30 ms·
I'm surprised no one has brought this up (yet). GDPR is super expensive to remain compliant, simply because of the broadness of the terms used, leading to undef
by throwaway13456 8y ago
I'm surprised no one has brought this up (yet). GDPR is super expensive to remain compliant, simply because of the broadness of the terms used, leading to undefined scope of liability.
As one other HNer previously mentioned, the cheapest way to stay compliant with GDPR is to completely block access to EU customers. In fact, this is what I did with my business. I redirect to a generic text file (not even a HTML that could trigger a GDPR clause by itself) explaining my stance.
Don't worry about false equivalence that many will raise "So, you don't care about our data HUH?". The intentions behind GDPR may be good. But, the roadmap seems completely stupid. Many think blocking EU customers is an arrogant move. No, it's not. Not everyone has the finance and time to comply with GDPR. A typical re-implementation of our web application will cost us weeks if not months, for example. That could be time spent building features customers want, not fighting some vague elitist law (comply with us or else you're doomed!). If enough business owners block access to EU customers, then, EU will lose a lot of business and that will trigger them to hopefully do something about the vagueness of GDPR. I don't even live in EU, for instance, yet this re-implementation will cost me tens of thousands of dollars (translating my time) that the EU isn't going to pay me for their vagueness.
I've had enough of GDPR. I know many EU HNers will not agree, but please consider putting yourself in a solo founder's shoes.
- fcarraldo 8y agoIf you are a solo founder without any business presence in the EU, or clients in the EU, you have nothing to worry about. Blocking EU site visitors is unnecessary, and GDPR covers this in clear language. What about reimplementing will cost you tens of thousands? That implies you either have a heavy use of personal data without a legitimate interest or have significantly misunderstood the requirements laid out in GDPR.
- tripletao 8y agoLet's say I operate a website where you can sign up with an email address, and I'll send you recipes. The recipes call out specific brands of ingredients. The vendors who sell those brands pay me for this service. I and my server are in the USA. Additionally: 1. My food vendors operate (a) all only in the EU; or (b) mostly worldwide, but one operates only in the EU; or (c) all worldwide; or (d) all only in the USA, but an independent third party imports many of their products into the EU. 2. My recipes are for (a) only French food; or (b) all kinds of food. 3. My email includes descriptions of the restaurants that originated the recipes. These restaurants are (a) all in France; or (b) about half in France, half in New Orleans; or (c) all in New Orleans. (New Orleans is an American city with strong French influence on its culture, and a francophone minority.) 4. The recipes are distributed in (a) French only; or (b) English and French; or (c) English only. 5. I advertise my site (a) with a run-of-network ad that shows mostly in the USA, but also on a French newspaper; (b) on a small blog whose American operator doesn't track its audience, but that I've heard is popular in France; (c) not at all, relying on word of mouth. So I've set out 4×2×3×3×3 = 216 cases. In which of them am I subject to the GDPR? What factors or combinations of factors are determining? If I asked this question of two lawyers, how closely would you expect their answers to agree? What confidence would they express that their answers would agree with the regulator? I think the people who think GDPR compliance is easy are saying to themselves, "If I behave in accordance with these general principles as I understand them, then the regulator will see me for the good person that I am and I'll be okay". That may be true, but it's not law.
- scrollaway 8y agoYou have EU customer emails. You're subject to gdpr in all of them. None of the factors you suggested matter. Store your emails properly, have unsubscribe links, answer data requests. You just gave one of the most straightforward cases...
- tripletao 8y agoThe post above said: > If you are a solo founder without any business presence in the EU, or clients in the EU, you have nothing to worry about. Blocking EU site visitors is unnecessary, and GDPR covers this in clear language. Do you think this statement is correct or incorrect? If you think it's incorrect, then why are you interpreting the "clear language" of the GDPR differently from its poster? (I personally think the statement is either incorrect or too vague to assess.) If you think the statement is correct--I presume, because you think that as soon as an EU visitor signs up, you have a "client" or "business presence" in the EU--then what meaning does that poster's statement convey? Does it mean anything more than "blocking EU visitors is unnecessary, as long as you have zero EU visitors", a true and entirely meaningless statement? Or are you saying that the email address makes this different from just a visitor? Even if my server is a typical default configuration that logs time and IP for each visit? Even if my ad network logs tracking cookies? Even if a data broker exists somewhere who could map that information to a real name? Even if I buy that data? And, for clarity: What about the case where the website (1) calls out only products with authorized distributors only in the USA, (2) has recipes for all kinds of food, (3) describes restaurants only in the USA, (4) is in English only, and (5) isn't advertised makes it subject to the GDPR? The EU says in an example that: > Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... Do you agree with this guidance? If yes, what factor constitutes the specific targeting? Or does the "travel" language mean we exclude only non-EU residents who temporarily visit the EU? Also EU residents who sign up while in the USA, but then return home? But not EU residents who sign up while in the EU? How sure are you that your answer is correct? I get that you're sure that it's morally right, and complying is always the conservative choice; but what probability would you assign that an EU court would reach your same conclusion, that all 216 cases are subject to the GPDR? And since any suggestion that the GDPR is less than perfect attracts angry reactions: I am not asking whether it's a good idea to comply with the general spirit of the GDPR for all visitors worldwide, and I think the answer to that question is yes. I'm asking what the law says. I think the rule of law is important, and I'd venture that most people who have lived in countries with and without it would agree.
- lajhsdfkl 8y agoI think Europeans really overestimate how much revenue is derived from European customers. European CPMs are a fraction of American CPMs. Europeans purchase a fraction of the products that Americans do.
- matthewmacleod 8y agoThis is nonsense. GDPR is cheap to comply with: following best practice, you should easily be able to comply with it.
- ebiester 8y agoHere's the question: are you willing to bet 20 million euros on your best practices? That's the maximum penalty as I understand it: https://gdpr.report/news/2017/06/16/gdpr-guidelines-consequences-non-compliance/ https://gdpr.report/news/2017/06/16/gdpr-guidelines-conseque... - and that doesn't count the cost of litigation before being fined. This has already been posted in here, but I count GDPR compliance as being able to respond to this: https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce... Even if I think I'm completely compliant, I think I'd make the decision to limit it to North America until I had enough revenue to hire a separate data protection officer.
- matthewmacleod 8y agoYes. I’m 100% willing to risk it, because I have a basic knowledge of how regulatory processes in the EU generally work. The LinkedIn example is excellent, because it lots all the things that you should have already known about and been able to do with personal data.
- cge 8y agoDo you note this somewhere on your sites so that non-EU customers are also aware you're doing this? While I know you believe that blocking EU customers over GDPR doesn't mean that you don't care about personal data, many of us do feel that way, and I know that I at least would like a way to avoid interacting with such companies in a more convenient way than running everything through an EU-based VPN.
- tomkinson 8y agoYup +++