Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

81–90 of 957 posts

Re: GDPR: Removing Monal from the EU

#81
post #54

Earlier quoted context omitted.

Regardless of what you log, here is a minimum cost of compliance, from the article: > I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. I do not have designated EU contacts. If a single user decides to send him/her the letter ( https://www.linkedin.com/pulse/nightmare-letter-subject-acce... ), he/she would either have to spend an enormous amount of resources…

Implying that every company operating in the EU needs to hire someone to be a DPO is as ridiculous as it is completely false.

> is as ridiculous as it is completely false

Agree, that's why I never implied that.

Re: GDPR: Removing Monal from the EU

#83
post #51

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

No. That article says you only need a DPO if you're a public authority or if you're processing certain data or you're processing very large amounts of data. I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

Re: GDPR: Removing Monal from the EU

#84
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...

That's not possible as the DPO must not have any conflict of interest (https://gdpr.dpkit.com/gdpr/chapter-iv/section-4/article-38....), so he/she cannot be an owner or executive of the company.

Re: GDPR: Removing Monal from the EU

#85

I'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement. You certainly don't need to hire extra people like author suggests and federation should be just f…

"Allow removing it" is a pretty big barrier for many.

You can just do it manually... I have a feeling deletion requests will be pretty few and far between anyway.

Re: GDPR: Removing Monal from the EU

#86
post #45

I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.

This might actually be a good thing, as it will open the opportunity for European companies to step up and fill the gaps.

Are you preparing to start such a company? I know zero funders excited about regulation. About technology and platforms, sure. But never about regulation. Only lawyers get excited about that.

Re: GDPR: Removing Monal from the EU

#87
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

One misconception about GDPR is that you can ignore it if your company is small. And that's basically what you're saying. And then the next would be that it's inexpensive to "make your case" if you get reported.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

Re: GDPR: Removing Monal from the EU

#88
post #63

Earlier quoted context omitted.

Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...

UK is not the only country that can sue you under GDPR. What if Bulgaria decides 20 million sound pretty good?

Same regulation... Same process. You have to be a flagrant and persistent offender who ignores the regulator to even be facing a fine.

Re: GDPR: Removing Monal from the EU

#89
post #55

Earlier quoted context omitted.

If he really said "probably", then he’s the one who doesn’t have to worry about the advice he gave you being incorrect.

The thing is, he can't say anything else. There are no reference cases in court yet, so it will need to be decided what is actually true. However, this cases will be fought with the Googles & Facebooks, not with 5 person companies.

How do you know that only Google and Facebook will have problems?

Re: GDPR: Removing Monal from the EU

#90
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

False: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage":

https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

Post reply on HN