Live data from Hacker News

What does the GDPR actually mean for startups?

hackernoon.com

51–56 of 56 posts

Re: What does the GDPR actually mean for startups?

#51

Earlier quoted context omitted.

> The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. The magic words here are "still stored", PII is a liability so you never want to store it longer than absolutely necessary. Why are you hoarding this data when you can't even retrieve it easily, what is the point ?

Why are you hoarding this data when you can't even retrieve it easily, what is the point ? Do you have a filing system for every email you ever wrote? Can you identify every backup copy, every forwarded message, every print-out, every excerpt copied and pasted into a Word document? Can you remember or look up every individual ever referenced in those messages? Now, let's talk about letters. The paper kind. And faxes.…

GDPR wasn't put in place to monitor people scribbling down phone numbers on pieces of paper. It was put in place to stop companies from hoarding vast amounts of personal data and using it to infringe on people's privacy (as well as making sure they looked after it properly).

If the regulator finds out that one of your staff scribbled down a customer's phone number once on a piece of paper while serving that customer, they won't care. If they find that your customer service process requires your customer service staff to scribble down phone numbers on scraps of paper that are then put out with the garbage, where they can be dumpster-dived, they will care (and so should you).

This is not some huge regulatory over-reach that will force you to go through every piece of paper in your organisation. It's a check on your data handling that forces you to acknowledge the trust placed in you by your customers.

Re: What does the GDPR actually mean for startups?

#52

Earlier quoted context omitted.

Anyone in retail deals with nightmare customers who use social media to cause them untold pain and misery, and wastes huge amounts of time. It's no different, except that in the GDPR case you can automate the response, and there's an actual regulator at the other end who can decide that the complaint was frivolous. Dealing with customers is always nightmarish waste of time. But necessary. I haven't heard about the ex…

Anyone in retail deals with nightmare customers who use social media to cause them untold pain and misery, and wastes huge amounts of time. Of course. But they don't do it with the active blessing and support of the legal system. Again, if you don't understand how your customer's data is being used by a third party, then perhaps you shouldn't use that third party. Unfortunately, that's easier to say than to respect i…

I used to work for a payment processor, I know your pain.

The obscurity and lack of information that you complain about, though, is exactly the thing that the GDPR discovery clauses are trying to eradicate. Let's hope that the utterly arbitrary and opaque banking system is held to the same standard eventually.

Re: What does the GDPR actually mean for startups?

#53

Earlier quoted context omitted.

Well, prepare yourself to be surprised launching in the US as there are also state laws, like in California [0]. And US government is actually working on it too [1] [0] https://www.cnet.com/news/californias-new-data-privacy-law-t... [1] https://www.reuters.com/article/us-usa-internet-privacy/trum...

Its a funny reference to bring up California. So many responses to GDPR have been a blanket refusal and cutting EU users off from a nontrivial amount of content on the internet. As a US citizen, I already know that everything on earth causes cancer to the citizens of CA, but its interesting how many product commercials where you see the products are not available in CA. Frankley, I think alot of data privacy crusader…

TBH it was a quick search on Google and I don’t know the details. What I wanted to point out was the parent thought that:

> The EU unlike the US isn't a contiguous block.

Re: What does the GDPR actually mean for startups?

#54

Earlier quoted context omitted.

Why are you hoarding this data when you can't even retrieve it easily, what is the point ? Do you have a filing system for every email you ever wrote? Can you identify every backup copy, every forwarded message, every print-out, every excerpt copied and pasted into a Word document? Can you remember or look up every individual ever referenced in those messages? Now, let's talk about letters. The paper kind. And faxes.…

GDPR wasn't put in place to monitor people scribbling down phone numbers on pieces of paper. It was put in place to stop companies from hoarding vast amounts of personal data and using it to infringe on people's privacy (as well as making sure they looked after it properly). If the regulator finds out that one of your staff scribbled down a customer's phone number once on a piece of paper while serving that customer,…

GDPR wasn't put in place to monitor people scribbling down phone numbers on pieces of paper. It was put in place to stop companies from hoarding vast amounts of personal data and using it to infringe on people's privacy (as well as making sure they looked after it properly).

Sure. The intent of the GDPR has not received much criticism, at least not that I've seen. The concerns some of us have always had are more about ambiguity and interpretation, because on the one hand the law as actually written doesn't allow for much leeway in some cases, and yet on the other hand it has huge ambiguities in key areas hiding behind words like "reasonable" or "legitimate".

It's easy to look at extreme positions, such as the example I gave above for illustrative purposes, and say no regulator is ever going to expect all of that. Probably you'd be right. The difficulty is that somewhere between not doing much of anything to comply and the other extreme such as I described, you cross an invisible line from being sufficiently compliant in the regulator's view (or potentially a court's if it really came to that) to not being sufficiently compliant and no-one really knows where that line is.

When you have not just the threat of fines but also potentially very significant costs in adapting your systems and processes, that sort of uncertainty is never good for anyone. That is particularly true in a case like GDPR, because many of those adaptations are more about being seen to comply than about fixing any actual security vulnerability or abuse of privacy or other tangible problem.

Re: What does the GDPR actually mean for startups?

#55

As a solo founder with already too much to do. I simply looked at the GDPR and decided to kick that can down the road for 12 months after launch of my start up. Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site. Why you may ask? - I don't have the funds to hire a DPO. - I don't have the funds to hire out an expensive company to go through the plat…

I recommend reading https://jacquesmattheij.com/gdpr-hysteria/ for a more detailed understanding of how you might be exposed, and what your obligations are.

Some of your notes have been addressed by other commenters in the thread, but overall many of your points directly contradict what is discussed by Jacques. You probably want to evaluate your risk of exposure with your current approach.

Re: What does the GDPR actually mean for startups?

#56

Earlier quoted context omitted.

GDPR wasn't put in place to monitor people scribbling down phone numbers on pieces of paper. It was put in place to stop companies from hoarding vast amounts of personal data and using it to infringe on people's privacy (as well as making sure they looked after it properly). If the regulator finds out that one of your staff scribbled down a customer's phone number once on a piece of paper while serving that customer,…

GDPR wasn't put in place to monitor people scribbling down phone numbers on pieces of paper. It was put in place to stop companies from hoarding vast amounts of personal data and using it to infringe on people's privacy (as well as making sure they looked after it properly). Sure. The intent of the GDPR has not received much criticism, at least not that I've seen. The concerns some of us have always had are more abou…

I get it. The best explanation I've heard is that this is a major difference between EU(and UK) regulation and US regulation. In US regulation, the letter of the law matters. In the EU the spirit matters.

The UK has had regulation like this for decades, and as loosely worded. The regulator rarely imposes fines, and then only when forced to because the infringer is refusing to change their processes. Almost always they give some advice, sometimes a warning. This is done in the context of a conversation with the regulator, like "hey, we've received a complaint, have you got any reason why this happened?" instead of "we received a complaint, you're fined $1000 for it".

It's not a revenue source for the government (which it would be in the US). The wording is loose deliberately so that the regulator has the power to enforce the spirit of the regulation without getting tied into knots by the letter of it.

So yeah, I get that it's freaking people out. And there are costs in adapting processes. But, to be honest, if those processes need adapting then they were probably doing the wrong thing in the first place. Also, the EU gave everyone years of warning, and nobody paid any attention to that.

Post reply on HN