6
10 Comments

Ask IH: Are you guys doing anything for the GDPR

I saw a few of the sites that I subscribe to telling me that they have updated their privacy policy for GDPR (General Data Protection Regulation, https://en.wikipedia.org/wiki/General_Data_Protection_Regulation). Out of curiousity, just wondering if you guys are doing any changes for your sites/ apps? Could you be at risk if you dont make changes?

  1. 7
    • You need an updated Privacy Policy. 99,999% chance that your old one isn't compliant.
    • Add a list of third-party processors (and what types of processing they do).
    • Add paragraphs to comply with the rights of the data subject (chapter 3 - handling these requests via email is OK, don't overcomplicate it).
    • Define your legal basis for each type of processing you do (biggest ones: legitimate interest and explicit consent).
    • For those that aren't legitimate interests, you now require consent (request: explicit, granular, opt-in) and you need to store consent (store consent, store timestamp of consent, store the exact text they opted into).
    • Make sure your cookies are compliant: only use cookies where you have a legitimate interest. Cookies that aren't legitimate interests can only be used with explicit consent.
    • And so on... There's more I'm probably missing right now, but I'm on mobile and this is off the top of my head. :)
    1. 1

      Thanks Sebastien for this detailed info. Didn't know that it takes that much to be compliant.

  2. 1

    I spent $15 and got a custom GDPR-ready privacy policy from https://getterms.io.

    1. 1

      Hmm this in interesting... do you think it would be worth it?

      1. 1

        I think it covers my bases well.

  3. 1

    Having to make changes for some decade old legacy php app today was fun. I always get a chuckle out of reading decade old php code.

  4. 1

    IANAL but I think the chances of the vast majority of Indie Hackers being audited and fined by the EU are pretty close to zero. That's not to say you shouldn't comply of course, many of the principles behind the regulation are good anyway IMO.

    Personally, I have just stripped the end of the IP addresses that my analytics tracks and made acceptance of terms, privacy policy and use of some third party tools more explicit. I spent much more time figuring out how to be compliant than actually doing it.

  5. 1

    Just added Export my data and Delete my account today!
    My website: https://hidifferent.com

    1. 1

      i already have the Delete my account, and adding export my data
      what about the freez/unfreez?
      also any idea what data other than the profile information need to be downloaded?

      1. 1

        I'd need to check more about the freez/unfreez.
        Currently I also include posts and comments.