Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

221–230 of 957 posts

Re: GDPR: Removing Monal from the EU

#221

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

https://ico.org.uk/for-organisations/guide-to-the-general-da... Under the GDPR, you must appoint a DPO if: you are a public authority (except for courts acting in their judicial capacity); your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or your core activities consist of large scale processing of special categories of data or data re…

In Germany the law has been that you only need a DPO if a) you are a public authority, b) at least 10 people in your organization/company handle or have access to personal data or c) you handle sensitive data (e.g. health records).

As far as I know the GDPR doesn't change these requirements here. So even if you're a company of 5 people and just handling some email addresses or similar data you certainly don't need a DPO.

Re: GDPR: Removing Monal from the EU

#222
post #211

Earlier quoted context omitted.

Where in the law does it say they only do this when ignored? Surely if this were the case, they'd put it in the law like they did punishment limits. Or are you banking on subjective enforcement?

Right here. You get a month to comply with any deletion request and can extend it to 3 months if needed. https://gdpr-info.eu/art-12-gdpr/ "The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into accoun…

That seems like a request from a data subject. I was responding to a comment that said you will only be sued by a regulator if you ignored them. There are multiple blog posts and articles that regulators have posted about what they will and wont do that is not codified.

Re: GDPR: Removing Monal from the EU

#223
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

A designated DPO is a ROLE not a person, that's a huge difference. Just like a security officer in a small company is a role assigned to someone who most likely has other duties too in a large company it will be a dedicated person (and in a really large company there might even be more people working in a team under a CISO or something to that effect). So 'designated' means that the role has to be assigned to a person, it does not say 'dedicated' where you'd have to have a person whose exclusive job is DPO.

So, DPO is not necessarily a person with no other duties. In most smaller organizations that deal with sensitive data the DPO role will be shared with the CCO (Chief Compliance Officer), only at a certain scale of processing and with certain data would you need to budget for a dedicated DPO from day one, but presumably your business plan will also foresee in other things such as office space, computers and so on. Certain businesses come with implied costs.

Re: GDPR: Removing Monal from the EU

#224
post #205

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

I think you're lumping together too many things. > I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. > All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. What if I didn't want you to visit my w…

If you didn't want visitors to your site you shouldn't have put it on the web. If you want visitors to your site without any strings attached you should serve the content without grabbing and storing anything about the clients.

This is called the "technician's responsibility" where I come from. To only track/store/process what is absolutlely necessary, in order to not be liable for the consequences when someone you cannot feasibly stop wants to do something untoward with the date (i.e. unconcented analysis, government extraction of data, breaches)

Re: GDPR: Removing Monal from the EU

#225

Earlier quoted context omitted.

> We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least) So someone having a copy of my data that I wish be removed is trampling on a webmaster's rights? That makes no sense whatsoever. > Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers This isn't even true. They h…

But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.

If I get nude picutures of you, or your mother, daughter etc. is it then "my data"? Am I therefore allowed to do with that data as I wish?

I think most people agree that unless those pictures are gathered with very specific consent, subject to many restrictions, they are not "my data". This is obviously an extreme example, but the reasoning extends to more data that is considered sensitive. The point being that "data ownership" is a complicated issue.

Re: GDPR: Removing Monal from the EU

#226
post #189
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

Maybe companies that are so flimsy didn't have long left anyway. You're required to have a fire safety officer at these companies too, but it's not a full-time position.

I think this is a legitimate cultural difference.

I’m fairly left leaning for a US citizen & find the idea that the default should be big companies abhorrent.

But I recognize my bias & am not st all convinced it’s in any way objectively correct.

Re: GDPR: Removing Monal from the EU

#227

Earlier quoted context omitted.

I don't think he can. The DPO may not be assigned any tasks that would result in a conflict of interest between their role as a DPO and their other responsibilities. I suspect that means that the sole proprietor can't be the DPO. But, you know, not a lawyer, not even European, could be wrong. See article 38, paragraph 6, 2nd sentence.

Yup, I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases. But, yeah, I'm not a lawyer too. Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion) > CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO?​​​ > Yes. However, you must ensure that other professional duties of this emp…

I would say there is a definite conflict of interest for the sole owner to be the DPO - you are responsible for the entire direction of the company, thus have considerations beyond data protection (rather than an individual who ONLY has to consider the data protection outcomes in the exercise of his duties). Even if you make data protection a paramount concern, and intend to be fully compliant, there is the possibility that you could e.g. make more money or provide a better service by making a different choice, therefore there is a conflict of interest.

Re: GDPR: Removing Monal from the EU

#228

Earlier quoted context omitted.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

> For a startup or small company, the cost is prohibitively high.

Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do in order to get to where they should be and the remainder has a bit more work but will mostly likely be more-or-less compliant by the 25th and what work remains will be done long before the eye of Sauron will turn their way by virtue of their size.

The cost is strongly related to the size of the organization and the amount of sensitive data you hold as well as whether or not you were a bad steward of the data in the past.

Re: GDPR: Removing Monal from the EU

#229
post #189
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

Maybe companies that are so flimsy didn't have long left anyway. You're required to have a fire safety officer at these companies too, but it's not a full-time position.

> You're required to have a fire safety officer at these companies too, but it's not a full-time position.

AFAIK, most of the "safety committee" regulations usually have waivers for small companies.

Re: GDPR: Removing Monal from the EU

#230

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. That person doesn't own those bits on that hard drive.

They don't own the bits. They own the data those bits represent. The person/company who does own the bits has to comply with the rights of the owner of the data.

How you decide to store it makes little difference as long as it's digital.

Fun aside: if you store it on paper you're not beholden to GDPR. Crazy.

Post reply on HN