Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

251–260 of 957 posts

Re: GDPR: Removing Monal from the EU

#251
post #28
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

Yeah, they are over-reacting. For example, IP addresses are considered personal information but what that means is you just can't blindly collect them. If the service you use relies on IP addresses as a basic point of operation then its fine. CDNs aren't going out of business for example.

> that means is you just can't blindly collect them

Genuinely curious, what about all of the web servers that log every request which usually by default includes the client IP? Not doing anything special with the IP, they are just there in log files and archives.

Re: GDPR: Removing Monal from the EU

#252
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Having an app that is non compliant out there induces anxiety. Having 10-20 old or fire-and-forget projects out there, it's anxiety multiplied. There is a non negligible chance that One disgruntled or trolling user or competitor will report you to their country's DPA . There are 28 DPAs and they are not all as good and fair as Germany's or the UK's , they may fine you even if there is no good reason. Example: in my country the DPA fined a company last week (3000 euros) because they searched a company's computer while the employee was not present, even though they found that the computer did not contain any personal information.

Re: GDPR: Removing Monal from the EU

#253
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

From my German perspective this whole GDPR panic is so interesting. The GDPR is basically a carbon copy of the data protections laws that have evolved in Germany since 1977. Yet we still have many thousands of small companies dealing with data, individuals running web forums etc. It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you…

Data Protection Officer, right to be forgotten, data exportability, ...

Can you hint me to one of those German laws which do require one of the above?

Re: GDPR: Removing Monal from the EU

#254
post #58

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

which clause would apply to require a DPO? clause a: not a public body clause b: not systematically monitoring (eg. installing video cameras all over the streets) clause c: not processing large scale sensitive or criminal information. doesn't look to me like a DPO is needed based on this article?

It really comes down to the definition of "systematically monitoring". On our service we capture behavior (say in FullStory) and Google Analytics at a "large scale". How the DPO clause gets interpreted is going to be a key finding in the next few months. This is imho the most confusing and potentially difficult part of GDPR

Re: GDPR: Removing Monal from the EU

#255
While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU.

As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide free meals for homeless people in my spare time. I just built this car from scratch for myself and now they tell me I can not drive it on public roads just because I don't have the time and money to meet the required standards?

Re: GDPR: Removing Monal from the EU

#256

Earlier quoted context omitted.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

> For a startup or small company, the cost is prohibitively high. Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do i…

> The cost is strongly related to the size of the organization

There is a correlation between the number of GB you store and eg. how many DPOs you require?

Re: GDPR: Removing Monal from the EU

#257
post #204
post #27

Earlier quoted context omitted.

The burden is if the EU does investigate him, for whatever reason whatsoever, even if he is 100% compliant he needs to spend money to prove he is compliant and deal with the EU.

Why would you think that? If he wanted to be compliant he only needs two things: 1. Some procedure that allows him to answer users privacy requests ("what information about me do you have?", "Please delete my personal data from your servers.") 2. A so called "directory of procedures" which states what data you collect and who's responsible for it. If your fail to comply with 1. the user can call upon their local data…

> Why would you think that?

I think the majority of users on HN are from the US. And going by the GDPR related comments over the past few months, it seems the litigious US stereotype really is true - a lot of people seem to be prepared to "lawyer up" at the drop of a hat!

Re: GDPR: Removing Monal from the EU

#258
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

Is a single person running an app as a hobby a business?

If I want to put an open source app in the App Store, that’s not a business model for me. It’s more just personal expression.

Re: GDPR: Removing Monal from the EU

#259
post #27

Earlier quoted context omitted.

The burden is if the EU does investigate him, for whatever reason whatsoever, even if he is 100% compliant he needs to spend money to prove he is compliant and deal with the EU.

As a North-American with no legal presence in the EU, how would he be 'investigated'?

Realistically, he wouldn't be.

The EU is not the USA.

The authorities have limited resources, and are only interested in large-scale privacy abuses.

Re: GDPR: Removing Monal from the EU

#260

Earlier quoted context omitted.

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

You've made many concrete, general statements in this discussion which turn out to be relevant to your personal situation and your personal appetite for risk. Maybe that's not an effective way of holding a conversation about the general issues around the GDPR?

I'm not sure what else I should reply to something like your comment before tbh. Neither can I predict the future, nor am I a lawyer. I'm just posting about my opinion, which I got by gathering information online and from consulting with a lawyer. I've stated the conclusion I've come to, based on this information and yes, I believe that to be correct (or as correct as one can be about a law with no reference cases in court yet).

I was just pointing out, that when a lawyer says "probably", he usually has a good reason to do so. And it's my strong belief that the reference cases in court will not be fought by small companies, because they rarely are.. There is just not enough money to make fit the effort you need to put in winning the first case. Before there is not one single case, I don't think it's necessary to panic and shut everyone out.

You don't need to believe me or agree with me, but reducing this to "my personal appetite for risk" is really weird.

Post reply on HN