Earlier quoted context omitted.
> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.
> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe. These are not burdens.
"Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not using any 3rd-party analytics."