4
12 Comments

Do you worry about GDPR readiness for your side project?

Before you launch your side-project (even beta launch) do you worry about GDPR compliance? Is that something you need to check before testing product-market fit for your side project?

  1. 3

    We don't worry about gdpr, because we decided not to offer out services to European users (compying with all EU regulations is just a huge time drain). I'm an European myself, but registered my company elsewhere for exactly same reasons.

    We launch in US first to figure out market fit, but also US alone is big enough market for us.

    I have another project that I do with my wife, and we again - starting out in Asia first (and I'm not really sure if we will go in Europe with it at all).

    1. 1

      How do you prevent EU visitors from signing up?

      1. 1

        One project I do is store builder (b2b), we show region during registration. So basically any EU members can register, but that store will only operate with US customers. It could be in violation with GDPR, but I don't really care - my company is in Asia.

        Project with my wife is B2C, we don't allow people to pay for a service if it's not in a whitelisted country (currently, Thailand only). We figure this out based on shipping address they provide.

        1. 1

          Ah I see. Quite interesting! Thanks for the tips.

  2. 2

    GDPR compliance is not that much of a burden if you design your side project correctly from the start. I read through the regulations before they were enacted this year and summarized them here: https://amberstone.digital/2018/05/08/what-small-businesses-need-to-know-about-gdpr/

    There's still a couple of gray areas, and the office responsible for GDPR has repeatedly said they're a lot less interested in issuing major fines than they are correcting the behavior of the industry. For instance, if you launch a product aimed at the US market, priced entirely in USD, and you have a bog-standard double-opt-in process for your newsletter, you're already like 80% of the way there.

    1. 1

      That clears up a lot of confusion. Thanks for the article.

      1. 1

        Glad it helped! The truth is that it'll still take a year or two to see how GDPR is actually implemented in practice. I'm pretty sure it'll just end up being another consumer protection thing - people will complain, you need to address it, you need to have certain boilerplate templates and wording on your sites, but otherwise things carry on as usual.

        The only significant disruption is if you've operated for years without caring at all about your customer's data, in which case it'll be a painful change to comply.

  3. 1

    I'm working on a new product, GDPRvalet.io. Mind if I ask you some questions to validate my assumptions?

    @shoaibalich @skatkov @petr17102018

    1. 1

      Sure, ask.

      1. 1

        Thanks. Sending you a DM via Twitter.

  4. 1

    I worry about GDPR in a sense that I will describe data handling in Privacy Policy and Terms of Service, I will ask for permission to send marketing emails and I will offer users to completely delete their data from my servers. I think that all of these things are good for the users generally and required in EU so I will do them for my products.

    I will also have a section about website analytics and cookies in Privacy Policy, but I don't really want to put an annoying popup on the web, so I won't. The Czech law is currently slightly different than the official European one, so it might as well be still legal. I wish EU would do something about the popups (cookie opt in automatically for normal website analytics ) - they are super annoying.

    That being said, I also run some small older content websites/blogs and I haven't adjusted them for GDPR in any way.

  5. 1

    No, if you work sensibly with the data you get gdpr is not an Issue. I run several affiliate blogs in Germany and my amount of changes was minimal.