Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For EU-based business: The DPA of your country is responsible for you.

For non-EU-based business: Appoint a representative in the EU. The DPA of that representative's country is responsible for you.

So where do the other 20+ DPAs come in? They might be responsible for your customers - in which case, they'll contact your DPA and sort it out among themselves. You still won't have to become an expert in the nuances of Bulgarian, Swedish and Portuguese privacy law.



> they'll contact your DPA and sort it out among themselves

No, they won’t. They’ll help you coördinate. You won’t have to become an expert in other bodies of law, but you will need to responsive to them, which is time consuming, distracting and—if you’re running a real business—expensive.

I’ve seen this deployed to remarkable efficacy, with asymmetry in defence:deployment cost in excess of 10:1.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: