4 ms·
I am not surprised and It’s even worse: important parts of European countries themselves aren’t ready as well. In the Netherlands parts of the taxes and even th
by digitalengineer 8y ago
I am not surprised and It’s even worse: important parts of European countries themselves aren’t ready as well. In the Netherlands parts of the taxes and even the authority that is going to do the checking.
I’ve been doing quite a few GDPR projects, even a GDPR website for a Dutch GDPR lawyer that used to be a developer and specializes in GDPR for small/medium American/Canadian SaaS and App companies. A lot of companies doing business in the EU need someone guiding them through the process and a EU Representative as well. The big companies charge you an arm and a leg. If your GDPR guy knows the tech scene and understands code and systems, it can really speed things up!
- merinowool 8y agoThis all GDPR market is all bullshitting. There are no guidances and nobody really knows how to implement it as law is vague. "GDPR guy" is a snake oil salesman.
- dogma1138 8y agoA “GDPR Guy” isn’t necessarily snake oil if you had a person or a team that their job was to work with a DPA prior to the GDPR to implement previous data protection regulations. That relationship is very important as it’s essentially a lobby. However beyond that it’s very hard to definitely make any claims and currently also use lawful basis other than consent that are not tied to pre-existing contracts. Other parts of the law like those which refer to anonymization including pseudo-anonymization, deletion and processing halt are also very tricky to implement currrently in a guaranteed manner. For example if I pseudo or fully anonymize a piece of information what is the benchmark that i need to ensure that it’s complaint? How resilient does it need to be against cross referencing? Specifically for examples how many additional pieces of information does one need to de-anonymize my information before my process is consider non complaint? Do I need only to consider information that i collect or process in this benchmark? Or do I need to evaluate my process against any potential information that can be gathered about a data subject by any other party?
- jiveturkey 8y agoThere are guidances. The ICO for example. You might misunderstand law in general. Much of it is expert guidance. For complex areas, like GDPR, you might have 3 lawyers with 5 different ideas. Most law is educated guesswork until it reaches court.