Live data from Hacker News

What does the GDPR actually mean for startups?

hackernoon.com

21–30 of 56 posts

Re: What does the GDPR actually mean for startups?

#21
post #20

Earlier quoted context omitted.

- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…

You actually can't appoint yourself as DPO since it would be a conflict of interest. But you only need a DPO if your core business is large scale user tracking, which it probably isn't (especially if you're a small startup). https://www.pensar.co.uk/blog/data-protection-officer > The following companies need to appoint a data protection officer under Article 37: * Public authorities or bodies, except for courts actin…

there's nothing in the document you linked to, or the guidance that it links to (http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_...) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.

Re: What does the GDPR actually mean for startups?

#22

Earlier quoted context omitted.

If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…

Well, for example, one of the mentioned points is about sending PII to a 3rd party where the startup didn't read the 3rd party's privacy policy. So how would the startup be able to accurately present me with information on how my data will be used if they don't even know? I think having an accurate and updated privacy policy is common sense handling of data, wouldn't you agree?

That's a reasonable point, but it's also reasonable to observe that businesses rely on other businesses all the time. As a small business, you usually have little meaningful oversight of the internal processes of outside services you use. You don't get to audit your bank's finances to make sure they're safe to trust with your money. You don't get to review your lawyer's office security arrangements to make sure no-one can break in and steal confidential data about your contracts. You don't get to review which products your office cleaning firm uses. At some point, you just have to trust that they do a decent job, and you change who you work with if you have reason to believe they aren't doing that.

If a privacy regime is going to have any value in practice, it has to work on the same basis. The emphasis has to be ensuring that each individual or organisation who actually knows about the way data is being processed and has the ability to influence that processing is behaving reasonably. Then you can have some sort of trust framework that can actually mean something, from the data subject to their direct contacts and right on through to the indirect service providers however far the chain goes. The rest is just CYA and box-ticking, no matter how many laws you write or what penalties you threaten.

Re: What does the GDPR actually mean for startups?

#23

Earlier quoted context omitted.

If your company can't be bothered to apply some common sense to handling user data Which of the specific points the GP mentioned do you think is about how they handle user data? As far as I can see, every one of them is administrative in nature. They're not saying they're going to be tracking everyone in shady ways. They're not saying they're going to be storing unencrypted details and unhashed passwords. They're not…

You don't have to hire a DPO. You do have to appoint someone within your company to be resposible for data protection, which seems like good practice anyway. You don't have to hire an expensive company to go through your systems. There is no such thing as GDPR "compliant" it is a series of steps for which a company can self-certify based upon the data they collect and the way that data is used. These steps are again…

We had all these debates ad nauseam in the time leading up to 25 May. The basic concerns haven't changed. There's still little clarity about the main ambiguities. Just linking from your privacy policy to each of your suppliers' is still as useful to data subjects as a clause saying "We can change our terms unilaterally at any time" in a contract, and in any sane world it would carry a similar amount of legal weight.

Re: What does the GDPR actually mean for startups?

#24
post #2

>> The scope of this protection extends to any natural person in the EU which can mean users, employees, vendors, partners, customers or even members of the general public. I hadn’t considered GDPR from the perspective of a company collecting/maintaining data about employees (as opposed to clients, prospects, website visitors etc.). Do the same rules apply inside a company for an employee as they do for a user of a w…

For a non-creepy company, an employee request can be more concerning than a customer.

They might know the systems in detail, and have information spread around all of them.

Former employees can also make a request.

(This is not a new right, it was in the earlier Data Protection Regulation.)

Re: What does the GDPR actually mean for startups?

#25
I'm surprised that the guide doesn't address automated decision making about users. In my day job, we are using a scheduling platform for short-notice, short-term work e.g. social care. A job is loaded on the sytem and pushed to x users for acceptance (fastest finger first).

The system has a ratings module (not active yet) whereby clients can rate the worker and vice versa. The system then makes decisions on future job releases based on the ratings. Part of the reason for not having the module active is due to the issue of communicating to the affected users how those decisions are being made and providing them with a right of manual review.

As organisations increasingly rely on AI or ML to make decisions affecting individuals, so the need for greater transparency into those decision making processes so they can be communicated to the people concerned.

Re: What does the GDPR actually mean for startups?

#26

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

- I don't have the funds to hire a DPO. Just appoint yourself as DPO. It's a role, not a qualification. > - I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR. Just go through your database and work out what data can be associated with an individual. Do you have a good reason to keep that data? If yes, cool, you're golden. If not, delete it and…

These are your customers. If you don't have the time or resources to talk to your customers, then your business is going to fail anyway.

This point isn't about your customers. It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. And if you think this is a hypothetical risk, read the news today about kids lining up to damage exam boards in exactly this way if they didn't get the grades they wanted, and explain to me how that isn't a threat to the integrity of the examination system.

You don't have to monitor them, you just need to read them. If you don't have time to read contracts that you're singing, then your business is going to fail anyway.

The fact that you have read the privacy policy of one of your suppliers does nothing to help the data subject. Unless they have meaningful information about how personal data about them is being processed and who is doing that processing, they haven't really gained any meaningful control or protection.

And no small business has the time to fully read all of the legal paperwork affecting them. Like consumer contracts, it's the great fiction of the legal community. Most new businesses won't even have had time to read the contract with their banks and other financial services before signing to open their account, and those often contain some very nasty and one-sided terms. But of course those contracts all tend to contain similarly nasty and one-sided terms, and you're going to need those services to do business anyway.

Re: What does the GDPR actually mean for startups?

#27
post #20

Earlier quoted context omitted.

You actually can't appoint yourself as DPO since it would be a conflict of interest. But you only need a DPO if your core business is large scale user tracking, which it probably isn't (especially if you're a small startup). https://www.pensar.co.uk/blog/data-protection-officer > The following companies need to appoint a data protection officer under Article 37: * Public authorities or bodies, except for courts actin…

there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.

Check out §38 6

> 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

It's difficult to ensure that there is no conflict of interests if the CEO === DPO.

Re: What does the GDPR actually mean for startups?

#28
post #27

Earlier quoted context omitted.

there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.

Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.

That seems really vauge. I'd argue anyone working for the company and getting paid could have a conflict of interest.

Re: What does the GDPR actually mean for startups?

#29
post #28
post #27

Earlier quoted context omitted.

Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.

That seems really vauge. I'd argue anyone working for the company and getting paid could have a conflict of interest.

Don't you think one could (contractually) minimize (probably not remove) conflicts of interest?

Quite obviously one will not be able to completely remove conflicts of interest as long as there is another (monetary) dependency. Which is the reason for a state owned regulatory agency in the first place.

Re: What does the GDPR actually mean for startups?

#30
post #27

Earlier quoted context omitted.

there's nothing in the document you linked to, or the guidance that it links to ( http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_... ) that says the DPO can't have any role in the organisation. There's no "conflict of interest" clause I can see... but I'd welcome any clarification.

Check out §38 6 > 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It's difficult to ensure that there is no conflict of interests if the CEO === DPO.

What duties would you have that would cause a conflict of interest that aren't already against the GDPR? It seems that's the only situation where there would be an issue.
Post reply on HN