Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

141–150 of 957 posts

Re: GDPR: Removing Monal from the EU

#141
> Obviously, this is needed for a notification to be delivered to the right person.

This seems pretty clearly a case of 'Legitimate Interest'. Filling in a couple of page word document (a LIA) and keeping it somewhere on the off-chance that someone queries you, is likely sufficient from my understanding. (This is not legal advice).

Re: GDPR: Removing Monal from the EU

#142
post #119
post #90

Earlier quoted context omitted.

False: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage": https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

Probably because that's a dumb exemption. Number of employees is pretty fucking irrelevant when it comes to data. By this standard, Cambridge Analytica would have had lessened burden on regarding objections to processing, demands for data deletion and so on.

[deleted]

Re: GDPR: Removing Monal from the EU

#143
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

When it's a one man show, you can't afford these kinds of unknowns. And by afford, I don't just mean monetary, I also mean mental costs, like your mind spinning at night wondering of the ways you might be harmed, or the ways you might develop a solution to the problem, etc.

This is what Limited Companies, LLC's and Corporations are for.

The monetary and time cost is minimal, but the mental benefit is pretty damn good.

Re: GDPR: Removing Monal from the EU

#144

Earlier quoted context omitted.

Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…

The point of GDPR is to switch collecting users’ personal data from being a benefit to being a liability. That will absolutely cause short term pain to some companies that hadn’t expected this, but it ends up as a long term benefit to society, the same as most legislation.

Do you have a source for most legislation being a long term benefit to society?

If forcing low-earning EU citizens off the internet because every website requires a subscription is a social good to you, then sure, it's a long term benefit.

Re: GDPR: Removing Monal from the EU

#145
post #51

Earlier quoted context omitted.

No. That article says you only need a DPO if you're a public authority or if you're processing certain data or you're processing very large amounts of data. I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

It's not “processing user data on a large scale” that requires a DPO, but “processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.”

Re: GDPR: Removing Monal from the EU

#146

This project is completely out of scope for GDPR, not having any presence whatsoever in the EU. You aren't going to be arrested when going on holiday. You wouldn't be breaking the law at all, even if it was possible to enforce anything. Even if it was in the EU, it wouldn't require a DPO, and your use of IP addresses is very reasonable and within the standard allowances which don't require user consent. Maybe bother…

If he offers his app to users in the EU and is not conform to the GDPR he is breaking his contract with the app store.

Re: GDPR: Removing Monal from the EU

#147
post #86

Earlier quoted context omitted.

Are you preparing to start such a company? I know zero funders excited about regulation. About technology and platforms, sure. But never about regulation. Only lawyers get excited about that.

I'm guessing they would be interested in 550m unserved users in a single-market for a validated business idea, regardless of GDPR.

Maybe, but GDPR is not the only business-hostile regulation EU has. Together they make an environment in which even 550m users may not be worth it for the small startup. They will simply pivot to the more competitive, but freer, US market.

Re: GDPR: Removing Monal from the EU

#148
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

Are you really can't imagine what state is capable of doing? Not so long ago they packed people on trains to gas them on an industrial scale, and there were people questioning whether this actually happened. Do you think jailing people for not complying with GDPR is not possible? Bookmark this comment and check in 5 years... if this site will even exist by then.

> and there were people questioning whether this actually happened.

Or equally bad: people trivialising it by comparing it to some new regulation to show how bad it is because "the state" somehow is involved.

Re: GDPR: Removing Monal from the EU

#149

> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. A DPO is most certainly not required by all organisations[0], and I would be suprised if it applied to this project. I know lots of blogs are saying it is, but it is simply untrue. I'm not saying that this totally relieves the burden however. [0]: https://ico.org.uk/for-organisations/guide-to-the-general-da…

> most certainly not ... but it is simply untrue.

Most certainly simply untrue?

Re: GDPR: Removing Monal from the EU

#150
post #125
post #71

Earlier quoted context omitted.

> I'm convinced this is the start where EU citizens become second class Internet users. This is free market with 550 mil potential users/citizens, void will be filled pretty quickly by other companies/developers that actually spent some time reading about what GDPR is.

You sure? Europe doesn’t have a stellar record when it comes to high tech startups. For many reasons. And I am afraid GDPR has just added another one.

> Europe doesn’t have a stellar record when it comes to high tech startups. For many reasons.

For many reasons indeed, this is broad topic and GDPR doesn't change anything if we are talking about big US players and their domination. None of them is getting out of EU.

> And I am afraid GDPR has just added another one.

I disagree, it's the other way around. Small single person companies/developers that will get out from EU market will could only strengthen local market. Any other US/EU/outside EU startup/developer can fill that void.

Post reply on HN