3 ms·
> GDPR is easy to implement once, but it is constantly changing every year. No it’s not. If you’re running an online store, compliance is pretty straightforwar
by scott_w 1mo ago
> GDPR is easy to implement once, but it is constantly changing every year.
No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that.
If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if you’re informed they changed.
For store analytics, your cookie banner covers you, the major players all integrate into standard tools, and they keep their compliance up to date, so you’re fine there.
Small mistakes are very much not punished. Your country’s Data Commissioner equivalent will want to see you try to be compliant first. You’re only going to get put out of business on a first offence if you’re taking the piss. I guarantee any example you provide me as evidence will be exactly that, but feel free to try.
- throw8484949ii 1mo ago> the major players all integrate into standard tools, and they keep their compliance up to date, I am not major player! I do not have dedicated team of people to keep "compliance up to date". > if you’re informed they changed Yet more extra work! > see you try to be compliant first Sounds like work for extra GDPR officer! I do not have that kind of money!
- scott_w 1mo agoBy “major player” I meant the analytics companies that you pay, not you. > Yet more extra work! If “customer asks me to update my records on them, so I do it,” is too much work then you really shouldn’t be in the business that requires it. > Sounds like work for extra GDPR officer! Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.” Seriously, all your answers here tell me you’re trying to do some shady shit and not even making money from it. If you were a simple retailer, as your original post implied, you would not be worried about the complexity of handling GDPR.
- throw8484949ii 1mo agojust because I have small profits, does not mean i sell drugs! (But drug dealer would probably get better deal from police for breaking GDPR). I am worried about several thousands euro fines! I have my own eshop, i do not use "major player"! Too expensive. > Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.” And than you get different offical, with different opinion. Their advice have same weight as weather forecast!
- scott_w 1mo ago> just because I have small profits, does not mean i sell drugs! I never said anything about drugs. I’m talking about doing illegal things with people’s data. > And than you get different offical, with different opinion. Their advice have same weight as weather forecast! If you’re getting audited this often you are DEFINITELY playing fast and loose with the rules. I have no sympathy for you.
- throw8484949ii 1mo agoYou said "shady shit"! Deleting some data a few days/weeks or months latter too late is not "shady shit"! You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides! Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects. And small eshops are easy targets for fines. Large corporations are untouchable.
- scott_w 1mo ago> You said "shady shit"! Look, I don’t think English is your first language, so I’m trying to give you the benefit of the doubt but it’s getting really tiring having to explain basic things like “context” to you. I’m obviously meaning in the context of data governance. I’m accusing you of selling customer data to unscrupulous characters, to be precise. > You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides! Either you’re bullshitting me or you live in Eastern Europe and need to give kickbacks to stay in business. If the latter, that’s not the GDPR’s fault. It’s the fault of your government for not being able to draft law. > Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects. That’s not the GDPR, that’s your country having a poor grasp of how to make law. It’s a different problem and I’d recommend either lobbying your local representative or just leave to a sane country which will let you do business.