Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

1–10 of 957 posts

Re: GDPR: Removing Monal from the EU

#4
Why not give the user control and have things such as crash reporting be opt-in?

We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it.

Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying that SMTP isn't compatible?

Re: GDPR: Removing Monal from the EU

#5
There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case.

At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Re: GDPR: Removing Monal from the EU

#7
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Another good read on DPO role: http://www.ascentor.co.uk/2017/06/gdpr-data-protection-offic...

Re: GDPR: Removing Monal from the EU

#8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies.

It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

Re: GDPR: Removing Monal from the EU

#9
I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore?

So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs?

I don't think that's the case.

//edit: It seems to be the case that you are ok if you do log-rotation and delete old ones - which makes sense, so you can still use them for debugging.

Re: GDPR: Removing Monal from the EU

#10
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

these assurances from internet forums are great and all, but hwy take such risk?
Post reply on HN