r/gdpr
Small UK indie app developer cold-emailed about GDPR Article 27 - how worried should I actually be?
- upvotes
- 11
- comments
- 33
Post
Highlighted: the lines this signal was extracted from
I’m a UK-based indie developer with a small budgeting app. A company recently cold emailed me out of the blue saying that because my app had been available to EU users, GDPR Article 27 required me to appoint an EU representative. They were selling this service for around €490/year. That email is what prompted me to look into all of this. My situation: - Very few users and essentially no revenue. - No user accounts or backend. I don’t collect names, email addresses or other obvious identifying information. - Users enter their budgeting/financial data locally on their own device. Optional backups go to the user’s own iCloud/Google Drive account. I don’t receive or have access to those backups. - I did use Firebase Analytics, but I have now completely unlinked Google Analytics from the Firebase project. As soon as Article 27 was brought to my attention, I removed the app from both Apple and Google Play throughout the EU/EEA. I am no longer offering the app or in-app purchases to EU/EEA users. I understand that removing the app now doesn’t necessarily determine what the legal position was historically. What I’m trying to understand is the real-world risk for someone in my position. Has anyone here dealt with Article 27 as a very small non-EU developer? Would Article 27 actually have applied to an app with this architecture and such limited processing? Now that...
Keep reading with a free account
The rest of this post, and every signal for Google, is in your free account.