Earlier quoted context omitted.
- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…
You actually can't appoint yourself as DPO since it would be a conflict of interest. But you only need a DPO if your core business is large scale user tracking, which it probably isn't (especially if you're a small startup). https://www.pensar.co.uk/blog/data-protection-officer > The following companies need to appoint a data protection officer under Article 37: * Public authorities or bodies, except for courts actin…
What does the GDPR actually mean for startups?
21–30 of 56 posts
Re: What does the GDPR actually mean for startups?
#22Earlier quoted context omitted.
If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…
Well, for example, one of the mentioned points is about sending PII to a 3rd party where the startup didn't read the 3rd party's privacy policy. So how would the startup be able to accurately present me with information on how my data will be used if they don't even know? I think having an accurate and updated privacy policy is common sense handling of data, wouldn't you agree?
If a privacy regime is going to have any value in practice, it has to work on the same basis. The emphasis has to be ensuring that each individual or organisation who actually knows about the way data is being processed and has the ability to influence that processing is behaving reasonably. Then you can have some sort of trust framework that can actually mean something, from the data subject to their direct contacts and right on through to the indirect service providers however far the chain goes. The rest is just CYA and box-ticking, no matter how many laws you write or what penalties you threaten.
Re: What does the GDPR actually mean for startups?
#23Earlier quoted context omitted.
If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…
You don't have to hire a DPO. You do have to appoint someone within your company to be resposible for data protection, which seems like good practice anyway. You don't have to hire an expensive company to go through your systems. There is no such thing as GDPR "compliant" it is a series of steps for which a company can self-certify based upon the data they collect and the way that data is used. These steps are again…
Re: What does the GDPR actually mean for startups?
#24>> The scope of this protection extends to any natural person in the EU which can mean users, employees, vendors, partners, customers or even members of the general public. I hadn’t considered GDPR from the perspective of a company collecting/maintaining data about employees (as opposed to clients, prospects, website visitors etc.). Do the same rules apply inside a company for an employee as they do for a user of a w…
They might know the systems in detail, and have information spread around all of them.
Former employees can also make a request.
(This is not a new right, it was in the earlier Data Protection Regulation.)
Re: What does the GDPR actually mean for startups?
#25The system has a ratings module (not active yet) whereby clients can rate the worker and vice versa. The system then makes decisions on future job releases based on the ratings. Part of the reason for not having the module active is due to the issue of communicating to the affected users how those decisions are being made and providing them with a right of manual review.
As organisations increasingly rely on AI or ML to make decisions affecting individuals, so the need for greater transparency into those decision making processes so they can be communicated to the people concerned.
Re: What does the GDPR actually mean for startups?
#26As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…
- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…
This point isn't about your customers. It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. And if you think this is a hypothetical risk, read the news today about kids lining up to damage exam boards in exactly this way if they didn't get the grades they wanted, and explain to me how that isn't a threat to the integrity of the examination system.
You don't have to monitor them, you just need to read them. If you don't have time to read contracts that you're singing, then your business is going to fail anyway.
The fact that you have read the privacy policy of one of your suppliers does nothing to help the data subject. Unless they have meaningful information about how personal data about them is being processed and who is doing that processing, they haven't really gained any meaningful control or protection.
And no small business has the time to fully read all of the legal paperwork affecting them. Like consumer contracts, it's the great fiction of the legal community. Most new businesses won't even have had time to read the contract with their banks and other financial services before signing to open their account, and those often contain some very nasty and one-sided terms. But of course those contracts all tend to contain similarly nasty and one-sided terms, and you're going to need those services to do business anyway.
Re: What does the GDPR actually mean for startups?
#27Earlier quoted context omitted.
You actually can't appoint yourself as DPO since it would be a conflict of interest. But you only need a DPO if your core business is large scale user tracking, which it probably isn't (especially if you're a small startup). https://www.pensar.co.uk/blog/data-protection-officer > The following companies need to appoint a data protection officer under Article 37: * Public authorities or bodies, except for courts actin…
there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.
> 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.
It's difficult to ensure that there is no conflict of interests if the CEO === DPO.
Re: What does the GDPR actually mean for startups?
#28Earlier quoted context omitted.
there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.
Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.
Re: What does the GDPR actually mean for startups?
#29Earlier quoted context omitted.
Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.
That seems really vauge. I'd argue anyone working for the company and getting paid could have a conflict of interest.
Quite obviously one will not be able to completely remove conflicts of interest as long as there is another (monetary) dependency. Which is the reason for a state owned regulatory agency in the first place.
Re: What does the GDPR actually mean for startups?
#30Earlier quoted context omitted.
there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.
Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.