Hacker News new | ask | show | jobs
by nannePOPI 2991 days ago
if I have a forum I store the email of the users so they can recover the password. Same thing if I put up a simple newsletter to contact my users, I have their emails (newsletters may not be fashionable but they're much more effective than using a facebook page or other systems, since you own the email list of people who want to hear from you).

So, even in the boring world of small websites, you have to comply.

2 comments

> if I put up a simple newsletter to contact my users, I have their emails

Okay, so then the only requirement of GDPR is that you must make the newsletter opt-in rather than opt-out and you must make the unsubscribe process as easy as the subscribe process.

This is indeed a problem if you run Mailman, which has a somewhat annoying unsubscribe process and which does not have the funding[1] to address this.

[1] http://mailman.9.n7.nabble.com/GDPR-td46775.html

What I’ve read indicates that if you’re not targeting EU users (via ads or as customers), especially if you aren’t commercial, you don’t have to do anything. Is that not true?