Should a developer be responsible for GDPR? Random question. I'm a non-EU national. But I do have an EU-based client. Today I was asked in an email whether his website complies with GDPR standards and I should make it GDPR if it doesn't. (I haven't replied yet) It was never discussed previously so I will have to add to the scope / quote extra because there's some missing features like delete / view data + account / suppose cookies, etc. This is just judging from doing a quick google search based on the requirements. Although I did recommend some of these features in the past (Me trying to scope more development hours - he said leave it to save $$$). Just to know, at the end of the day, should developer take the GDPR responsibility? I think it's more a matter of, he should probably consult a lawyer first, tell me what needs to be done to make it compliant and then we go from there - not the other way around. Thoughts? |