Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

21–30 of 957 posts

Re: GDPR: Removing Monal from the EU

#21
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

these assurances from internet forums are great and all, but hwy take such risk?

Do you think you're going to be slapped with a 20 million euro fine on day three?

Re: GDPR: Removing Monal from the EU

#22

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

Pretty sure that is exactly the case. GDPR went all out on user privacy that is simply a burden for small businesses to deal with EU citizens, it's financially more sensible to just block the entire EU from their services.

Re: GDPR: Removing Monal from the EU

#23

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

Regardless of what you log, here is a minimum cost of compliance, from the article:

> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. I do not have designated EU contacts.

If a single user decides to send him/her the letter (https://www.linkedin.com/pulse/nightmare-letter-subject-acce...), he/she would either have to spend an enormous amount of resources to reply, or be non-compliant and risk him/herself.

Re: GDPR: Removing Monal from the EU

#24
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> 9. Profiling activities always require consent: WRONG!

Well that's a disappointment.

Re: GDPR: Removing Monal from the EU

#25
> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.

Is there any actual requirement within the GDPR that this needs to be a dedicated person, or does being a DPO just need to be someone's responsibility, e.g. in the case of a one-man open source project the guy who runs the project?

Re: GDPR: Removing Monal from the EU

#26
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

these assurances from internet forums are great and all, but hwy take such risk?

Sure, feel free to "leave", really, no offense. We talked to a lawyer in Germany regarding this (we are a small software company with 5 people). His response was: If you don't do shady shit with customer data, you'll probably don't have to worry. Also, if you are in a "contractual agreement" (e.g. EULA), you can apparently justify most data collection without any change at all.

Re: GDPR: Removing Monal from the EU

#27

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

The burden is if the EU does investigate him, for whatever reason whatsoever, even if he is 100% compliant he needs to spend money to prove he is compliant and deal with the EU.

Re: GDPR: Removing Monal from the EU

#28
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

Yeah, they are over-reacting.

For example, IP addresses are considered personal information but what that means is you just can't blindly collect them. If the service you use relies on IP addresses as a basic point of operation then its fine.

CDNs aren't going out of business for example.

Re: GDPR: Removing Monal from the EU

#30
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

these assurances from internet forums are great and all, but hwy take such risk?

Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...
Post reply on HN