How is everyone approaching implementing GDPR?
We have a freemium business model, and the contract requirements + EU Member State Representative requirement ($$$!) are causing me to wonder if we need to rethink that model for GDPR-subject customers.
Take a look at our series of GDPR articles, the first one is here: https://www.gdprhq.io/post/how-the-new-european-general-data-protection-regulations-gdpr-will-affect-your-business
We're developing a SaaS solution for GDPR for small businesses, currently it's in a beta, should be production-ready soon.
are there any sites or resources on how GDPR affects startups? Especially those not based in Europe? Do we need to just shut access for Europeans?
Not that I can find specifically for startups. There are some general guides for developers that have been floating around ex https://techblog.bozho.net/gdpr-practical-guide-developers/
Non-EU companies still need to comply if a) we have any EU customers and/or if b) our customers are sending any data to our products that have data from EU citizens. There is no startup or company size exemption. The fine for not complying is 4% of revenue or 20M euro, whichever is greater.
I have seen a couple of companies trying to shut off access for Europeans (one simply stated in their TOS that users won't upload GDPR-subject data). Works for some companies, but probably not most of us.
how does GDPR affect tiny sites like designernews or indiehackers (yeah I know they're owned by Stripe, but what if some guy decided to put together a similar forum)? Does it effectively make most sites like this illegal if they don't spend the large amounts of effort to adhere to the rules?
Also, what does enforcement look like for tiny forums like indiehackers?
I'm curious if this will open up other countries wanting to start to enforce similar rules (e.g. China adding a law that every site needs to send all the data to China for filtering or whatever) and how companies would deal with that?
From what I can find, anyone with EU users is impacted. Most of the regulation from a "data controller" perspective is not too onerous if you have things like simple user accounts. Probably the biggest change for a forum like IndieHackers would be to let people download/delete all of their data (including deleting it from third party services like Google Analytics) and stating in "human terms" how it is stored, as well as receiving a double-opt-in paper trail for email/contact consent.
It's unclear what enforcement means for small companies. At this point, everyone is subject to the 4%/EU 20M fines. From my non-lawyer read of things, unclear how an enforcement action would take place.
Yes, that could be quite the minefield if each country decides to implement their own rules.