As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…
First of IANAL, I'm a European citizen within IT that has to deal with GDPR in my professional role. I believe there is a lot of hysteria and FUD around GDPR. Anyway, this is how I would handle your problems. 1. In the same article[1] that you reference, the following paragraph might apply to your business: >27.2 The obligation laid down in paragraph 1 of this Article shall not apply to: >processing which is occasion…
Re #1: To be exempt you must fit all 3 criteria: 1. processing is occasional 2. does not include, on a large scale, processing of special categories of data (e.g. religious, political, criminal backgrounds, sexual orientation, etc.) AND 3. unlikely to result in a risk to the rights and freedoms of natural persons I collect a number of emails on my website and apps every day, so I don't think my processing is "occasional". If I collected emails once a year or even once a month, sure I could argue that processing is occasional. But collecting 10-20 email signups per days doesn't seem occasional to me.
2. Thanks for this opinion on this. I think I agree your assessment.
3. Again, I think I agree with you - thanks for you opinion.
Very helpful, thanks!