Hacker News new | ask | show | jobs
by Silhouette 2581 days ago
That's one small exception to one small part of the compliance burden, though.

Small businesses are still, for example, subject to abusive SARs of the kind used for illustration here. They're still required to write documentation like privacy policies according to the new standards. And unlike large organisations, where there is the 4% cap on fines, a small organisation faces an existential threat if regulators decide to impose heavy fines, which they have considerable powers to do.