Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

211–220 of 957 posts

Re: GDPR: Removing Monal from the EU

#211

Earlier quoted context omitted.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

Where in the law does it say they only do this when ignored? Surely if this were the case, they'd put it in the law like they did punishment limits. Or are you banking on subjective enforcement?

Right here. You get a month to comply with any deletion request and can extend it to 3 months if needed.

https://gdpr-info.eu/art-12-gdpr/

"The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests."

Re: GDPR: Removing Monal from the EU

#212
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high.

I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

Re: GDPR: Removing Monal from the EU

#213

Earlier quoted context omitted.

But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.

> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

I hate this binary choice between all or nothing

Your personal info, username, account settings, marketing anayltics, etc. are definitley you're data and you should be free to have them deleted.

The two year old IPs in a server log sitting in backup, or a chance occurrence of your username in a random call stack for some web exception is not your data, and you shouldn't force a business to have to dig through that mound of digital noise to satisfy your deletion needs

Re: GDPR: Removing Monal from the EU

#214

Earlier quoted context omitted.

> no, only larger orgs handling lots of personal data need this. I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?

Section 1 only requires A DPO when you are operating at "large scale".

Article 1 (c): the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or ....

What makes you believe that the "large scale" refers to the size of the organisation and not on the amount of processed data.

Re: GDPR: Removing Monal from the EU

#215

Earlier quoted context omitted.

> If people named Jane are more likely to eat ice cream, you can't target ice cream ads at them and help keep your site free, without asking them. Apart from the fact that people named Jane aren't more likely to eat ice cream, you seem to criticize that it gets harder to target ads? Oh no, that's a real pity. Oh no, poor webmasters.

>Oh no, that's a real pity. Oh no, poor webmasters. Why are the rights of people who own websites less important to you than the rights of other people? Regardless, you might not still be saying this once half the websites smaller than Google become subscription-based in the EU or just block the EU altogether.

I didn't really realise it until the GDPR got into full swing but I'd much rather pay with money than with data.

What you're describing is a good thing. If you're going to treat my data like an almost stale slice of pie selling it off cheap to anyone who will buy it - Please do block my access!

Re: GDPR: Removing Monal from the EU

#216

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it.

That person doesn't own those bits on that hard drive.

Re: GDPR: Removing Monal from the EU

#217

Earlier quoted context omitted.

This is what Limited Companies, LLC's and Corporations are for. The monetary and time cost is minimal, but the mental benefit is pretty damn good.

Corporate veil piercings happen a lot more when your a small or one man shop, and officers can often be directly liable for the actions of the company. It's not as bulletproof as you think.

But the usual requirement for piercing the corporate veil is that the owner/operator of the business is using the business with the sole reason of insulation from having their private assets in the line of fire. If the business is otherwise legit and a fine were levied against the business there would be a fairly strong barrier before the assets of the shareholder become part of the story. A good precaution against this is to have more than one shareholder (preferably more than a token percentage for the second shareholder).

Re: GDPR: Removing Monal from the EU

#218

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

I suspect it's going to be a bit like IR35 in the UK. Menacing on first glance, but so broad in it's definition that any court is going to struggle to draw the hard conclusions for anything that isn't what the law was explicitly created to prevent.

Having to rely so much on the discretion of the courts is not a good thing. Generally, it is better if all people who agree on what happened agree about the legality of that.

When instead it is up for interpretation, that comes with issues. The first is selective enforcement, there is also the chilling effect on both sides. Those who ought to be protected worry about the slack given to their potential predators. Meanwhile those who are 'potential predators' need to worry about the slightest move that is illegal under some interpretation.

The end result of this chilling effect is fewer willing customers, fever willing companies, and less mutual trust. Notably, this lack of trust persists even if you presume everyone still follows the law. At that point it seems to me a law has failed.

Re: GDPR: Removing Monal from the EU

#219

Earlier quoted context omitted.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

As a webmaster, I have an absolute right to carve '192.0.2.7 requested /foo.html from me' into stone and store it for posterity.

The GDPR prohibits me from doing that, and in fact requires that I have the ability to rewrite history by removing that fact if the user who had 192.0.2.7 ever requests it.

Some people, on hearing this, say, 'well, that's fine, you can just store 192.0.2 or 192.0 instead.' That seems pretty silly to me, since the whole point of logs is that they contain full information.

The GDPR tries to do the right thing, but it's broken. Immutable logs are a fundamental right.

Re: GDPR: Removing Monal from the EU

#220

Earlier quoted context omitted.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

"users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do" I'll let that excerpt speak for itself. And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary.

> And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary

Views like this are exactly why we need the GDPR.

I find it utterly ridiculous - disgusting even - that you really believe you have the right to do whatever you want with someone else's personal information. When you provide an email address, physical address, name or other PI, it's with the expectation of it being used for a specific purpose - you should absolutely not give you the right to sell that information to the highest bidder.

Post reply on HN