{"id":1442,"date":"2018-08-16T10:38:19","date_gmt":"2018-08-16T08:38:19","guid":{"rendered":"https:\/\/staging.techgdpr.com\/?p=1442"},"modified":"2024-02-22T18:14:38","modified_gmt":"2024-02-22T17:14:38","slug":"disruptive-startups-must-also-disrupt-common-gdpr-assumptions","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/","title":{"rendered":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions"},"content":{"rendered":"\n<p><span style=\"font-weight: 400;\">In July, I attended the <a href=\"https:\/\/piratesummit.com\/the-experience\" target=\"_blank\" rel=\"noopener\">Pirate Summit<\/a> in Cologne where there was plenty of discussion among startups and entrepreneurs about the GDPR. As the founder of a consulting firm with \u201cGDPR\u201d in the name (as well as the wearer of a customized T-shirt just for this occasion) attendees were eager to share their thoughts with me about the regulations that officially came into effect in May. A common feeling among founders was that they had navigated some rather stormy regulatory seas in recent months. When one considers a regulatory timeframe, however, their voyage is only beginning.<\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/pirate-summit-768x1024.jpg\" alt=\"TechGDPR CEO Silvan Jongerius at the Pirate Summit 2108\"\/><\/figure>\n<\/div>\n\n\n<p><span style=\"font-weight: 400;\">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<br><\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>All Hands on Deck for GDPR<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Given that the Pirate Summit is one of the largest startup events in Europe, it stands to reason that my conversations there with founders were an accurate representation of current perceptions and concerns about the GDPR in the startup sector overall. Among the most common reactions is, \u201cOh, yes, GDPR. We already took care of that, and I\u2019m glad it\u2019s behind us now.\u201d <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Actually, not quite.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Such a &nbsp;reaction is concerning because it leaves companies vulnerable to much larger problems later on. As TechGDPR continues to emphasize with our clients, GDPR compliance is never \u201cdone\u201d; it is a <a href=\"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/\" target=\"_blank\" rel=\"noopener\">process<\/a><\/span><span style=\"font-weight: 400;\">\u2014one requiring ongoing vigilance over each new data-related activity that a company begins.&nbsp; Whenever personal data is collected or processed, action needs to be taken.<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>The Size of Your Ship<\/b><\/h4>\n\n\n\n<p><span style=\"font-size: inherit;\">The second most common reaction from founders is frustration and even resentment about the perception that startups and other smaller companies face a heavier burden to become GDPR compliant than larger, more established companies.\u00a0\u00a0<\/span><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p><span style=\"font-weight: 400;\">In reality, even the smallest startup need not be overwhelmed. Unlike large corporations, whose compliance issues span multiple departments (and in many cases, continents), it remains far easier for a smaller company to analyze why it is collecting and processing data. Such questions can be sorted through in a matter of days within startups, setting a solid path for integrating GDPR practices throughout the company as it grows and expands.<\/span><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/pirates-1024x768.jpg\" alt=\"Evening event at Pirate Summit 2018\" style=\"width:559px;height:auto\"\/><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">In reality, even the smallest startup need not be overwhelmed. Unlike large corporations, whose compliance issues span multiple departments (and in many cases, continents), it remains far easier for a smaller company to analyze why it is collecting and processing data. Such questions can be sorted through in a matter of days within startups, setting a solid path for integrating GDPR practices throughout the company as it grows and expands.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Larger companies, on the other hand, often don\u2019t know what data exists &nbsp;where or why, and they are at a loss to justify many disparate mountains of personal data that have been collected for years\u2014\u201cjust in case.\u201d Big firms may have more resources for responding to the GDPR, but they also have far more holes to patch and processes to implement\u2014not to mention the organizational aspect of involving many more people in their GDPR compliance efforts.<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>Changing Tides&nbsp;<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Being aware of how to implement key data collection storage is paramount, both for my fellow Pirates and for the rest of the global tech community. Sooner or later, all companies will need to properly comply if they want to stay in business. The key question is: which companies, regardless of size, will be proactive, and thus be able to feature their customer-focused privacy practices to attract and retain business? Conversely, which companies will sabotage their reputation by addressing personal data protection only because of the threat of serious fines or a devastating privacy breach?