Although a UK Citizen, will be bootstrapping the startup in the US and simply blocking EU buyers from accessing the site.
Why you may ask?
- I don't have the funds to hire a DPO.
- I don't have the funds to hire out an expensive company to go through the platform in minute details and prepare it for GDPR.
- I don't have the resources to deal with inquiries to that nightmare letter or any questions for that matter.
- I don't have the resources to monitor the 3rd parties privacy policies that I send data to use their service and constantly update my own.
From my perspective this is just burdens my company with more costs in doing business with the EU. I'm more than happy to concentrate on the US and the rest of the world.
One issue that I'd like to point out as well. Some commentators mention that the EU is ~22-25% of the worlds GDP to be accessed. Well, that's a complete fallacy.
The EU unlike the US isn't a contiguous block. There are 28 nations and 24 languages to deal with. You simply can't launch in the EU like you would in the US. Each country has it's own idiosyncrasies to deal with. Which is why some companies just launch in France, Germany, UK and then push out the other smaller markets years down the line and in some cases not at all. There may be other local regulations to deal with.
My opinion is that the GDPR over the long term, will hamper the ability of EU companies to do business on the world stage, even more than currently. But that's a completely different topic for another time.