3 ms·
Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? It seems like there’s room for an enterprise
by jiggliemon 8y ago
Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling?
It seems like there’s room for an enterprise framework that does all the compliance work for you (for US gov contacts, i18n, user info download etc). Maybe calling it enterprise is a misnomer. Maybe it’s a spec that framework’s can target or comply with?
- trjordan 8y agoSalesforce, roughly speaking.
- Kalium 8y ago> Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? I understand why you think this way! It's an obvious approach, where there's a bunch of stuff that needs to be done and it's the same everywhere. Why not just have a framework that handles it all for you? It's so clear! It's perhaps possible that many of the requirements of GDPR are beyond the scope of what any kind of framework or code pattern or generator might be reasonably expected to handle. Code cannot readily become a Data Protection Officer or respond to inbound requests. Code cannot address the need to identify and inform users affected by any breach. Code will likely struggle to do the vendor assurance required of all your Data Processors. You're absolutely right! There's excellent reason to have the technical requirements handled for you by a framework so you can focus on the important parts of your business. It's just perhaps possible that this could be less than the whole of GDPR.
- jiggliemon 8y agoI get the process parts, that make more sense to have a human interface, can’t be abstracted out. However, maybe they can? Compliance as a service? Sounds like just the kind of Bay Area centric idea that VC’s love to fund. But it seems like there’s some commen sense patterns that our tooling should take up. A framework can take up the transparency, and user control aspects. Framework might be too narrow, platform might be more like it. Things like Wordpress, Magento or Shopify can be “GDPR compliant”.
- Kalium 8y agoYou're once again completely right! Some of this could be farmed out with compliance-as-a-service! However, it's perhaps possible that certain parts of GDPR impact core businesses processes involving the handling of customer data. None of this can be farmed out in a hands-off manner. It requires deep integration into your daily business. I cannot think of any framework that could handle such a thing, or a compliance service that could handle it for you. You could definitely offer GDPR-compliance Wordpress or Magento as a service! It's just possible, however, that some things your customers could do with your offering might hold the potential to violate GDPR. As a result, you could not guarantee that you assume all the compliance requirements on their behalf in all cases. In short, you're right! There is definitely room for some compliance services to be offered as a service! It's just, barely, possible that some small fraction of the items concerned might not be well-suited to this approach is all. Have you considered reading the text of GDPR? You might find it to be an educational and informative experience. I did.