4 ms·
Here's an example: I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only
by throwaway974 8y ago
Here's an example:
I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication.
I've been talking to a very well known giant corporation (also based in US, but has many global offices) for months. The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. They are putting some draconian clauses (various ISO certifications and such) in the contract that I, as a small company, cannot comply. That's their interpretation of GDPR. It doesn't matter whether it's right or wrong.
The VP and Director are really nice people and I've developed very good rapport with them. But I'm afraid their patience will run out soon and they'll go back to using spreadsheets. A lose-lose situation.
This is the side-effect of GDPR.
I'm all up for GDPR. I have uBlock, have blackholed all Facebook domains, etc. But don't assume that GDPR doesn't affect normal business transactions. Anyone who says, "Oh, how hard could it be?" has no idea what they are talking about.
- openIce 8y ago>It's a trivial application that stores mostly already public data So wtf are you worrying about then? Only shady companies are afraid of GDRP, the fact that you look at GDPR as a problem is a huge let down in trust for your company
- BjoernKW 8y agoThat's a gross generalization. In fact, the parent explained quite well why GDPR can become a problem for smaller companies. It's not the law itself that matters in this case but the clients' (quite possibly wrong) interpretation of that law. As of now, GDPR unfortunately leaves a lot of room for interpretation.
- smoe 8y agoI think once the dust settles and it becomes clearer how the law is being handled, it is going to get easier. My first job twelve years ago was at a company similar to yours in Switzerland. A small bootstrapped SaaS targeted at enterprise and government. Switzerland is quite serious about privacy with strict laws regarding them, but since they have been around for a long time, nobody freaked out about it. It is just part of the daily business for everyone. I can't remember compliance with such constraints being a serious competitive disadvantage for the company. In fact after Snowden the label "Made in Switzerland" and images of datacenters in mountain bunkers became an advantage internationally.
- dang 8y agoWould you please stop copy-pasting the same thing in multiple threads? You've done it 5 times. That's particularly abusive. It strictly lowers the signal/noise ratio of this site, meaning it's just what we don't want here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- IshKebab 8y agoIt's not really a criticism of the GDPR that some companies are irrationally panicked about it.
- geocar 8y agoThis is how "well known giant corporations" are. They have chosen not to understand the GDPR, gotten a lawyer to state that "ISO27001 certified vendors" will not pose a risk to them under the GDPR's security requirements, and so have set policy that they cannot purchase from vendors that are non-compliant. Their policy office is probably still busy waiting for Y2K. It sucks, but HIPPA was exactly the same, and I heard exactly the same complaint from tiny companies back then too. You can get ISO27001 for as little as $5k. My advice is that if you can afford it, suck it up, if you can't, offer ISO27001 on-prem installation for an extra $10k. If they walk. They walk. You can probably get them later (see below). But see, it's important to understand that you're wrong: This isn't a side-effect of the GDPR. This is a side-effect of capitalism: With no laws requiring that they keep personal data safe, it is to their benefit to keep the data in as insecure a form as possible. Look at Equifax[1], who have lost control of perhaps every single american's name, DOB, SSN, and address. Data Protection laws are designed to protect people. Eventually, people will get used to them; the dust will settle. You'll have an opportunity to explain the actual risk/reward clearly to your potential customer's CIO office because the savings/efficiency you're promising will make it worthwhile. But right now? Too much fucking hyperbole about the GDPR for anyone to be thinking clearly. [1]: https://www.sec.gov/Archives/edgar/data/33185/000119312518154706/d583804dex991.htm https://www.sec.gov/Archives/edgar/data/33185/00011931251815...