr/)

And you don't need to hire an expensive company to 'prepare' for gdpr. A conversation with a lawyer should suffice where you lay out how you (plan to) use or process PII.

Re: What does the GDPR actually mean for startups?

#17

Earlier quoted context omitted.

If it helps any, I read that a DPO is only needed for companies larger than X number of employees. I think X was like 50 or 100. And that the DPO "role" could be fulfilled by anyone.

Which is why I think the OP is spreading a load of FUD.

it seems like it.

In the "Steps to take" section they write > 2) Identify/review your legal basis for processing, ideally with a legal professional.

where legal professional links to the author companie's info email, and linking to their own site about 30 times in the article.

This looks like "you're violating the law, but we'll help you fix it" kind of deal.

Re: What does the GDPR actually mean for startups?

#18

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

- I don't have the funds to hire a DPO.

Just appoint yourself as DPO. It's a role, not a qualification.

> - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR.

Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and you're golden. The only thing that GDPR changes about data is (rightly) turning it from an asset into a liability.

> - I don't have the resources to deal with inquiries to that nightmare letter or any questions for that matter.

These are your customers. If you don't have the time or resources to talk to your customers, then your business is going to fail anyway.

> - I don't have the resources to monitor the 3rd parties privacy policies that I send data to use their service and constantly update my own.

You don't have to monitor them, you just need to read them. If you don't have time to read contracts that you're singing, then your business is going to fail anyway.

Pretty much everything in GDPR was already covered by existing UK Data Protection legislation. Under UK law you already had to appoint someone in your organisation to deal with Data Privacy, you already needed to have a good reason to collect personally identifiable information, and an obligation to ensure it wasn't disclosed to third parties.

I suggest you start taking all of this a bit more seriously than your comment suggests, not because of the legal implications, but the moral ones. Your customers are trusting you with their personal information. It's a serious responsibility that you need to take seriously. If you can't be bothered making sure that your customer's data is safe, then you shouldn't be trusted with it.

Re: What does the GDPR actually mean for startups?

#19

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

This is really not a big deal. As has been mentioned you most likely don't need a DPO. Just sign up to Iubenda, it'll help you manage the compliance and make it as easy as humanly possible.

Re: What does the GDPR actually mean for startups?

#20

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…

You actually can't appoint yourself as DPO since it would be a conflict of interest. But you only need a DPO if your core business is large scale user tracking, which it probably isn't (especially if you're a small startup).

https://www.pensar.co.uk/blog/data-protection-officer

> The following companies need to appoint a data protection officer under Article 37:

* Public authorities or bodies, except for courts acting in their judicial capacity.

* Companies who process data requiring ‘regular and systematic monitoring of data subjects on a large scale.’

* Companies who process, on a large scale, any special category of personal data. This includes data which reveals racial or ethnic origin; political opinions; religious or philosophical beliefs and other such information.

* Companies who process, on a large scale, personal data relating to criminal convictions and offences

Post reply on HN