I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore. The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling. Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-…
The "best practice" you mention was already illegal if you have European users, the right to be forgotten was already a consequence of existing laws and directives (just ask Google).
As for startups the GDPR already takes company size into account, so unless their business is literally being a private NSA/Stasi/etc. they don't have much burocracy to deal with (https://ec.europa.eu/info/law/law-topic/data-protection/refo...)