3 ms·
Ugh, I feel like this is a common and overly simplistic take. While it's definitely true that GDPR is harder to comply with if you're doing a ton of evil shit o
by nsp 8y ago
Ugh, I feel like this is a common and overly simplistic take. While it's definitely true that GDPR is harder to comply with if you're doing a ton of evil shit or selling user data, it can definitely be quite onerous to comply with even if you're not.
The company I work for (Teachable) is a specialized site builder for course content. We make all of our revenue from people either paying us directly for a plan, or transaction fees on people buying from our customers, no ads or data selling. Nevertheless, complying with GDPR still took well over a month of some of our best engineers time. Even if you don't sell data, the odds you had a plan prior to GPDR for how to handle right to be forgotten - how do you delete PII (which is defined broadly, including ip addresses) from db backups without ruining their integrity? If you use something with an immutable log, like Kafka, how do you remove the data there? Etc, etc
- twblalock 8y agoPlus, even if you do all of those things properly, you will still need to field GDPR data requests, and when you tell users that you don't have any data, they might not believe you. You also might be falsely accused of violating the GDPR, and just saying "no we aren't violating the GDPR" without relying on legal advice is not a good approach if you care about the future of the company.