4 ms·
Having worked in a US health tech start-up (and done some compliance work there), and now working with GDPR as a US company, I'm similarly frustrated with how i
by sterwill 5y ago
Having worked in a US health tech start-up (and done some compliance work there), and now working with GDPR as a US company, I'm similarly frustrated with how imprecisely the regulations are worded. US health information privacy laws are much easier to interpret and follow. Large, important parts of GDPR compliance hinge on wording like "the processing is not occasional." "Occasional" is not defined in the regulations, and different countries' advisory bodies have completely opposite interpretations about what it means.
- wil421 5y agoFeel your pain. At my last job I worked with mostly EMEA and mainly EU countries. Worked directly with our lawyers in the EU to makes sense of it all. This was right when the GDPR was looming and it was stressful to figure out how to comply.