Hacker News new | ask | show | jobs
by woolvalley 2758 days ago
And the EU didn't apply SME carve outs to the GDPR, really showing how much of a big company regulation lock in it was.
1 comments

If you're tiny you get out of a few GDPR regulations, like having a data protection officer. Also the GDPR mostly calls for reasonable and appropriate measures, which are terms that scale with company size (measures reasonable for a hairdressing salon are not appropriate for a fortune 500).

Making even further cutouts for SMEs seems unreasonable, after all the individual citzen has similar impact from a data breach in a medium sized company compared to a data breach in a large enterprise.