While technically not wrong, some of it is so misleading that the reader might be less informed about the law than when they started.
I wish I had a better option than just reading the text of the law, but most explainer sites I've seen have been misleading, confusing, biased, incorrect or generally not so good.
I've been using this[0] reference—basically the text, but better organized.
- what it is your startup does
- how you process user data
- what third parties - if any - you draw upon to process that user data
If you process any user data at all (of users currently located in the EU, that is) the very least you need is:
- a privacy policy
- a list of your data processing activities
- a list of your technical and organisational measures for protecting user data
- a data processing agreement with every third party that processes user data on your behalf
What's your startup? GDPR's burden on you is going to be different depending on how much and what kind of user data you handle, why you handle it, and for how long.