3 ms·
If you just aim to provide static content, i.e. public web pages and articles I think you’d really have to “go out of your way” to break GDPR (which in this cas
by e_proxus 6y ago
If you just aim to provide static content, i.e. public web pages and articles I think you’d really have to “go out of your way” to break GDPR (which in this case is likely tons of ad network code among other shady things).
- eli 6y agoDoes your web server create logs that contain IP addresses (as most do by default)? Now you’re processing PII according to GDPR. Do you include any assets at all that are hosted by a third party who therefore have access to IP addresses? Do you have the necessary DPA with them plus your web host? Do you have a compliant privacy policy, data retention policy, breach notification policy? Have you named a data privacy officer? Do you have a written process for erasure requests? You’re probably right that the ads are a problem but ain’t nobody getting GDPR compliance for free.
- jeroenhd 6y agoGDPR compliance is no different from any other kind of compliance. If you're a big publication then you've got more than enough legal people walking around the office to make sure you aren't accidentally printing something that can be construed as libel, to ensure that you're paying your taxes correctly, to check new employee contracts, etc. Besides, most websites need to update their privacy policy to be accessed in California anyway. The Californian privacy protection rules aren't as strict as the GDPR, but they are very similar. I don't really buy the "it's expensive to comply" argument a lot of American companies seem to use because of this. The companies want to collect and trade your personal information to the highest bidder, the GDPR got in their way and now these companies are acting out.