Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

181–190 of 957 posts

Re: GDPR: Removing Monal from the EU

#181

Earlier quoted context omitted.

how do I know that I will not be? that's the issue

Because European courts and regulatory authorities are not run by gibbering morons. The Data Protection Directive was materially similar to the GDPR and was enforced by the same supervisory authorities. The DPD gave member states total discretion as to the level of fines, with no upper limit. I have found no evidence whatsoever of irrationally large or unreasonable fines under the DPD. You could be breaking the law i…

Well usually they aren't any kind of social or economic hubs, so I don't really worry if I can't enter or do business with north korea in my day to day life.

The EU on the other hand...

Also almost all laws stay in one jurisdiction, they don't go beyond their own country.

Re: GDPR: Removing Monal from the EU

#182

Earlier quoted context omitted.

And it's good that it wasn't allowed. Otherwise we'd just have medium sized companies worrying about GDPR while large companies spawn one-man shell companies that "specialise in data processing".

That is resolved today by subsidiary clauses in laws. If owned or controlled by big-co in an non arms length manner, then it wont be considered a 'small company' in terms of the GDPR. Edit: These corporate control laws have teeth, otherwise every small & large business owner would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done…

Oh, but they're completely "independent", I don't understand what's the problem, Mr regulator ;-) This already exists in many ways for financial aspects. Sure, it's not super legal/moral, but...

Or the could be completely legitimate small businesses doing this device for anyone.

Re: GDPR: Removing Monal from the EU

#183

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

From Article 37 GDPR: (1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or .... Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or tr…

I don't think he has access to the messages, it's an IM client. If he did have access to the messages then I fail to see how having to hire a DPO in that case would be outrageous. If anything, that's the reasonable thing to do.

Re: GDPR: Removing Monal from the EU

#185
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

GDPR does not require deleting data from backups.

http://blog.quantum.com/backup-administrators-the-1-advice-t...

"The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations will have to clearly explain to the data subject (using clear and plain language) that his or her personal data has been removed from production systems, but a backup copy may remain, but will expire after a certain amount of time (indicate the retention time in your communication with the data subject). Backups should only be used for restoring a technical environment, and data subject personal data should not be processed again after restore (and deleted again)."

Re: GDPR: Removing Monal from the EU

#186
post #56

Earlier quoted context omitted.

First of all, you're saying "core business". Is this even a business? And I copy-pasted direct text from the regulation. Note how it says "large scale". Twice. If he is actually processing personal data on a large scale, then maybe it is not unreasonable to have a DPO.

Is "large scale" defined?

I think it's clear that 1 person is not a large scale op. I do agree it should be defined in at least somewhat precise terms though.

Re: GDPR: Removing Monal from the EU

#187
post #98

If I continue to maintain mail and web server syslogd logs and Europeans access one of the swervers do I risk getting nailed under the GDPR?

If you're not in the EU and not actively trying to market your services to people in the EU, GDPR does not apply

And if no one of your customers is using your service to process data from EU users.

Re: GDPR: Removing Monal from the EU

#188
post #171

Earlier quoted context omitted.

Even though that's a personal risk you're willing to take, it might not be one everyone else is willing to. One might question a law that asks everyone to take risks (or pay/pray for peace of mind).

There are many other laws where you‘re taking risks. Maybe you‘re violating some US securities statute? Maybe you‘re violating some German accounting rule? Why haven‘t all those doomsayers closed down their businesses long before the GDPR?

I mean, technically I'm taking a risk when I step out of my house every day. So why ever walk?

There are varying degrees to which people see laws as affecting them. Small business tech owners, when a law says they have work to do, are going to feel affected. If there was a securities or accounting law that felt similarly overreaching one could expect a similar reaction. This is especially true if there is an alternative (locking out markets) that is easier. It's not helpful to try and compare the situations. It's also not fair to consider people weighing the costs of these laws as doomsayers. They aren't closing down their business, they're just restricting it to more business-friendly environments in their view.

Re: GDPR: Removing Monal from the EU

#189
post #8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

Maybe companies that are so flimsy didn't have long left anyway.

You're required to have a fire safety officer at these companies too, but it's not a full-time position.

Re: GDPR: Removing Monal from the EU

#190
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

So it's a law that's arbitrarily enforced? Kinda like giving limitless power to discriminate to someone?

There is no misconception on GDPR: the idea is good, the implementation is horrible and retarded and it is lead by people who do not understand a single thing about technology.

Post reply on HN