Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

191–200 of 957 posts

Re: GDPR: Removing Monal from the EU

#191

Earlier quoted context omitted.

When it's a one man show, you can't afford these kinds of unknowns. And by afford, I don't just mean monetary, I also mean mental costs, like your mind spinning at night wondering of the ways you might be harmed, or the ways you might develop a solution to the problem, etc.

This is what Limited Companies, LLC's and Corporations are for. The monetary and time cost is minimal, but the mental benefit is pretty damn good.

Corporate veil piercings happen a lot more when your a small or one man shop, and officers can often be directly liable for the actions of the company. It's not as bulletproof as you think.

Re: GDPR: Removing Monal from the EU

#192

Earlier quoted context omitted.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

If the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?

I think everyone already knows that more regulations hurt businesses. We don't have to wait for the result to find that out. The question is whether the help done to consumers outweighs that. There are many ways to tackle the privacy issue beyond a large, sweeping law.

Re: GDPR: Removing Monal from the EU

#193
post #8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

From my German perspective this whole GDPR panic is so interesting. The GDPR is basically a carbon copy of the data protections laws that have evolved in Germany since 1977. Yet we still have many thousands of small companies dealing with data, individuals running web forums etc.

It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you can say is "yeah, you should have implemented that 15 years ago, it's already been German law that long".

In Germany not much will change, but at least companies like Facebook can no longer just move to another country with worse privacy laws (like Ireland) and call it a day. For us the GDPR means that protecting user data will no longer be a competitve disadvantage. But if you're a small company and handling data reasonably, the GDPR won't hurt you anyway.

Re: GDPR: Removing Monal from the EU

#194
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

> The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

Okay: when you were writing this, you must been either drunk, you forgot how easy it is to find your projects via your HN profile and general googling, or you simply don’t have a single enemy out there who is waiting to hurt you/your business. I hope all of it together!!

Re: GDPR: Removing Monal from the EU

#195

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

> no, only larger orgs handling lots of personal data need this. I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?

Section 1 only requires A DPO when you are operating at "large scale".

Re: GDPR: Removing Monal from the EU

#196
As a mostly disinterested party here, I can't help but to be happy about GDPR. I know that the large internet companies in my country like Google, Facebook, Amazon, Twitter, Oracle, IBM, etc. will have no trouble complying with this law but it will help to deter smaller competitors and upstarts from other countries and from within the EU. That's more money for us and a nice fat moat to keep everyone else out. This just made Silicon Valley impregnable.

All that's very well though. The fact this was posted on a large traffic like Hacker News means the author of monal.im will be subject to spiteful abuse from EU citizens whom believe their nation^H^H^H^H "union" can do no wrong.

Re: GDPR: Removing Monal from the EU

#197
post #8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

Re: GDPR: Removing Monal from the EU

#198

Earlier quoted context omitted.

From Article 37 GDPR: (1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or .... Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or tr…

I don't think he has access to the messages, it's an IM client. If he did have access to the messages then I fail to see how having to hire a DPO in that case would be outrageous. If anything, that's the reasonable thing to do.

Avoiding the cost and removing the app from the EU market is also a reasonable decision.

Re: GDPR: Removing Monal from the EU

#199
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

AFAICT, it's not a public authority or body (37(1)(a)), it's not "regular and systematic monitoring of data subjects on a large scale" (37(1)(b)) (it seems to be merely crash reports and minimal information required for the service, not systematic monitoring), nor is it one of the special classes of data (37(1)(c)). I'm not sure how you could could conclude a DPO is necessary.

Re: GDPR: Removing Monal from the EU

#200
post #156

Earlier quoted context omitted.

Ask the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance. https://ico.org.uk/for-organisations/guide-to-the-general-da... https://ico.org.uk/global/contact-u…

ICO is just the UK regulator. How about the regulators of the other 28 EU states?

Harmonized. So an ok from one would count pretty heavily when interacting with others.
Post reply on HN