Hacker News new | past | comments | ask | show | jobs | submit | scollins's comments login

I have a few products on AWS marketplace. My biggest complaint with AWS is that there is 0 visibility into conversion metrics as a publisher. You don't know how many times your listing appeared in search, who clicked on it but didn't signup etc. AWS shows ref tag reports, but they only tell you how much traffic you drove to the listing.

Also, optimizing search ranking for your product is hit-and-miss, with no clear guidelines or tips.


Serious question: What are the odds of someone offical even noticing that you are in violation of GDPR? It's not like they'll enforce GDPR and collect $7.89 in fines from small businesses.


A good question. But that’s not how these things work. The law has to be self enforced or it’s useless - since as you say, how will small to medium businesses ever be caught violating?

Megacorps comply because of mega fines.

Small business comply because their owners or future buyers are a larger Corp who fears that their sub-subsidiary might be in violation, causing a future mega fine.

So small businesses who care about the value of their company follow these rules. It’s almost exactly the same reason small business buy software licenses. It’s not of fear of fines but because otherwise they don’t look like a serious company.

I question I have been wondering is how many companies will leave some violations such as data in backups - simply because removing it is too expensive so it’s a risk worth taking. I honestly haven’t understood how backup of data fits into the requirement to delete data of a certain age?


GDPR has the concept of backups and their expiration windows covered.

I'll pick an example from my work. Data can be deleted from the active set, at which point it takes extra effort to retrieve it. (If you can't SELECT it anymore from the warm slaves, it's gone.) But as long as you can make a point-in-time-recovery from your backups, the data is still present in the inactive set. Using the inactive set requires, by definition, extra effort.

So you need to state that fact in the data protection/retention policy, AND put reasonable technical enforcement mechanisms ("controls") in place to ensure that backups are expired and fully deleted after a given retention period. The older your unexpired backups get, the less valuable they should become.


All it takes is one disgruntled employee


Why would you care about someone official? I'd care more about a bot that is set up to save the officials some work.


Minimum fine is $20 million, isn’t it?


No. It's part of the calculation for the maximum fine.

The maximum fine is defined as €20,000,000 or 4% of your global anual turnover, whichever is largest.


Yep

> Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher

https://www.gdpreu.org/compliance/fines-and-penalties/


What are the odds of someone offical even noticing that you are in violation of GDPR?

Plenty of ordinary people will be actively looking for opportunities to file GDPR complaints. I know I will. This is a crusade. Taking the Internet back from adtech.


Are you going after amazon or my neighbours small online flower business?


It depends, for example a local restaurant mini-chain has been doing some spamming and refused to take me off their list, so if I get a single message from them after May 26th, I'll definitely file a complaint. From the consumers perspective, the main GDPR effect is that things that previously were scummy but legal have now become forbidden, and some of the things that have been forbidden but not enforced now have an enforcement mechanism with teeth to make it happen.


If they have Google ads they’re fair game.


If I'm not a resident of US and didn't visit US in a tax year, would I have to pay US income tax for the LLC?


Owning a US LLC as a non-resident can be complicated; it depends on a variety of circumstances regarding what you do, how your business interacts with the US market, whether you are a US citizen, where you live, etc. You may wish to speak to an accountant.


Would it be easier to own a C Corp as a non-resident? Does Atlas provide that as well?


We do provide C corporations. It was the first option we launched with, and a core goal of that was supporting non-US founders.


Hi Peter,

Indian Citizen here. I have a startup incorporated via Stripe Atlas. If it reaches $1 Million in annual revenue, can I qualify for EB5 green card?

Or if I have around $500K in revenue and raise $250K from investors, does that help with EB5?


No OP but for EB5 you need million dollar in assets not revenue and you need to hire 10 people in the US.


Thanks for noticing :)

Fixed them on the site.


Hi, OP here.

I'd love your feedback on my side project. My goal with screenshotapp is to make it easy to visually monitor any site or webapp for changes across browsers and different resolutions.


I received similar emails this week, so I'm posting this on HN to caution others.


You're not alone. I have had similar experience as an outsider on bunch of other similar sites as well. My submissions are "Pending Approval" for over a year. No reply to tweets or emails, when clearly new sites from SF are approved daily / weekly.


9gag... I need help!


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: