4 ms·
How can a small website cope with GDPR compliance though? The rules that sprang up to constrain the social-media behemoths seem onerous for anyone but them to
by throwhauser 5y ago
How can a small website cope with GDPR compliance though? The rules that sprang up to constrain the social-media behemoths seem onerous for anyone but them to comply with.
- matheusmoreira 5y agoAll you have to do is not collect any data. Don't set any cookies.
- johannes1234321 5y agoSetting cookies is fine. If they are needed. You need a session cookie for the login function the user uses? - Use a cookie. No banner needed. The user puts something in their shopping basket? - Use a session cookie. No banner needed. You want to store information, not required, in order to identify the user again even though they didn't login, maybe to share the identity with an ad network? - You need a cookie banner where the user can opt out easily.
- MereInterest 5y agoNot only that, but storing information to identify the user again requires affirmative consent. GDPR doesn't just require that the user can opt out of tracking, but that any tracking occurs only after the user has freely given informed consent.
- johannes1234321 5y agoYes. If your users create an account with name and address data they need to agree to that data storage. If your shop just sells them a virtual thing there is no need to collect personal information. If you ask for the address and more or less directly print it on the label and then delete again it is a bit of an edge case where no explicit confirmation might be needed, however having a good data policy is good practice anyways and then having the extra checkbox in the order flow is not a big deal.
- WesolyKubeczek 5y agoBy not collecting data it has no need for, and not passing that data on to third parties? By providing an ability to delete any user account, and for editing any personal information? By not using EBCDIC to store said information? Are you making this more complicated than it needs to be?
- throwhauser 5y ago> Are you making this more complicated than it needs to be? I'm not sure. I guess if one trusts the default logging settings on the server software to be compliant, and only uses static HTML, maybe that's adequate? But as soon as any third-party code or data provided by some other server gets involved, it's hard to know what might be logged elsewhere as a result of visiting your site. I mean, would an old-fashioned web visitor counter be compliant? It's tracking something in order to provide that number.
- jrochkind1 5y agoYou tell us you have no idea what third-party code you add might be tracking from users. And say this is a reason why you/they should be allowed to do it? (With "it" being... anything the third-party sites want to at all?)
- corobo 5y agoYou can +1 a database `views` column without storing anything at all about the user. If you’re just doing that you’re good to go
- erulabs 5y agoI mean, most "unique view counters" store the users IP address, so that would be right out. I'm fairly sure even being aware of what complying with a complex legal documents implies constitutes enough of a complication that it's worth mentioning. It is a complication, but I believe it's worded so that small companies and individuals are immune from its consequences.
- kstrauser 5y agoAs a practical matter, GDPR doesn't apply to personal sites outside of EU. They're not going to go after some personal site in Iowa, and if they did, so what? After the massive PR debacle that would ensue, the EU regulators wouldn't actually be able to do anything about it. The CCPA doesn't apply to personal, not-for-profit sites.