Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

301–310 of 957 posts

Re: GDPR: Removing Monal from the EU

#301

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

> extremely shallow interpretation of the GDPR

Please elaborate. I was unable to perceive the legal depth of interpretation.

> you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away

Businesses limit liability and legal exposure all the time.

It's a tradeoff, as all things are.

Re: GDPR: Removing Monal from the EU

#302
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

GDPR does not require you to delete PII from backups. This is a misconception. You do need to have a documented and implemented backup retention policy and communicate this if you receive a request to delete a user's data.

There are other laws which require you to keep data for up to 10 years. This will require you to split up your backups and clean the ones for the longer storage from all unnecessary PII. That is already costly and challenging. Problem is nobody really knows what data you have to strip of and what do you have to retain for other laws.

Re: GDPR: Removing Monal from the EU

#303

Earlier quoted context omitted.

It doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.

You are making a claim to one of 2 things: - the ip addresses never uniquely identify someone or - you have a legitimate interest to collecting this data. Neither provides carte blanche for collecting IP address.

I'm actually saying that both are a requirement for logging IPs in the circumstances being discussed here, but I certainly don't mean to suggest that either would grant you "carte blanche" to collect and log IPs.

Re: GDPR: Removing Monal from the EU

#304
post #111

Earlier quoted context omitted.

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

He's not monitoring the data. He's not handling sensitive personal data. He doesn't need a DPO. See also the derogation for micro companies: https://gdpr-info.eu/recitals/no-13/ > To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.

> He's not handling sensitive personal data.

How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".

Re: GDPR: Removing Monal from the EU

#305

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

If you are not doing anything shady, if you have your house in order security wise and if you do not collect data that you have no use for you are 95% there. The remainder will maybe require consultation with a lawyer for an hour or two if you want to play it safe but you could also simply wait for a few months to see how it all plays out.

If you are respectful of other people's privacy then there is very little chance that you will be found afoul of the law and even if you should be then you will be warned to become compliant long before you will be fined.

This whole discussion is beyond ridiculous.

Imagine the rest of the world reacting to the DMCA this way which has far wider scope and effect.

Re: GDPR: Removing Monal from the EU

#306
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

Backups have an expiration. That should be enough to satisfy the requirement for deletion.

[deleted]

Re: GDPR: Removing Monal from the EU

#307

Earlier quoted context omitted.

He is meeting the required standards... by not having an EU users. In doing that he's as equally compliant as any company who has jumped through the various GDPR hoops.

And has made his business that much less viable, and opened himself up to competition from a company with a comparable product that does comply with the law. And maybe one day the USA will pass some privacy legislation...

I'm not actually sure he is running this as a business? It seems open source? He even suggests people download and build their own?

So all he's done is save himself the time and effort of dealing with the GDPR and cost himself nothing.

Re: GDPR: Removing Monal from the EU

#308

Earlier quoted context omitted.

He is meeting the required standards... by not having an EU users. In doing that he's as equally compliant as any company who has jumped through the various GDPR hoops.

And has made his business that much less viable, and opened himself up to competition from a company with a comparable product that does comply with the law. And maybe one day the USA will pass some privacy legislation...

> opened himself up to competition from a company with a comparable product that does comply with the law

I'm sure another free and open source product will seriously impact his profit.

Re: GDPR: Removing Monal from the EU

#309

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Re: GDPR: Removing Monal from the EU

#310

This project is completely out of scope for GDPR, not having any presence whatsoever in the EU. You aren't going to be arrested when going on holiday. You wouldn't be breaking the law at all, even if it was possible to enforce anything. Even if it was in the EU, it wouldn't require a DPO, and your use of IP addresses is very reasonable and within the standard allowances which don't require user consent. Maybe bother…

Disclaimer: I work on GDPR stuff for a company it certainly applies to, this is my opinion not my companies We’ve spent tons of money & interacted with lots of official sources trying to get opinions about what GDPR means and it just isn’t available. Everything is a risk mitigation technique right now with no real answers in sight. If I had any personal projects serving traffic in the EU right now that weren’t profit…

What are you talking about? There's a ton of information about what GDPR means, both from the EU and the national regulators (particularly the ICO). The best sign that the regulators aren't going to go crazy with this, is that they already have quite significant powers and they're not throwing their weight around now.
Post reply on HN