Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

291–300 of 957 posts

Re: GDPR: Removing Monal from the EU

#291

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

Well, the "appropriate indicators" would need to meet the "required standards" mentioned in the parent post. I think the example is ok.

Re: GDPR: Removing Monal from the EU

#292

Earlier quoted context omitted.

From my German perspective this whole GDPR panic is so interesting. The GDPR is basically a carbon copy of the data protections laws that have evolved in Germany since 1977. Yet we still have many thousands of small companies dealing with data, individuals running web forums etc. It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you…

Data Protection Officer, right to be forgotten, data exportability, ... Can you hint me to one of those German laws which do require one of the above?

https://de.wikipedia.org/wiki/Bundesdatenschutzgesetz

It literally translates to "federal data protection law" and has been German law since 1978. In certain conditions it has also mandated a DPO (https://de.wikipedia.org/wiki/Datenschutzbeauftragter) since then, but in fact the first DPO position in Germany was created in 1971.

The right to be forgotten is mandated by article 35 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__35.html).

The right to a data export is mandated by article 34 BDSG (https://www.gesetze-im-internet.de/bdsg_1990/__34.html). It has always been common use this law to get a free copy of the data which our credit reporting agencies have about you, I've done that multiple times.

Re: GDPR: Removing Monal from the EU

#293

Earlier quoted context omitted.

> For a startup or small company, the cost is prohibitively high. Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do i…

> The cost is strongly related to the size of the organization There is a correlation between the number of GB you store and eg. how many DPOs you require?

No.

Re: GDPR: Removing Monal from the EU

#294

Earlier quoted context omitted.

You've made many concrete, general statements in this discussion which turn out to be relevant to your personal situation and your personal appetite for risk. Maybe that's not an effective way of holding a conversation about the general issues around the GDPR?

I'm not sure what else I should reply to something like your comment before tbh. Neither can I predict the future, nor am I a lawyer. I'm just posting about my opinion, which I got by gathering information online and from consulting with a lawyer. I've stated the conclusion I've come to, based on this information and yes, I believe that to be correct (or as correct as one can be about a law with no reference cases in…

You stated your extremely general conclusions, and only later mentioned that they were relevant to your personal business. And in this particular sub-thread, you made a very general statement about risk, again without qualifying it at all. And you only mentioned the lawyer after you were challenged about a general statement.

Maybe you have huge assumptions that people reading what you say will add all kinds of limitations to what you say? I don't. It leads to terrible discussions, like this one.

Re: GDPR: Removing Monal from the EU

#295

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

"Even if I had the desire to read through the law (I don't)"

"If such a set of instructions exists, I haven't seen it"

https://gdpr-info.eu/

Maybe for me it is easy set of instructions, for some maybe not.

Re: GDPR: Removing Monal from the EU

#296

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.

If you abstract away the industry specific details of my examples, you are not supposed to physically endanger, harm or kill people regardless of the actual industry. So I would say it is exactly the same but instead of physical harm we are talking about harming peoples' privacy.

Maybe one could argue that there is something to be gained by differentiating the rules based on the industry but, at least to me, it is not obvious that the result would be better and not just more complex. Also there are already rules and laws for specific industries and how they have to handle personal information, think for example medical or financial data.

Re: GDPR: Removing Monal from the EU

#297

Earlier quoted context omitted.

But the usual requirement for piercing the corporate veil is that the owner/operator of the business is using the business with the sole reason of insulation from having their private assets in the line of fire. If the business is otherwise legit and a fine were levied against the business there would be a fairly strong barrier before the assets of the shareholder become part of the story. A good precaution against t…

IANAL, but that is not the requirement I've heard. It is perfectly valid to insulate one's other assets from corporate creditors. One must voluntarily commingle those assets with corporate assets in order to justify a piercing. It's not always obvious to the careless what will constitute commingling, but this is kind of the point of corporations. Frankly this post has prompted me to reevaluate your other legal advice…

My exposure to this is limited to cases in Europe and ones that I was a direct witness to and in all those cases it was pretty clear that the company was created with the express purpose to commit bankruptcy fraud and the result was the owner of those companies lost his shirt. All other attempts to pierce the corporate veil that I've seen failed.

Re: GDPR: Removing Monal from the EU

#298

Many of the comments here are rebutting - saying that a DPO isn't needed or that this guy gave up unnecessarily. But the fact that he had to spend who knows how much of his time to even discover whether he needs to do anything (or what sort of trouble he could get into) is too much of a barrier for many people and their hobby side projects. This is unfortunate and not surprising collateral damage of the GDPR.

I'm a small businesses owner. When I first found out about the GDPR, this was exactly my view, and I even posted on HN to that effect.

Then I actually spent a little time to find out more and, as someone who cares about privacy, quickly realised the positive intent behind it, and how simple it is to comply with in principle: let users know what data you collect and what you do with it, and give them the possibility to request it or request it's deleted.

TBH, if someone requested any of this, I'd do it without the GDPR.

Re: GDPR: Removing Monal from the EU

#299

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR)

> Legal compliance is a requirement for any business

You are required to comply with the laws of your country, not those of other countries.

Re: GDPR: Removing Monal from the EU

#300

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

From Article 37 GDPR: (1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or .... Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or tr…

> Even though no message traffic passes through Monal’s sever

He has no data of the kind described in Article 9.

Post reply on HN