# Not another GDPR thread…

**URL:** https://community.glideapps.com/t/not-another-gdpr-thread/60283
**Category:** Ask for Help
**Created:** [April 8, 2023, 10:51am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283 "2023-04-08T10:51:49Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Joshjoshua1](https://avatars.discourse-cdn.com/v4/letter/j/bbce88/32.png) [@Joshjoshua1](https://community.glideapps.com/u/Joshjoshua1)
#### Post date: [April 8, 2023, 10:51am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/1 "2023-04-08T10:51:49Z")

</div>

After a lot of googling, searching forums and reading articles, tackling the GDPR requirements in a Glide app is still none the clearer.

Of course, this is a mandatory requirement for everyone in Europe (and those with any European users) and must be addressed when making an app aimed at a public audience.

I have seen a lot of discussion (most of it in 2020) with people worrying about how to comply. Of course, if it’s impossible perhaps glide isn’t the software for you. But there are many successful apps out there who have navigated this requirement.

To make things easier for newcomers, I propose that app developers here share THEIR steps to make their apps GDPR compliant. Of course, every app is different and this won’t be a rule book any app can follow, but I feel we can all learn from each others ideas in order to protect our users data and avoid a big fine. Big thanks to Glide for implementing a required checkbox for privacy policies on sign up….but is this enough? What else have we all done? Front-end and back-end…?

Looking forward to hearing your suggestions and solutions. I know many here are desperate to make sure they are doing everything correct, and would appreciate some successful app developers thoughts on the matter.

Thanks

---

<div class="post-metadata">

### Author: ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)
#### Post date: [April 9, 2023, 2:03am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/2 "2023-04-09T02:03:03Z")

</div>

Here are some related parts from Glide’s website.

> **[Glide • GDPR](https://www.glideapps.com/security-center/gdpr)**
>
> Learn more about Glide’s approach to GDPR.

> **[Glide • Security Whitepaper](https://www.glideapps.com/security-center/security-whitepaper)**
>
> Learn more about Glide's approach to security and compliance, including details on organizational and technical controls

> **[Glide • EU Data Processing Addendum (Processor Form)](https://www.glideapps.com/legal/dpa)**
>
> Please read.

> **[Glide • Privacy Policy](https://www.glideapps.com/legal/privacy)**
>
> We take your privacy seriously.

Personally I don’t work much with EU clients but European experts like @V88 @Oscar_V88 @Aymeric_de_Maussion @VVerhille @nathanaelb @Marc-Olivier may have something to say about this.

---

<div class="post-metadata">

### Author: ![nathanaelb](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nathanaelb/32/43079_2.png) [@nathanaelb](https://community.glideapps.com/u/nathanaelb)
#### Post date: [April 9, 2023, 7:57pm UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/3 "2023-04-09T19:57:08Z")

</div>

> [@Joshjoshua1](#):
>
> many here are desperate to make sure they are doing everything correct

My personal view is that GDPR is a bunch of baloney, no company is doing everything correctly and therefore no company in the ~~EU~~ world is GDPR compliant. They might think they are, but they are not.

The best a company can do is be on a journey towards GDPR compliance, somewhere on the scale of compliance, and show good intentions. If a company can show it has good intentions and has done all it can do, then that should be good enough to be considered compliant. This is the current status of most companies in the EU.

---

<div class="post-metadata">

### Author: ![Simon\_Hill](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/simon_hill/32/94730_2.png) [@Simon\_Hill](https://community.glideapps.com/u/Simon_Hill)
#### Post date: [April 10, 2023, 11:41am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/4 "2023-04-10T11:41:35Z")

</div>

Disagree. Many companies have strict policies in place to comply and ensure all staff are trained and well informed.

---

<div class="post-metadata">

### Author: ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)
#### Post date: [April 10, 2023, 11:55pm UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/5 "2023-04-10T23:55:04Z")

</div>

I’m just curious. How hard would it be for them to use a Glide solution? What things would have to be done technically from a builder’s perspective to make sure you comply with the policies?

---

<div class="post-metadata">

### Author: ![Simon\_Hill](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/simon_hill/32/94730_2.png) [@Simon\_Hill](https://community.glideapps.com/u/Simon_Hill)
#### Post date: [April 11, 2023, 7:21am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/6 "2023-04-11T07:21:40Z")

</div>

GDPR mainly protects users from 3rd parties storing and/or using their personal data without their permission. Therefore, if you have their explicit permission to store and do whatever you intend to do with their data then you can do just about anything with Glide.

That said, I see one of the biggest hurdles will be the likelihood that all data is stored outside of the EU.

---

<div class="post-metadata">

### Author: ![Scotttiey](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/scotttiey/32/57378_2.png) [@Scotttiey](https://community.glideapps.com/u/Scotttiey)
#### Post date: [April 11, 2023, 9:31am UTC](https://community.glideapps.com/t/not-another-gdpr-thread/60283/7 "2023-04-11T09:31:23Z")

</div>

My understanding is the DPA (Data Processing Agreement) references the SCC’s (Standard Contractual Clauses) for either the EU or UK in order to ensure compliance. Section 6 of the DPA covers a lot of this
