Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

171–180 of 957 posts

Re: GDPR: Removing Monal from the EU

#171

Earlier quoted context omitted.

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

Even though that's a personal risk you're willing to take, it might not be one everyone else is willing to. One might question a law that asks everyone to take risks (or pay/pray for peace of mind).

There are many other laws where you‘re taking risks. Maybe you‘re violating some US securities statute? Maybe you‘re violating some German accounting rule?

Why haven‘t all those doomsayers closed down their businesses long before the GDPR?

Re: GDPR: Removing Monal from the EU

#172
post #85

Earlier quoted context omitted.

"Allow removing it" is a pretty big barrier for many.

You can just do it manually... I have a feeling deletion requests will be pretty few and far between anyway.

There are already services that are automating them for you. They send to 2-300 companies on your behalf.

Re: GDPR: Removing Monal from the EU

#173
I don't think you can have it both ways- some things will close down/leave EU over this because they can't afford to comply, or rather they can't afford the risk of being found noncompliant. I think the law is at the very least a good start, but like they say, you have to break some eggs to make an omelet.

It's easy to claim over-reaction when it's not your hide at risk.

Re: GDPR: Removing Monal from the EU

#174
post #156

Earlier quoted context omitted.

Ask the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance. https://ico.org.uk/for-organisations/guide-to-the-general-da... https://ico.org.uk/global/contact-u…

ICO is just the UK regulator. How about the regulators of the other 28 EU states?

There are specific mechanisms in place to ensure that the regulations are applied consistently, set out in Chapter 7 of the GDPR.

https://gdpr-info.eu/chapter-7/

Re: GDPR: Removing Monal from the EU

#175
post #90

Earlier quoted context omitted.

False: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage": https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...

And it's good that it wasn't allowed. Otherwise we'd just have medium sized companies worrying about GDPR while large companies spawn one-man shell companies that "specialise in data processing".

That is resolved today by subsidiary clauses in laws.

If owned or controlled by big-co in an non arms length manner, then it wont be considered a 'small company' in terms of the GDPR.

Edit: These corporate control laws have teeth, otherwise every small & large business owner would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done actually in the territory itself.

Re: GDPR: Removing Monal from the EU

#176
Every time something like this comes up, we see similar objections. They normally take one of three forms:

1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity.

This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enforcement? I suspect not, but perhaps there's a business opportunity in giving them the opportunity to do so. Sort of a GoFundMe for peer-to-peer insurance.

2) The GDPR is all about not being a jerk with your users' data. As long as you don't do that, and do relatively minor things X, Y and Z, you're totally fine.

This flavor of argument might actually be true, but if I'm assuming the risk I'm probably going to want to hear it from someone with skin in the game, like a lawyer, who I can point to if it turns out to be false. Even if I had the desire to read through the law (I don't) and understand the specific implications for my project (I wouldn't), the very act of doing this represents a cost that I could more simply avoid by excluding EU residents from my service. I'd choose the latter path every time, and put "support EU residents, check into the legal implications of GDPR" on the roadmap, for "someday".

3) You're exposed to millions of risks anytime you do anything. This is just one more and you're making a big deal of it.

Often this accusation comes with a subtext that you're trying to prove some political point, suggesting that you're making a decision in bad faith to "punish" the EU. Well, I personally think something like the GDPR is needed, and have no particular axe to grind, but I also have no idea if the legal exposure is serious, and no particular desire to put in the work to find out.

Yes, business, or really any activity, involves legal risk. In this case though, the risk is pretty serious, first of all because the penalties (20M Euros max) are serious, and secondly because it will be very difficult to claim that you've never heard of the GDPR. If Tonga creates some law impacting side hustles on the internet, at a minimum I can credibly claim to be unaware of that law. The GDPR on the other hand has been all over the news for weeks. I've clearly heard of it (especially now that I've commented on a discussion of it on HN).

My feeling is there's a real risk that this law will lead to a general practice of non-EU individuals, and non-EU startups launching MVPs to at least temporarily block the EU to avoid unnecessary risk. That's not the intended purpose of the law, but laws have unintended consequences all the time. If the EU wants to avoid this unintended consequence they should provide a clear, objective, and cheap (in terms of both time and money), set of instructions that will allow projects like monal to continue operating there. If such a set of instructions exists, I haven't seen it.

Re: GDPR: Removing Monal from the EU

#177
post #60

Please be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

If the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?

Re: GDPR: Removing Monal from the EU

#178
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

That's only the case if you store personally identifiable information in your logs. IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP. Plus, if you rotate out your logs and clean them up regularly, you don't really need to worry about it. (That's what the EU lawyers at my work told us.)

Database backups are only a problem if you save them forever, though it sounds like you are. GDPR generally requires that you regularly archive, rotate out, and clean up old data.

Re: GDPR: Removing Monal from the EU

#179

Earlier quoted context omitted.

Yup, I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases. But, yeah, I'm not a lawyer too. Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion) > CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO?​​​ > Yes. However, you must ensure that other professional duties of this emp…

> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.

If you're Zuck or anyone working for FB, that'd be true. But what if one of my interests in running my company is the protection of my users' data?

Re: GDPR: Removing Monal from the EU

#180
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

Backups have an expiration. That should be enough to satisfy the requirement for deletion.
Post reply on HN