Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

111–120 of 957 posts

Re: GDPR: Removing Monal from the EU

#111
post #51

Earlier quoted context omitted.

No. That article says you only need a DPO if you're a public authority or if you're processing certain data or you're processing very large amounts of data. I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

He's not monitoring the data.

He's not handling sensitive personal data.

He doesn't need a DPO.

See also the derogation for micro companies:

https://gdpr-info.eu/recitals/no-13/

> To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.

Re: GDPR: Removing Monal from the EU

#112

My understanding of GDPR, if the logs remain anonymized... i.e. the IP addresses are not correlated with user records, then the solution is compliant. The IP addresses are not considered PII.

PII is not a GDPR concept. Most opinions (including the GDPR faq) will tell you IP is personal data.

Re: GDPR: Removing Monal from the EU

#113

Earlier quoted context omitted.

these assurances from internet forums are great and all, but hwy take such risk?

Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...

Neither does the ICO answer the question if a sole owner can be the DPO nor does it help to determine if this case would require a DPO.

Anyway, how should the ICO be able to be more concrete then the GDPR?

Re: GDPR: Removing Monal from the EU

#114

Earlier quoted context omitted.

BetOnSports, an AIM listed UK company took sports bets over the internet, including from US customers: > In July 2006, their then-CEO, David Carruthers, was arrested while changing planes in Texas on the way to Costa Rica from the U.K. In April 2009 he pleaded guilty to federal racketeering charges, and in January 2010 was sentenced to 33 months in prison.

From Wikipedia: > BetonSports plc is a British online gambling company founded by Gary Kaplan in 1995. The company was one of the biggest players in the United States online gaming market, drawing in several billion US dollars in wagers in the early 2000s.[1] In June 2006 US authorities indicted the company and a number of its executives on RICO, mail fraud, and tax evasion charges arising from its supplying online b…

While I agree that violating the GDPR is much less likely to result in being pulled off a plane than running a company that allows people to gasp gamble on the internet, your characterisation of the problem as 'federal crimes' seems to suggest that there was something much more nefarious going on than simply allowing people in another jurisdiction to do something over the internet that is completely legal in the jurisdiction you are based in. I could be wrong, but according to my understanding, that's not the case.

The 'federal crimes', were precisely enabling US customers to gamble over their phone lines. That was enough to get a publicly traded company in a friendly nation categorised as 'organised crime'.

The other thing you mention about how it's not a criminal offense is something important a lot of people seem to be missing. If you're violating the GDPR and someone notices, the first thing that happens is that they work with you to try to correct the problem, not that they hit you with huge fines and laugh while twirling their mustaches.

Re: GDPR: Removing Monal from the EU

#115
post #63

Earlier quoted context omitted.

UK is not the only country that can sue you under GDPR. What if Bulgaria decides 20 million sound pretty good?

Same regulation... Same process. You have to be a flagrant and persistent offender who ignores the regulator to even be facing a fine.

Citation needed. I have seen absolutely zilch about the implementation of GDPR in countries like Hungary, Romania or Bulgaria. And they are members of the EU as well, you know.

Re: GDPR: Removing Monal from the EU

#116
post #51

Earlier quoted context omitted.

No. That article says you only need a DPO if you're a public authority or if you're processing certain data or you're processing very large amounts of data. I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

>Even though no message traffic passes through Monal’s sever

Sounds to me like they are not a) processing b) collecting message data.

Re: GDPR: Removing Monal from the EU

#117

Earlier quoted context omitted.

The thing is, he can't say anything else. There are no reference cases in court yet, so it will need to be decided what is actually true. However, this cases will be fought with the Googles & Facebooks, not with 5 person companies.

How do you know that only Google and Facebook will have problems?

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

Re: GDPR: Removing Monal from the EU

#118

Earlier quoted context omitted.

The op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

Where in the law does it say they only do this when ignored? Surely if this were the case, they'd put it in the law like they did punishment limits. Or are you banking on subjective enforcement?

Re: GDPR: Removing Monal from the EU

#119
post #90
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

False: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage": https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

Probably because that's a dumb exemption. Number of employees is pretty fucking irrelevant when it comes to data. By this standard, Cambridge Analytica would have had lessened burden on regarding objections to processing, demands for data deletion and so on.

Re: GDPR: Removing Monal from the EU

#120
post #21

Earlier quoted context omitted.

these assurances from internet forums are great and all, but hwy take such risk?

Do you think you're going to be slapped with a 20 million euro fine on day three?

how do I know that I will not be? that's the issue
Post reply on HN