Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

121–130 of 957 posts

Re: GDPR: Removing Monal from the EU

#121
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

Are you really can't imagine what state is capable of doing? Not so long ago they packed people on trains to gas them on an industrial scale, and there were people questioning whether this actually happened. Do you think jailing people for not complying with GDPR is not possible? Bookmark this comment and check in 5 years... if this site will even exist by then.

Well in the UK the only criminal offenses under gdpr are around falsifying records to fool the regulator or attempting to deanonymise data. Both of which are punishable by a fine, not prison. And since you can't go to prison for a civil offense I think your comment is misguided.

Now if the state has got to the levels of your tasteless gas-chamber example, i don't think you need worry about data protection law

Re: GDPR: Removing Monal from the EU

#122

Earlier quoted context omitted.

Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...

That's not possible as the DPO must not have any conflict of interest ( https://gdpr.dpkit.com/gdpr/chapter-iv/section-4/article-38.... ), so he/she cannot be an owner or executive of the company.

That's a big assumption. In an executive/owner role where, say, you are the CTO, surely data protection (and therefore the risks and penalties involved in controlling this data) are a core concern? Owning or being in an executive position seems to me to be an investment of interest, not a conflict.

And even if such a conflict does arise, as it surely will somewhere, the text linked states that the controller and processor shall ensure that such a conflict does not exist. It does not say that "You can't do this because 'conflict of interest'", it just says those two roles will ensure there will be no conflict of interest. If you read all the guidance, you will see that the DPO is the most protected role. It has the least liability. The data controller and processor have their own responsibilities, from a liability pov.

Unless you are the business owner/executive, DPO, data controller and data processor...I can't see this being a conflict of interest. Ever.

Re: GDPR: Removing Monal from the EU

#123
> registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance. APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person.

Article 6, Paragraph 1, seems to cover those two parts of data collection. Logging a user's IP for security is acceptable, as is logging for a legitimate interests of the user (or operator) as long as it do not conflict with the interest of the data subject in regard to their need for data protection. APNS push tokens seems to fit that description quite well.

Re: GDPR: Removing Monal from the EU

#124

Earlier quoted context omitted.

> We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least) So someone having a copy of my data that I wish be removed is trampling on a webmaster's rights? That makes no sense whatsoever. > Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers This isn't even true. They h…

But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.

> But it's not "their" data. It's the webmaster's data.

No

> It rightfully belongs to the webmaster.

No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

Re: GDPR: Removing Monal from the EU

#125
post #71

I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.

> I'm convinced this is the start where EU citizens become second class Internet users. This is free market with 550 mil potential users/citizens, void will be filled pretty quickly by other companies/developers that actually spent some time reading about what GDPR is.

You sure? Europe doesn’t have a stellar record when it comes to high tech startups. For many reasons. And I am afraid GDPR has just added another one.

Re: GDPR: Removing Monal from the EU

#126
post #86
post #45

Earlier quoted context omitted.

This might actually be a good thing, as it will open the opportunity for European companies to step up and fill the gaps.

Are you preparing to start such a company? I know zero funders excited about regulation. About technology and platforms, sure. But never about regulation. Only lawyers get excited about that.

I'm guessing they would be interested in 550m unserved users in a single-market for a validated business idea, regardless of GDPR.

Re: GDPR: Removing Monal from the EU

#127

Earlier quoted context omitted.

The op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

> you can't be sued except by the regulator

Regulators. "Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation".

So, 28 countries, each with 1+ organizations. So you could find yourself having to deal with multiple parties in different languages.

Re: GDPR: Removing Monal from the EU

#128

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

SMTP is federated. Did GDPR outlaw email?

I am assuming the answer is no, but would a startup be able to build a SMTP or NNPT like system today? It would be a shame for the GDPR to be yet another force moving the Internet from its historical decentralization reinforcing the current centralization trend.

Re: GDPR: Removing Monal from the EU

#129

Earlier quoted context omitted.

> [...] Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time. You are saying that's a bad thing? Services that require you to sign up, should provide the possibility for users to look at, modify and delete their user data - th…

Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…

> If people named Jane are more likely to eat ice cream, you can't target ice cream ads at them and help keep your site free, without asking them.

Apart from the fact that people named Jane aren't more likely to eat ice cream, you seem to criticize that it gets harder to target ads?

Oh no, that's a real pity. Oh no, poor webmasters.

Re: GDPR: Removing Monal from the EU

#130
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

When it's a one man show, you can't afford these kinds of unknowns. And by afford, I don't just mean monetary, I also mean mental costs, like your mind spinning at night wondering of the ways you might be harmed, or the ways you might develop a solution to the problem, etc.

> When it's a one man show, you can't afford these kinds of unknowns.

One really can. It took me all of a few seconds to shrug of the GDPR when I first heard of it. Then, with all the scare mongering (webserver logs will be illegal!), I spent a few minutes reading up on it. It's all more than reasonable: if you're not doing anything shady, or are being negligent bordering on incompetent, you can just shrug it off and sleep soundly.

Post reply on HN