I’ve been invited to present the Canvas Method for Information Security to the We Hack Purple Community on May 16th!
More about the Method here: https://www.iso27diy.com
Doesn't matter if they're from the EU or not. If you target (people in) the EU, the GDPR applies, no matter where you're from. Whether the GDPR can be effectively enforced is another question of course.
I'm working on a startup, GDPRvalet.io, currently in the phase of testing my assumptions.
Target audience is startup/scale-ups who need to comply with GDPR but don't have the money to hire lawyers (spoiler alert: in most cases you don't need any, certainly not in this phase of your company).
I'd like to ask you some questions to test my assumptions.
As a return favour I'd be happy to answer any questions about the practical implications of GDPR for your company – I've been working as a GDPR consultant for about 10 clients since 2017.
For new users, explaining this in the privacy policy and getting their consent is enough. It is wise to store the consent, for a user might complain that he/she never gave their OK, and then it's up to you to prove that they did.
If you already have a user base, you should inform them that you are changing your processing of their data, again they must consent. (you will probably have received those kind of mails or popups on websites during the last year yourself)
Important question: are you offering the service to individuals interacting directly with your service, or are you processing this data on behalf of a business client (the "controller")?