Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

151–160 of 957 posts

Re: GDPR: Removing Monal from the EU

#151

Earlier quoted context omitted.

Are you really can't imagine what state is capable of doing? Not so long ago they packed people on trains to gas them on an industrial scale, and there were people questioning whether this actually happened. Do you think jailing people for not complying with GDPR is not possible? Bookmark this comment and check in 5 years... if this site will even exist by then.

Well in the UK the only criminal offenses under gdpr are around falsifying records to fool the regulator or attempting to deanonymise data. Both of which are punishable by a fine, not prison. And since you can't go to prison for a civil offense I think your comment is misguided. Now if the state has got to the levels of your tasteless gas-chamber example, i don't think you need worry about data protection law

If you don't pay a fine you go to prison...

Re: GDPR: Removing Monal from the EU

#152
post #60

Please be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

Re: GDPR: Removing Monal from the EU

#153

Earlier quoted context omitted.

> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense.

And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer or whatever.

Re: GDPR: Removing Monal from the EU

#154
post #61

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

Reading the FAQ, the only way to really safely ignore the DPO provision would be to hire a law firm with GDPR expertise to parse the vague language in the law and to give written guidance as to whether the law applies to each specific web site, which you can then present to EU authorities in the future to show you performed due diligence to try to meet the requirements of the law.

The FAQ is referencing the legal concepts in the law's text. For example "sensitive data":

"(...) including for the processing of special categories of personal data (‘sensitive data’)", special categories are mentioned on Article 9. "(...) personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation"

Do you store or transfer or process any of that data on a large scale? Is it personally identifiable? "Processing" is defined on Article 4.

I believe the original legal text, though not the easiest to read, gives you a fairly clear idea on where your organization or project should stand with respect to GDPR.

(1) What data do you process? (2) How is it connected to your economic activity? (3) How do users consent this use of the data? (4) Is your data "sensitive data"?

If you're some random guy online doing large scale processing of "sensitive data" you better hire a law firm with GDPR expertise to understand and comply with the law, I mean, that's the whole point.

Re: GDPR: Removing Monal from the EU

#155
post #90
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

False: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage": https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

And it's good that it wasn't allowed. Otherwise we'd just have medium sized companies worrying about GDPR while large companies spawn one-man shell companies that "specialise in data processing".

Re: GDPR: Removing Monal from the EU

#156

Earlier quoted context omitted.

So when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.

Ask the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance. https://ico.org.uk/for-organisations/guide-to-the-general-da... https://ico.org.uk/global/contact-u…

ICO is just the UK regulator. How about the regulators of the other 28 EU states?

Re: GDPR: Removing Monal from the EU

#157
post #115

Earlier quoted context omitted.

Same regulation... Same process. You have to be a flagrant and persistent offender who ignores the regulator to even be facing a fine.

Citation needed. I have seen absolutely zilch about the implementation of GDPR in countries like Hungary, Romania or Bulgaria. And they are members of the EU as well, you know.

It's in the text of the legislation. Chapter 7 sets out the requirements for the European Data Protection Board to ensure consistent application of the regulations across all member states.

Article 83 states that any penalties must be proportionate to the nature, gravity and duration of the infringement, the intentional or negligent character of the infringement, action taken to prevent or mitigate an infringement and the degree of cooperation with the supervisory authority.

https://gdpr-info.eu/

Re: GDPR: Removing Monal from the EU

#158

Earlier quoted context omitted.

> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

I'm sure the person you're replying to is also talking in the 'rightful' sense. While the data collected technically belongs to you, it can still be a privacy violation. This is extremely important on the web where it's very easy to share that data, make it public or accidentally leak it.

Re: GDPR: Removing Monal from the EU

#159

Earlier quoted context omitted.

> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

> The law doesn't make something right.

I absolutely agree. If you feel a law is wrong, it is your absolute right to say so and demand change. This is the basis of all law and civilisation. The consensus of what is right-or-wrong is what makes a society.

Go for it.

Re: GDPR: Removing Monal from the EU

#160

Earlier quoted context omitted.

> [...] Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time. You are saying that's a bad thing? Services that require you to sign up, should provide the possibility for users to look at, modify and delete their user data - th…

Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…

> Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it

They don't have that right. GDPR only applies to business. If you mean you wrote it in your house for some business reason then yeah they have the right to know you've done so and why and the right to ask you to remove it if you don't need to have that information.

In no situation do they have the right to come into your house. That's a touch too far into the absurd.

Post reply on HN