Earlier quoted context omitted.
So my MVP is an imaginary service that does X for you. It charges $5/month and it uses your email as the log in. It captures no data other than what you give it to do said service. Other than good data practices which should be followed anyway, please described the huge GDPR hurdles that will make this service not viable.
Apparently you need to appoint a Data Protection Officier and you cannot just be e.g. CEO, developer and DPO at the same time. https://ico.org.uk/for-organisations/guide-to-the-general-da... > Basically this means the DPO cannot hold a position within your organisation that leads him or her to determine the purposes and the means of the processing of personal data Are there exemptions for very small companies? If you…
There is the Data Protection Officer (DPO), which comes from Article 37, and a representative in the Union (EU Rep), which comes from Article 27.
The purpose of the DPO is to oversee data protection. Whether or not a company needs one depends on the nature and volume of data they handle. I'd expect most small companies that are selling a product or service would not need one.
The purpose of the EU Rep is to provide a point of contact in the Union for data subjects and regulators to contact the company. It is only required for companies that are not in the Union. If the company only occasionally processes data, does not process data from certain particularly sensitive categories, and the processing is unlikely to result in a risk to rights and freedoms of natural persons, no EU Rep is required.
The DPO requirement seems to generate a lot more discussion than the EU Rep requirement, which I find odd. The EU Rep seems to me a much bigger deal from the point of view of small non-EU companies, because the EU Rep has to be in the Union.