GDPR as an Indie hacker?
Hey all, how do you prepare yourself for GDPR for MVP projects? Everybody here talks about streamlining production and doing absolute minimum necessary, and yet GDPR, at least on paper, requires a lot of things. What's your minimum set of compliances for this? Thanks.
IMHO it is not that much for the tiny companies or solo guys. The essentials for me are.:
And remember that an IP adress is already personal data :-)
Your list starts ok, but having agreement with all third party tools is a bit bigger hurdle. Firebase, Stripe, etc. Do you usually just mention that you save user data there, or actually have to provide some access to that content?
There is another case, in which you become the service provider and you need to provide a dpa to your customers. For example, your a Saas is a CRM or web analytics tool. Account data is covered by your privacy policy, but you also collect data of your customer's customers like ip address, name, phone numbers, etc. If you customer must complay to gdpr he needs a dpa from you. The can be in the form of an addendum or directly in the Tos like Amazon Aws does. If this applies, I'd hire an attorney to write one in a way I can reuse for many other Saas.
If you want to comply, you must have those agreements.
As far as I know, you just have to mention that you use them and what kind of information you store. However, you need to be able to delete a customer's data on all such systems.
In Germany, the first fines were given, but honestly, they are understaffed and will probably not go after every single violation. Two main issues were not having a dpa and not having a privacy policy at all. But it also depends a lot on your country.
If I were living outside the EU, I'd not care about it at all. I'd also care less in another EU country.
The major platforms have those agreements ready and you just need to read and sign them online/mail. That did not take that much, but yep, I skip many of the fancy tools now because I don't like the hassle either. And the small ones don't have a gdpr dpa anyways.
Essentially, it depends on your risk aversion and a guestimate on how high the risks actually is.
I like great list and pragmatic approach. For me the biggest challenge was just wrapping my head around the regulations. The government advice (I was using the UK) was very dry and sometimes ambiguous. Unfortunately it's just not something you can off load to someone else.
The good news is now we understand it, and have a good footing for answering any questions from clients. The only lasting problem we've had is with a client that had an incredibly risk adverse legal team. They couldn't cope with having some data stored (Names and email addresses) in a third country. There will always be some who over interpret GDPR guidance.
I agree, it is dry, boring and ambigous. My guess is, it is intentionally so attorney have work. Many politicians here in Germany have an attorney background...
As far as I understood it, third countries can be a problem if they do not have privacy regulations of similar high standard. For example, the US is not acceptable by gdpr rules, it works only because of the privacy shield treaty and only with companies who joined and compley with the privacy shield. The big guys joined like Mailchimp, Drip, etc. so you have no problem. It might be different when using small indie Saas. If they are gdpr relevant and did not join the priv a cy shield you violate the gdpr.
Frankly, it is a beaurecracy monster hurting the small corps more than the big ones. The intention was good, the rest not. And if you get punished for a violation or not depends a lot on your country.
Yes. You’re right about the privacy shield. Companies would have valid concerns if the data was stored in a country with less reputable privacy credentials - e.g Morth Korea, China, etc. In our case the third country was the USA and all our suppliers had privacy shield compliance - the client’s legal team wouldn’t progress the deal nevertheless.
This is why it's not a great idea to target Europe or China for your MVP unless you're going all in in a local market. Start with tech-friendly regions less burdened by regulation and then expand to Europe when you have the resources to. Save China for last, because it's even tougher than the EU.
I hope it's not too late to comment. :-) A year ago I've tried to understand GDPR & Privacy Shield and explained it to the rest of my colleagues.
Check these two posts out: https://blog.uploadcare.com/gdpr-for-saas-in-plain-spoken-english-d535253efbde and https://blog.uploadcare.com/privacy-shield-as-a-shortcut-to-gdpr-c250aa99c0f3.
(It was originally in Russian, if someone is interested — https://medium.com/@rsedykh/gdpr-and-privacy-shield-in-plain-russian-for-saas-9dfa03e72f9b).
This is great, thank you @rsedykh
My wife is works in data protection, she says for small companies the primary thing you need to do is make sure you are upfront about everything you will use your users data for and make this clearly available in the privacy policy or TOS. Also make sure to adhere to the basics like opt-in marketing if you are collecting emails or physical addresses.
Whilst GDPR documentation is pretty lengthy, it's not as daunting as you think . The first thing is that you are thinking about it and that's already a plus. You want to go through the 6 principles and use this as your framework. The main thing in dealing with personal data you collect (aside from informing your customers via privacy/cookies policy) is to know how and where this data is. A good way is to create a data map and inventory - The whole process needn't be complicated, it really is just best practice - this short article might help further https://siteimprove.com/en/gdpr/personal-data-inventory-data-maps/
Great, thanks for the link.
According to the articles I've read, the bare minimum would be to inform the user who to email when they want to download their user data or delete all their data from your system.
Is there a good place to find out what you need to do? I even searched for gdpr as a service and couldn't find anything that seemed good for me.
There's little point in gdpr as a service since it's something you have to do yourself as it's heavily dependant on services you offer and data you collect. Adding third party here only complicates everything even more. That being said, there are companies that advise on gdpr for each case, but it costs a bit more.
Have a good privacy policy accessible through your landing page. GDPR really isn’t a lot of extra work if you’re adhearing to proper privacy principles.
I believe that privacy is something that's easy to do if you think, but the hard part is actually documenting it and showing to users in a way that it's compliant and that noone can't give me any trouble about it, even though all actual practices are good.
This comment was deleted 6 years ago
Harder to do this when you live in Europe :D
I agree, this is pretty destructive advice, especially since I'd block myself with that :D