4 ms·
I'm curious what the implications are if I host a free web-app that EU users might end up using. As far as I understand, you're still subject to GDPR even if y
by theLiminator 1y ago
I'm curious what the implications are if I host a free web-app that EU users might end up using.
As far as I understand, you're still subject to GDPR even if you're not making money off it. Seems like to me there's massive overreach where the lowest liability way forward is to just ban EU users from using anything you make (which still takes engineering/time to do).
- piva00 1y agoIf you don't run a business in the EU there's no liability, you are only liable if you have users from the EU and a business entity in any EU country. Blanket bans for EU users is quite common, I see it all the time with local US news outlets, they simply block me from accessing it.
- orwin 1y agoObviously? I mean, half of the GDPR is 'if you have to store users data, make sure it's encrypted and don't sell it unless the agree to it', doesn't matter if you make money or not. But just following industry standards is enough. Like if you want to build a bridge at your own cost because the state doesn't want to do it. Even if you don't install a toll booth, you still have to follow safety regulations before people other than you can cross it, right?
- theLiminator 1y agoNot only, you also must be able to delete user data. If you have anything that could be considered PII (including IP addresses) you're responsible for potentially needing to delete that. It completely makes certain engineering patterns like event sourcing/soft deletion almost infeasible, as you cannot have immutable records. The way it's described is very fuzzy and it's 200 pages long. Certainly it's long enough that I'd rather ban EU residents than open myself up to liability even if I generally want to do the right thing with user data.
- latexr 1y agoThe GDPR isn’t hard and its application isn’t unreasonable. Just don’t be an asshole collecting unnecessary user data and you’re fine. No one’s going to ask you to delete specific IP addresses, and you don’t need to keep those forever anyway. The only people who need to fear that law are those who have no respect for user data.
- orwin 1y agoIt forces you to separate your user data from the billing data, and that's just good practice too. Keep your billing information immutable, and separate it from user logs. Honestly following GDPR make your code better. At least when it passed, it pushed us to rework our DB architecture, which was heavily needed. After that i left and got hired to implement a global RBAC in a big company (took almost two years, but it was a solo project), and once again GDPR rules made the architecture decisions a breeze, because the constraint it brings pushes for good architecture (and it make it easy to sell it to the managers to be honest). Maybe in countries where KYC and tax laws are different than in europe it might be different, but for european devs who cared about good design, GDPR was a good thing (i have a friend who worked for a French Defense company at the time, he told us that multiple teams including his spent 6 month or more refactoring old code and fixing years old issues)