Earlier quoted context omitted.
> The legislation has clearly been dreamt up by folks saying “ah ha! if we threaten the Facebook UK executive mangement team with jailtime unless they do better at filtering self-harm/CSAM/terrorism/etc then they will obviously get their house in order!”. Whereas in practice they crush their own UK-based startups instead. So frustrating. Isn’t that exactly what the GDPR did? I know I pulled my apps for fear of fines…
GDPR really isn’t that complicated for most purposes - it boils down to: tell your users what data you store; let them delete their data if they want; let them export their data if they want. Which is not exactly unreasonable - the only scary thing was being obligated to do it by law with threats of fines if you didn’t. It wasn’t that hard to put together, particularly if you’re a normal centralised website or app th…
You're coming at it from a position of knowledge and confidence. The guide produced by the Information Commissioner's Office for organisations has 48 sections/pages [1] and features a toolkit with 7 different self assessment quizes [2], plus an extra one to help small businesses [3]. Even the "What is personal data?" section of the site alone contains dozens of pages [4]. And obviously the regulation itself is pretty verbose [5].
Given the legal ramifications, it's a bit dismissive to say it just boils down to three phrases. Whether or not GDPR is reasonable (and I agree that it is), it's perfectly understandable that sole traders and small businesses are concerned about the resources required to understand and implement it - especially when even many large organisations currently flout it (through ignorance or negligence).
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
[2] https://ico.org.uk/for-organisations/sme-web-hub/checklists/...
[3] https://ico.org.uk/for-organisations/sme-web-hub/checklists/...
[4] https://ico.org.uk/for-organisations/guide-to-data-protectio...