4
5 Comments

What are your concerns about data security? has GDPR changed your opinion?

I am trying to understand how small and medium businesses are thinking about data security.

Storing personal data has an associated risk. Data leaks can be harmful for your reputation. Customers can be put off your product when asked to provide data consent. Finally GDPR has financial consequences for failing to protect data properly.

My questions are:

  • What is your approach to data security? are you using external services, have you got legal advice.
  • Do you think how you handle data will affect your customers opinion of your service product?
  • Does the operation of your business rely on knowing personally who your customers are? For example flights require passport information but twitter doesn't need to know anything about you.
on October 7, 2019
  1. 1

    Data security is extremely important.

    We handle this by making sure we’re following basic smart procedures with our site logins, databases, etc - enforced SSL & HTTPS where possible. On the internal side we keep as much data out of the cloud as possible. One thing I want to be sure of is getting better at encrypting our backup hard drives (physical copies).

    Customers are more and more concerned about privacy, but I don’t think they care as much as they should.

    Yes, we do need to know who our customers are. We store payment info as well as tax information.

    GDPR - we’re not European so that hasn’t even crossed our peripheral vision.

    1. 2

      On the internal side we keep as much data out of the cloud as possible.

      Are you trying to minimize the data your hold or is it more the case that you make sure data is on machines you hold.

      Yes, we do need to know who our customers are. We store payment info as well as tax information.

      Does this mean you don't use services like stripe that would allow you not to have to store payment information

      1. 1

        We don’t use Stripe, but we do use merchant services for some credit card transactions.

        However we actually do need to have payment information on hand because some of our customers pay through wire transfer or ACH.

    2. 1

      For other readers, keep in mind that GDPR doesn't just apply to companies within the EU, but also to any company doing business with the EU, including just having users based in an EU country.

      1. 1

        We don’t go out of our way to market to EU users, but we definitely don’t worry about being GDPR compliant.

        Argentina and Japan and Turkey also have data privacy laws which you’re technically supposed to abide by if your users are there, but does anyone bother unless they’re based there? We can’t comply with every country’s laws, so we’ve chosen to stick with the laws of our own jurisdiction.