>> The scope of this protection extends to any natural person in the EU which can mean users, employees, vendors, partners, customers or even members of the general public. I hadn’t considered GDPR from the perspective of a company collecting/maintaining data about employees (as opposed to clients, prospects, website visitors etc.). Do the same rules apply inside a company for an employee as they do for a user of a w…
Yes. You can request a copy of any personal information held by any company. This is a pre-GDPR right too.
What does the GDPR actually mean for startups?
11–20 of 56 posts
Re: What does the GDPR actually mean for startups?
#12Earlier quoted context omitted.
Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.
If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…
Re: What does the GDPR actually mean for startups?
#13As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
If it helps any, I read that a DPO is only needed for companies larger than X number of employees. I think X was like 50 or 100. And that the DPO "role" could be fulfilled by anyone.
Re: What does the GDPR actually mean for startups?
#14Earlier quoted context omitted.
Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.
If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…
Re: What does the GDPR actually mean for startups?
#15Earlier quoted context omitted.
Seems like the GDPR is working as expected. If your company can't be bothered to apply some common sense to handling user data (which is what the GDPR is mostly about, if you take a couple of hours to actually read it), then we're better off without it. I'm sure if what you're doing is relevant, some other company will happily take your place.
If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…
You don't have to hire an expensive company to go through your systems. There is no such thing as GDPR "compliant" it is a series of steps for which a company can self-certify based upon the data they collect and the way that data is used. These steps are again good practice e.g. only collect the data you really need, database encryption, access controls and so on.
In terms of "nightmare letters" - your company should have a privacy policy which answers a user's generic concerns, again this is good practice. If a user requests a copy of their data or to have data removed this is a simple reapeatable process that you should design into your system from day one. Remember, the key premise of GDPR is "privacy by design". If you take that into consideration when designing and building your solution, you are 90% of the way there.
You don't have to constantly monitor 3rd parties privacy policies and update your own. Your privacy policy, which I think we all agree every company which collects personal data should have, can link to the privacy policies of the companies you send data to.
Re: What does the GDPR actually mean for startups?
#16As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
I would argue the opposite. Most of the laws laid out in the GDPR were already laws in EU countries such as Germany and the Netherlands. Creating a single EU law should reduce the effort needed to launch a company that is compliant in multiple countries within the EU.
Also, you wont need a DPO if you don't process large quantities of PII. (https://gdpr-info.eu/art-37-gdpr/)
And you don't need to hire an expensive company to 'prepare' for gdpr. A conversation with a lawyer should suffice where you lay out how you (plan to) use or process PII.
Re: What does the GDPR actually mean for startups?
#17Earlier quoted context omitted.
If it helps any, I read that a DPO is only needed for companies larger than X number of employees. I think X was like 50 or 100. And that the DPO "role" could be fulfilled by anyone.
Which is why I think the OP is spreading a load of FUD.
In the "Steps to take" section they write > 2) Identify/review your legal basis for processing, ideally with a legal professional.
where legal professional links to the author companie's info email, and linking to their own site about 30 times in the article.
This looks like "you're violating the law, but we'll help you fix it" kind of deal.
Re: What does the GDPR actually mean for startups?
#18As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
Just appoint yourself as DPO. It's a role, not a qualification.
> - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR.
Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and you're golden. The only thing that GDPR changes about data is (rightly) turning it from an asset into a liability.
> - I don't have the resources to deal with inquiries to that nightmare letter or any questions for that matter.
These are your customers. If you don't have the time or resources to talk to your customers, then your business is going to fail anyway.
> - I don't have the resources to monitor the 3rd parties privacy policies that I send data to use their service and constantly update my own.
You don't have to monitor them, you just need to read them. If you don't have time to read contracts that you're singing, then your business is going to fail anyway.
Pretty much everything in GDPR was already covered by existing UK Data Protection legislation. Under UK law you already had to appoint someone in your organisation to deal with Data Privacy, you already needed to have a good reason to collect personally identifiable information, and an obligation to ensure it wasn't disclosed to third parties.
I suggest you start taking all of this a bit more seriously than your comment suggests, not because of the legal implications, but the moral ones. Your customers are trusting you with their personal information. It's a serious responsibility that you need to take seriously. If you can't be bothered making sure that your customer's data is safe, then you shouldn't be trusted with it.
Re: What does the GDPR actually mean for startups?
#19As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
Re: What does the GDPR actually mean for startups?
#20As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…
https://www.pensar.co.uk/blog/data-protection-officer
> The following companies need to appoint a data protection officer under Article 37:
* Public authorities or bodies, except for courts acting in their judicial capacity.
* Companies who process data requiring ‘regular and systematic monitoring of data subjects on a large scale.’
* Companies who process, on a large scale, any special category of personal data. This includes data which reveals racial or ethnic origin; political opinions; religious or philosophical beliefs and other such information.
* Companies who process, on a large scale, personal data relating to criminal convictions and offences