6 ms·
My guide to being GDPR compliant: don't do business in the EU. Much simpler.
by simplysimple 8y ago
My guide to being GDPR compliant: don't do business in the EU.
Much simpler.
- scrollaway 8y agoHow not to pay taxes: don't sell anything. It's a foolproof plan really.
- Silhouette 8y agoHow not to pay taxes: don't sell anything. You jest, but this is exactly what at least one of my businesses is about to do. We are in the UK, so Brexit uncertainty dominates any sort of EU-related planning for the next few months. The EU VAT rules for digital sales were already full of complication and red tape, and right now we don't even know whether the existing UK government systems will still be operating after the end of the current quarter on 31 March because it might all disappear with Brexit on 29 March. When we took professional advice on how to prepare for this as well as we can under the circumstances, no-one in the room had any confidence in what little formal guidance exists so far or that the official positions currently set out by either the UK or EU governments will be realistic when the time comes. The consensus (by which I mean "view strongly advocated by literally every professional advisor in the room") was to suspend sales to rEU states until the dust has settled, and just redirect our efforts and finite budgets towards customers elsewhere in the meantime. That will inevitably involve some short term financial cost, but then so would making major changes in our technical systems and accounting practices at short notice to comply with all foreseeable possibilities at the start of April. I don't find it inconceivable that lawyers in places like the US might give similar advice to some clients regarding the GDPR for similar reasons. If the clients are primarily dealing with data subjects outside the EU as well, avoiding the entire area as much as possible might be a reasonable position to take, even if again it's only temporarily until there is more known about the real implications of the GDPR as guidance and the first enforcement actions start to resolve the uncertainties.
- alliecat 8y agoHang on a sec, I'll move my EU-based company's entirely EU customer base as well as all of our EU citizen staff and EU-based suppliers... oh wait.
- hennsen 8y agoThanks for staying away! If you’re not interested in caring about our privacy and personal data concerns, you‘re very welcome to shove your products up to where the sun doesn’t shine...
- Shebanator 8y agoThese kinds of responses are unhelpful. Yes, data protection is incredibly important. That doesn't mean that GDPR as written is a well-done regulation - in point of fact its insanely complicated and its pretty much impossible to know whether or not you comply, even if you store zero data about users. It also doesn't mean that people who don't want to deal with GDPR don't care about privacy. Tarring and feathering someone for such things is lazy and unfair.
- simion314 8y ago>its pretty much impossible to know whether or not you comply, even if you store zero data about users. Can you explain how you store Zero data but you are not sure? Are you referring at the fact that you include third party code or use third party services? The fact that the laws are not simple is because they need to define things very specifically to make it impossible for "clever" people to interpret them different then the "spirit oft he law"
- Shebanator 8y agoServers have logs, which can have a lot of personal data in them. Not all of that logging is under your control, especially if you rely on 3rd party services like AWS. This is a simple example but there are many more.
- scaryclam 8y agoWhat logs are you thinking of? There are none that I can think of that require a lot of personal data. IP address storage is explicitly covered provided you log them for security etc.
- tivert 8y ago> My guide to being GDPR compliant: don't do business in the EU. > Much simpler. As an American, could you please tell me what businesses you run, so that I can make a note to avoid dealing with them in the future? Thanks in advance.
- fixermark 8y agoIt's going to be funny when we learn he works for the IRS. ;)
- simplysimple 8y agoMy company is over and above compliant with the requirements of the GDPR - not because we bothered to give a crap about the EU, but because we did it on our own years in advance, of our own volition and the need for heavy data protection. As an American, I'm suprised you aren't skeptical of a foreign government trying to control what you do.
- matthewmacleod 8y agoSounds amazing, to be honest. I'm quite enjoying the weird interstitial pages from a variety of US-based sites that block EU users. It's like a massive billboard saying "WE ARE USING YOUR DATA IN WAYS THAT YOU DON'T CONTROL", and is a reminder to use other services elsewhere. GDPR is relatively straightforward to comply with, particularly for the simpler kind of sites that don't seem to have bothered. It basically codifies the sort of best practice that should have been in place already, and I'm sure many of us are happy to see that there is movement towards regulating the disastrous dumpster fire of personal data in this way.
- kasey_junk 8y agoIt’s not at all simple for ad supported publishers who are the most prominent users of the blocking. It maybe a case where this is the intended consequence of the law but it wasn’t sold that way ahead of time. European publications are being even more impacted by this as they can’t resort to blocking. It will be very interesting how this impacts the publishers in the next few years.
- JAlexoid 8y agoHere's the kicker - most European online publications were already in compliance. GPDR is only slightly more stringent, than most EU privacy laws on file. The biggest complaints come from foreigners, if you haven't noticed.
- kasey_junk 8y agoNo one knows if they are in compliance or not yet. For instance https://www.bankinfosecurity.com/fresh-gdpr-complaints-take-aim-at-targeted-advertising-a-11487 https://www.bankinfosecurity.com/fresh-gdpr-complaints-take-... outlines a complaint that all of real time bidding that is compliant with the IAB compliance framework is not compliant with GDPR. Major publications, for instance Der Spiegel, which are trying to be compliant by following that standard (and they had to do major work to do so) may find they are out of compliance http://www.spiegel.de/extra/what-we-do-with-your-data-a-1211940.html http://www.spiegel.de/extra/what-we-do-with-your-data-a-1211... Similar complaints have been brought against publishers that used googles compliance framework.