<\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-59-1024x439.png\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">As people (or, as the GDPR calls them, \u00a0\u201cdata subjects\u201d) continue to increase their awareness of the rights and freedoms that any form of data privacy affords them, customers will increase their scrutiny of corporate privacy practices and seek out companies that align with customers\u2019 data protection expectations. Successful companies will leverage the GDPR as a framework for the best practices in protecting customers\u2019 or users\u2019 personal data. Such companies will be able to build not only better data storage systems, but a better reputation among customers. <\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>Staying on Course for GDPR Compliance<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">If you are a founder or leader of a startup or other small company and you are feeling overwhelmed by the GDPR, you are not alone. At TechGDPR, we are used to meeting clients who are grappling with the GDPR and don\u2019t know where to start. We also spend a great deal of time reminding them of the <\/span><a href=\"https:\/\/www.forbes.com\/sites\/forbestechcouncil\/2018\/03\/29\/five-benefits-gdpr-compliance-will-bring-to-your-business\/#64798e70482f\" target=\"_blank\" rel=\"noopener\">advantages<\/a><span style=\"font-weight: 400;\"> of sustained GDPR compliance. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The best place to start is in shifting our perception of the GDPR to see it as an opportunity for protecting privacy for everyone, including you. Every person who is part of a startup is also a \u201cdata subject\u201d in countless databases and with a rapidly growing digital footprint. When we, as leaders in small companies, prioritize protecting human rights related to privacy, we are also advocating for our employees, our families, and ourselves\u2014not to mention avoiding a few shipwrecks. <\/span><\/p>\n\n\n\n<p><i><span style=\"font-weight: 400;\">Silvan Jongerius is the Managing Partner of TechGDPR.<\/span><\/i><\/p>\n\n\n\n<p>Follow <strong><a href=\"https:\/\/twitter.com\/techgdpr?lang=en\" target=\"_blank\" rel=\"noopener\">TechGDPR on Twitter<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In July, I attended the Pirate Summit in Cologne where there was plenty of discussion among startups and entrepreneurs about the GDPR. As the founder of a consulting firm with \u201cGDPR\u201d in the name (as well as the wearer of a customized T-shirt just for this occasion) attendees were eager to share their thoughts with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1450,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[11,13],"tags":[],"class_list":["post-1442","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-subjects","category-startups"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",200,86,false]},"post_excerpt_stackable":"<p>In July, I attended the Pirate Summit in Cologne where there was plenty of discussion among startups and entrepreneurs about the GDPR. As the founder of a consulting firm with \u201cGDPR\u201d in the name (as well as the wearer of a customized T-shirt just for this occasion) attendees were eager to share their thoughts with me about the regulations that officially came into effect in May. A common feeling among founders was that they had navigated some rather stormy regulatory seas in recent months. When one considers a regulatory timeframe, however, their voyage is only beginning. &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&nbsp;&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/startups\/\" rel=\"category tag\">Startups<\/a>","author_info":{"name":"Silvan Jongerius","url":"https:\/\/techgdpr.com\/blog\/author\/silvan\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png",200,86,false]},"post_excerpt_stackable_v2":"<p>In July, I attended the Pirate Summit in Cologne where there was plenty of discussion among startups and entrepreneurs about the GDPR. As the founder of a consulting firm with \u201cGDPR\u201d in the name (as well as the wearer of a customized T-shirt just for this occasion) attendees were eager to share their thoughts with me about the regulations that officially came into effect in May. A common feeling among founders was that they had navigated some rather stormy regulatory seas in recent months. When one considers a regulatory timeframe, however, their voyage is only beginning. &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&nbsp;&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/startups\/\" rel=\"category tag\">Startups<\/a>","author_info_v2":{"name":"Silvan Jongerius","url":"https:\/\/techgdpr.com\/blog\/author\/silvan\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR<\/title>\n<meta name=\"description\" content=\"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-16T08:38:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-22T17:14:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1408\" \/>\n\t<meta property=\"og:image:height\" content=\"604\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Silvan Jongerius\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@silvanjongerius\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Silvan Jongerius\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/\"},\"author\":{\"name\":\"Silvan Jongerius\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/34bb17183811103b88ab2bf349c7fe5e\"},\"headline\":\"Disruptive Startups Must Also Disrupt Common GDPR Assumptions\",\"datePublished\":\"2018-08-16T08:38:19+00:00\",\"dateModified\":\"2024-02-22T17:14:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/\"},\"wordCount\":856,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-01.png\",\"articleSection\":[\"Data Subjects\",\"Startups\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/\",\"name\":\"Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-01.png\",\"datePublished\":\"2018-08-16T08:38:19+00:00\",\"dateModified\":\"2024-02-22T17:14:38+00:00\",\"description\":\"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-01.