Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

31–40 of 957 posts

Re: GDPR: Removing Monal from the EU

#31
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

these assurances from internet forums are great and all, but hwy take such risk?

Risk is a part of life. Even before GDPR there was a risk that you were violating some privacy law in countries that your customers were connecting from. By putting your product out there, you've taken on most of this risk already.

Re: GDPR: Removing Monal from the EU

#32
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls

We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time.

The EU has shot themselves in the foot and more and more companies are going to refuse to do business with them because of it.

Re: GDPR: Removing Monal from the EU

#33
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

[deleted]

Re: GDPR: Removing Monal from the EU

#34

Does GDPR have any non-monetary enforcement? For a site with no revenue, can they take any action other than a $0 fine?

20m euro or 4% of revenue, whichever is higher, is the max fine. Up to the individual to say how truly likely it is a small revenueless project could possibly get fined, even with large amounts of malfeasance.

Re: GDPR: Removing Monal from the EU

#36
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

Indeed and TBH when the part about Crashlytics made me glad about GDPR (although the rest of the message does indeed sound like an overreaction). I do not like when applications i use try and do things that are irrelevant to what the application is all about, especially when these "things" involve communicating through the internet and even more so when i am not informed about it.

Re: GDPR: Removing Monal from the EU

#37
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...

Re: GDPR: Removing Monal from the EU

#40
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate.

https://gdpr-info.eu/art-37-gdpr/

Post reply on HN