3 ms·
I get the process parts, that make more sense to have a human interface, can’t be abstracted out. However, maybe they can? Compliance as a service? Sounds like
by jiggliemon 8y ago
I get the process parts, that make more sense to have a human interface, can’t be abstracted out.
However, maybe they can? Compliance as a service? Sounds like just the kind of Bay Area centric idea that VC’s love to fund.
But it seems like there’s some commen sense patterns that our tooling should take up. A framework can take up the transparency, and user control aspects. Framework might be too narrow, platform might be more like it. Things like Wordpress, Magento or Shopify can be “GDPR compliant”.
- Kalium 8y agoYou're once again completely right! Some of this could be farmed out with compliance-as-a-service! However, it's perhaps possible that certain parts of GDPR impact core businesses processes involving the handling of customer data. None of this can be farmed out in a hands-off manner. It requires deep integration into your daily business. I cannot think of any framework that could handle such a thing, or a compliance service that could handle it for you. You could definitely offer GDPR-compliance Wordpress or Magento as a service! It's just possible, however, that some things your customers could do with your offering might hold the potential to violate GDPR. As a result, you could not guarantee that you assume all the compliance requirements on their behalf in all cases. In short, you're right! There is definitely room for some compliance services to be offered as a service! It's just, barely, possible that some small fraction of the items concerned might not be well-suited to this approach is all. Have you considered reading the text of GDPR? You might find it to be an educational and informative experience. I did.