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/TechGDPR-Main-Graphics-01.png\",\"width\":1408,\"height\":604},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Disruptive Startups Must Also Disrupt Common GDPR Assumptions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/34bb17183811103b88ab2bf349c7fe5e\",\"name\":\"Silvan Jongerius\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Silvan_OF_3869_700-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Silvan_OF_3869_700-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Silvan_OF_3869_700-150x150.jpg\",\"caption\":\"Silvan Jongerius\"},\"description\":\"Silvan Jongerius FIP, CIPT, CIPP\\\/e, is the Managing Partner and Founder of TechGDPR. He leads the team of data protection consultants and engages in key client projects as lead consultant. Silvan has been recognized as Fellow of Information Privacy by the renowed IAPP, and is certified as by the IAPP as Certified Information Privacy Professional (Europe\\\/GDPR), Certified Information Privacy Technologist (CIPT) and T\u00dcV certified Data Protection Officer (Datenschutzbeauftragter).\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/silvanjongerius\\\/\",\"https:\\\/\\\/x.com\\\/silvanjongerius\"],\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/silvan\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR","description":"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/","og_locale":"en_US","og_type":"article","og_title":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR","og_description":"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.","og_url":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/","og_site_name":"TechGDPR","article_published_time":"2018-08-16T08:38:19+00:00","article_modified_time":"2024-02-22T17:14:38+00:00","og_image":[{"width":1408,"height":604,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png","type":"image\/png"}],"author":"Silvan Jongerius","twitter_card":"summary_large_image","twitter_creator":"@silvanjongerius","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Silvan Jongerius","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/"},"author":{"name":"Silvan Jongerius","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/34bb17183811103b88ab2bf349c7fe5e"},"headline":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions","datePublished":"2018-08-16T08:38:19+00:00","dateModified":"2024-02-22T17:14:38+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/"},"wordCount":856,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png","articleSection":["Data Subjects","Startups"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/","url":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/","name":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png","datePublished":"2018-08-16T08:38:19+00:00","dateModified":"2024-02-22T17:14:38+00:00","description":"GDPR compliance is never \u201cdone\u201d; it is a process\u00a0\u2013 one requiring ongoing vigilance over each new data-related activity that a company begins.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/08\/TechGDPR-Main-Graphics-01.png","width":1408,"height":604},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/disruptive-startups-must-also-disrupt-common-gdpr-assumptions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Disruptive Startups Must Also Disrupt Common GDPR Assumptions"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/34bb17183811103b88ab2bf349c7fe5e","name":"Silvan Jongerius","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Silvan_OF_3869_700-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Silvan_OF_3869_700-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Silvan_OF_3869_700-150x150.jpg","caption":"Silvan Jongerius"},"description":"Silvan Jongerius FIP, CIPT, CIPP\/e, is the Managing Partner and Founder of TechGDPR. He leads the team of data protection consultants and engages in key client projects as lead consultant. Silvan has been recognized as Fellow of Information Privacy by the renowed IAPP, and is certified as by the IAPP as Certified Information Privacy Professional (Europe\/GDPR), Certified Information Privacy Technologist (CIPT) and T\u00dcV certified Data Protection Officer (Datenschutzbeauftragter).","sameAs":["https:\/\/www.linkedin.com\/in\/silvanjongerius\/","https:\/\/x.com\/silvanjongerius"],"url":"https:\/\/techgdpr.com\/blog\/author\/silvan\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=1442"}],"version-history":[{"count":34,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1442\/revisions"}],"predecessor-version":[{"id":8161,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1442\/revisions\/8161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/1450"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=1442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=1442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=1442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}