Is GDPR necessary for small niche sites ??

The problem is that GDPR applies to EU citizens even in US. So how do you know your visitor is from US? Having an US IP doesn't mean they are not from EU.

That is a bunch of bs, the EU doesn't override the law of others nation that their citizens are travelling in.
 
@ExperimentalSEO you might as well read up on the subject. The whole idea of the law is to protect citizens, wherever they are. It's no bs at all, the United States practices that (not in data protection, mind you) since as long as I live (and that's a very long time). An American tourist got harmed in my country? The local company gets dragged in front of a US court.
Now, if you say "I give a damn about those guys over there, I just don't appear in court", fine. But what if you have economic interest there? Or want to travel there?
 
Overriding laws of other nations as a traveler is the most insane thing I've heard in a long time. Even the Europa's answer on GDPR doesn't go that far.


Who does the data protection law apply to?
The law applies to:

  1. a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or
  2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU.
https://ec.europa.eu/info/law/law-t...ulation/who-does-data-protection-law-apply_en
 
It costs virtually nothing to be compliant, but it will cost thousands in legal fees if someone wants to test the law against your site.

Once a few test cases have been tried, we'll have a better idea of what liability (if any) non-EU websites have in regard to this law. But until the case law is established, I'd prefer not to become one of those test cases.
 
They won't spend as much time as you will with lawyers

That is only to scare people, in the reality nothing will happening. Give a little months and you will see, everybody will forget about that.

Do you think they will search one by one to see who don't have GDPR policy applied on their websites, blogs and others?

This is like a cookie notification in the beginning all blogs using that, today i didn't any fees OR legal threats against blogs, forums and others

And there are a manyyyy but mannny websites without that incluiding my own.

Just have privacy policy, terms of service is enough.

Paying a lawyer lol, Offshore Hosting and you are fine, you can make it more harder and host it on Ásia.

Even Facebook and instagram don't follow GDPR and others laws allowing Child <15y creating accounts and uploading photos...

Are you sure about you are saying now my friend? I really have my own doubts.
 
Overriding laws of other nations as a traveler is the most insane thing I've heard in a long time. Even the Europa's answer on GDPR doesn't go that far.



https://ec.europa.eu/info/law/law-t...ulation/who-does-data-protection-law-apply_en

Thanks for digging that out, it is however not complete. You need to know that the "in" doesn't refer to where these citizens are at the moment of service but where they were targeted. So, if I'm a European travelling to the States, and a travel agency has done adwords targetting e.g. French to take their "French Heritage in Mississippi" tour, this US company needs to comply with the GDPR.
Not that I believe this will be a major use case, and chances to get a complaint are probably minor, but because you mentioned "traveler" a couple of times, I thought I'd make it clear that yes, travelers are also protected by the GDPR in certain cases.

One more word about getting caught, fines etc. I don't believe that any EU law enforcement group will come after you, but the question is: do you have competitors that would like to see you get in trouble? And as so many before me have commented, complying takes so little effort....
 
Takes 5 minutes to implement, might as well do it


This ^^ sums it up.

Yes it's a legal requirement, however it's upto you if you choose to ignore it.
Get caught - don't come crying if you get a fine .
Take 5 minutes to activate a plug-in and job's done.


I have to say it's a new regulation, there's no test case or legal precedent been set that I have seen ( although not actively looking ) so it's still all in the air just now. If/when they decide to hand out fines, it will no doubt be bigger businesses who they'll go after first.
 
That is only to scare people, in the reality nothing will happening. Give a little months and you will see, everybody will forget about that.

Do you think they will search one by one to see who don't have GDPR policy applied on their websites, blogs and others?

This is like a cookie notification in the beginning all blogs using that, today i didn't any fees OR legal threats against blogs, forums and others

And there are a manyyyy but mannny websites without that incluiding my own.

Just have privacy policy, terms of service is enough.

Paying a lawyer lol, Offshore Hosting and you are fine, you can make it more harder and host it on Ásia.

Even Facebook and instagram don't follow GDPR and others laws allowing Child <15y creating accounts and uploading photos...

