While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…
Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…
GDPR: Removing Monal from the EU
291–300 of 957 posts
Re: GDPR: Removing Monal from the EU
#292Earlier quoted context omitted.
From my German perspective this whole GDPR panic is so interesting. The GDPR is basically a carbon copy of the data protections laws that have evolved in Germany since 1977. Yet we still have many thousands of small companies dealing with data, individuals running web forums etc. It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you…
Data Protection Officer, right to be forgotten, data exportability, ... Can you hint me to one of those German laws which do require one of the above?
It literally translates to "federal data protection law" and has been German law since 1978. In certain conditions it has also mandated a DPO (https://de.wikipedia.org/wiki/Datenschutzbeauftragter) since then, but in fact the first DPO position in Germany was created in 1971.
The right to be forgotten is mandated by article 35 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__35.html).
The right to a data export is mandated by article 34 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__34.html). It has always been common use this law to get a free copy of the data which our credit reporting agencies have about you, I've done that multiple times.
Re: GDPR: Removing Monal from the EU
#293Earlier quoted context omitted.
> For a startup or small company, the cost is prohibitively high. Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do i…
> The cost is strongly related to the size of the organization There is a correlation between the number of GB you store and eg. how many DPOs you require?
Re: GDPR: Removing Monal from the EU
#294Earlier quoted context omitted.
You've made many concrete, general statements in this discussion which turn out to be relevant to your personal situation and your personal appetite for risk. Maybe that's not an effective way of holding a conversation about the general issues around the GDPR?
I'm not sure what else I should reply to something like your comment before tbh. Neither can I predict the future, nor am I a lawyer. I'm just posting about my opinion, which I got by gathering information online and from consulting with a lawyer. I've stated the conclusion I've come to, based on this information and yes, I believe that to be correct (or as correct as one can be about a law with no reference cases in…
Maybe you have huge assumptions that people reading what you say will add all kinds of limitations to what you say? I don't. It leads to terrible discussions, like this one.
Re: GDPR: Removing Monal from the EU
#295Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…
"If such a set of instructions exists, I haven't seen it"
Maybe for me it is easy set of instructions, for some maybe not.
Re: GDPR: Removing Monal from the EU
#296While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…
Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.
Maybe one could argue that there is something to be gained by differentiating the rules based on the industry but, at least to me, it is not obvious that the result would be better and not just more complex. Also there are already rules and laws for specific industries and how they have to handle personal information, think for example medical or financial data.
Re: GDPR: Removing Monal from the EU
#297Earlier quoted context omitted.
But the usual requirement for piercing the corporate veil is that the owner/operator of the business is using the business with the sole reason of insulation from having their private assets in the line of fire. If the business is otherwise legit and a fine were levied against the business there would be a fairly strong barrier before the assets of the shareholder become part of the story. A good precaution against t…
IANAL, but that is not the requirement I've heard. It is perfectly valid to insulate one's other assets from corporate creditors. One must voluntarily commingle those assets with corporate assets in order to justify a piercing. It's not always obvious to the careless what will constitute commingling, but this is kind of the point of corporations. Frankly this post has prompted me to reevaluate your other legal advice…
Re: GDPR: Removing Monal from the EU
#298Many of the comments here are rebutting - saying that a DPO isn't needed or that this guy gave up unnecessarily. But the fact that he had to spend who knows how much of his time to even discover whether he needs to do anything (or what sort of trouble he could get into) is too much of a barrier for many people and their hobby side projects. This is unfortunate and not surprising collateral damage of the GDPR.
Then I actually spent a little time to find out more and, as someone who cares about privacy, quickly realised the positive intent behind it, and how simple it is to comply with in principle: let users know what data you collect and what you do with it, and give them the possibility to request it or request it's deleted.
TBH, if someone requested any of this, I'd do it without the GDPR.
Re: GDPR: Removing Monal from the EU
#299This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
> Legal compliance is a requirement for any business
You are required to comply with the laws of your country, not those of other countries.
Re: GDPR: Removing Monal from the EU
#300You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
From Article 37 GDPR: (1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or .... Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or tr…
He has no data of the kind described in Article 9.