740 karma · joined October 2, 2012
A better solution would be a webpage, hosted by the state of Idaho saying "Here's what we're after, don't do these things, and you're in no danger." Followed, hopefully, by a list of things that you weren't planning on doing anyway because you're not a jerk, and that are crystal clear so you don't have to speculate about how selective the attorney general of the state of Idaho is in prosecuting these sorts of crimes.
But I was an american being advised by a top tier british law firm. How is a random guy releasing free (or cheap) services on the internet supposed to deal with a situation like that? The arbitrary nature of the enforcement is exactly what makes this a problem. If there were strong penalties, but clear ways to remain in compliance, this developer might have made a different call.
If I know I'm technically out of compliance, and I don't have a high powered lawyer telling me it's not a big deal, then I'm not sleeping well. And if I can solve the problem once and for all by taking the unfortunate step of simply cutting EU residents off of the service, then I'm going to at least consider that option, and probably take it in the short term.
If the EU wants to reassure people that "The regulators send a letter asking you to come back into compliance unless you've been really bad. They only move to fines if you ignore them." then they would be well advised to make that very clear. If they don't, you're going to see more of this, and really, if it's true, why wouldn't they?
EDIT: Turns out the US-style kinder eggs are indeed available outside the US.
IANAL, but I was a licensed real estate agent in NYS about 15 years ago, and this was covered in the course materials.
1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity.
This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enforcement? I suspect not, but perhaps there's a business opportunity in giving them the opportunity to do so. Sort of a GoFundMe for peer-to-peer insurance.
2) The GDPR is all about not being a jerk with your users' data. As long as you don't do that, and do relatively minor things X, Y and Z, you're totally fine.
This flavor of argument might actually be true, but if I'm assuming the risk I'm probably going to want to hear it from someone with skin in the game, like a lawyer, who I can point to if it turns out to be false. Even if I had the desire to read through the law (I don't) and understand the specific implications for my project (I wouldn't), the very act of doing this represents a cost that I could more simply avoid by excluding EU residents from my service. I'd choose the latter path every time, and put "support EU residents, check into the legal implications of GDPR" on the roadmap, for "someday".
3) You're exposed to millions of risks anytime you do anything. This is just one more and you're making a big deal of it.
Often this accusation comes with a subtext that you're trying to prove some political point, suggesting that you're making a decision in bad faith to "punish" the EU. Well, I personally think something like the GDPR is needed, and have no particular axe to grind, but I also have no idea if the legal exposure is serious, and no particular desire to put in the work to find out.
Yes, business, or really any activity, involves legal risk. In this case though, the risk is pretty serious, first of all because the penalties (20M Euros max) are serious, and secondly because it will be very difficult to claim that you've never heard of the GDPR. If Tonga creates some law impacting side hustles on the internet, at a minimum I can credibly claim to be unaware of that law. The GDPR on the other hand has been all over the news for weeks. I've clearly heard of it (especially now that I've commented on a discussion of it on HN).
My feeling is there's a real risk that this law will lead to a general practice of non-EU individuals, and non-EU startups launching MVPs to at least temporarily block the EU to avoid unnecessary risk. That's not the intended purpose of the law, but laws have unintended consequences all the time. If the EU wants to avoid this unintended consequence they should provide a clear, objective, and cheap (in terms of both time and money), set of instructions that will allow projects like monal to continue operating there. If such a set of instructions exists, I haven't seen it.