Are you sure about you are saying now my friend? I really have my own doubts.
OK being a defiant keyboard warrior is all well and good, but complying also builds trust. I have a right to be forgotten form on all sites I run, so visitors can see it's totally transparent.
This is so simple to do except for you revolutionary types lol!
 
OK being a defiant keyboard warrior is all well and good, but complying also builds trust. I have a right to be forgotten form on all sites I run, so visitors can see it's totally transparent.
This is so simple to do except for you revolutionary types lol!

My friend do you think, is easy to takedown or enter in legal battle? Remember one thing, Likewise you start a legal battle in court. I can likewise ask for money compensation if I win in court. You can ask for indemnity lost time, lost money and associated costs.

Always remember that. If you think is only "pressing" any button and shutdown the website or going to court is easy, think again. Like I said, if you lose and if you don't have any valid proof against me, I can argue for indemnity in the case, you lose. And that is bad very bad ;)

Ahhh and yes you have the right to be forgotten, but if is a blog of health, or other something? You don't have account, you don't have any data from you. Except IP, Hostname, Browser version, Country.

There's no name or address associated with that, so this maybe only applies to forums, social media and others website that allow to create a account.

I'm not saying that we shouldn't respect any GDPR Guidelines, but they don't will do nothing related with new websites or blogs with less than <1000 visits per month. ;)

And Like I said, I didn't have cookie consent for more than 1 year and nothing happens, and I know a lot of owners of blog, forums that do the same and nothing has been happen.

Why? They forget the law of cookie consent!? Can you answer my question? Ooops..
 
My friend do you think, is easy to takedown or enter in legal battle? Remember one thing, Likewise you start a legal battle in court. I can likewise ask for money compensation if I win in court. You can ask for indemnity lost time, lost money and associated costs.

Always remember that. If you think is only "pressing" any button and shutdown the website or going to court is easy, think again. Like I said, if you lose and if you don't have any valid proof against me, I can argue for indemnity in the case, you lose. And that is bad very bad ;)

Ahhh and yes you have the right to be forgotten, but if is a blog of health, or other something? You don't have account, you don't have any data from you. Except IP, Hostname, Browser version, Country.

There's no name or address associated with that, so this maybe only applies to forums, social media and others website that allow to create a account.

I'm not saying that we shouldn't respect any GDPR Guidelines, but they don't will do nothing related with new websites or blogs with less than <1000 visits per month. ;)

And Like I said, I didn't have cookie consent for more than 1 year and nothing happens, and I know a lot of owners of blog, forums that do the same and nothing has been happen.

Why? They forget the law of cookie consent!? Can you answer my question? Ooops..
That's not a question but a rant. As I said earlier this has been discussed at length on other threads, so best leave it as it's taking over op's thread. I'm out
 
My friend do you think, is easy to takedown or enter in legal battle? Remember one thing, Likewise you start a legal battle in court. I can likewise ask for money compensation if I win in court. You can ask for indemnity lost time, lost money and associated costs.
Lawsuits aren't won by being right, they're won by whoever has more money and more lawyers to throw at the problem. Since I have less money and fewer lawyers than whatever EU organization is going to be pursuing these lawsuits, compliance is the far cheaper option.

If you're so certain that these cases are an easy win, perhaps you could create a BST offering anti-GDPR legal defense, and fight these cases for BHW members in exchange for half the winnings?
 
I read somewhere that they first warn you, the owner, then report you and try to suspend your data and finally, sue you or whatever. But in reality, time will tell if this is really the case.
 
Haha. If the EU is going to spend all of it's time trying to find GDPR violations on sites with less than 1,000 daily visitors, then the government needs to be reevaluated.
The problem isn’t the government, the problem are the users and visitors itself. They can sue YOU if you don’t have a GDPR Privacy Policy statement in your website and and you’re in your obligation of paying them. The problem here isn’t the government, are the visitors since they can take a really great sum of money off making sues.
 
The best solution is to follow GDPR and use its loopholes but charge EU residents more and donate that extra charge to eurosceptic organisations.
 
It's always better to be safe than sorry. Even if you don't particularly care about GDPR and what it stands for (although you should), since it isn't going to take a lot of time or effort to comply, you might as well do it.
 
Back
Top