You have a few hundred customers and maybe 10 of those are in Europe.
Would that company need to worry about complying? How much should they worry?
You have a few hundred customers and maybe 10 of those are in Europe.
Would that company need to worry about complying? How much should they worry?
1. It's becoming a checkbox buying issue for EU customers. Depending on what data you have, what you're doing with it, the fact that you aren't GDPR compliant may mean that your EU customers aren't GDPR compliant b/c they use you.
2. At some level you should care about the security and privacy of your users and while far from perfect the GDPR is a good general framework.
3. Unlikely is not the same as none. Given the tremendous technical leverage that exists now, it's not crazy to think that even a small SAAS with a couple hundred customers might have tens or hundreds of thousands of personal records. (consider an email newsletter service with 200 customers each of whom have 5,000 subscribers -> 1 million personal records).
If you have a million records on hand and a data breach happens, it's quite likely someone is going to complain and you might suddenly be on someone's radar. Don't take that to mean "omg, if I have a databreach I could get fined for $$$$". Because it's much more like: if you have a databreach and you haven't done a good job securing the data or letting people delete it or have some clear data handling rules and you failed to report the breach you might be in trouble.
* https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Which requires the organization to supply information about use of personal information. This will have an operational overhead regardless of scope of Personal Information used.
For a worse-case (hopefully impossible) variant of what this request looks like: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
Oh please somebody correct me if I'm wrong. Otherwise that's a silly amount of operational overhead for bootstrapping. Even for systems designed from the start to not use personal data: The org would still need to handle a rather detailed and costly administrative request.
You need to worry and you should probably just refund them and block them from your service.
The scary stuff is what happens if you have thousands of customers and they start requesting deletion or information. But if you only have a hand full of EU customers you can wait till that happens, you only have to comply within a month.
EU regulators are generally very reasonable. If you show that you made reasonable effort but had a genuine mistake they will generally give you a warning or at worst a low fine.