Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

361–370 of 957 posts

Re: GDPR: Removing Monal from the EU

#361

I'm pretty sure lawyers and "consultants" are the only ones super happy about GDPR. Companies will still harvest user data with updated T&Cs and more buttons for the user to click, because all services will be useless without accepting. Governments will also continue gathering users' data for "the common good".

I'm pretty sure that many ordinary European (and US!) citizen are pretty happy about the GDPR as well. If clicking an extra button is really all it takes.

But despite the assurances of many here that it's not hard to comply, I'd probably have shut down the servers of my own hobby non-profitable location data gathering website as well, simply because even reading the GDPR document would be too much effort.

Re: GDPR: Removing Monal from the EU

#362

Earlier quoted context omitted.

> A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). They don't do safety inspections in the US? Doesn't the vehicle need to have brakes, a means to change direction, emission checks and so on?

TIL in some states they do emissions checks (although in a lot of states motorcycles are totally exempt from those anyway). And no, they don't do safety inspections of "specially constructed vehicles". And based on the ones I've seen, I can't imagine a world in which they'd pass. [1] [1] http://bosshoss.com/supersport-bike/

However, at least some states (probably most) require a minimum level of insurance from a carrier licensed in the state. There's nothing that requires those carriers to provide insurance to vehicles that don't meet their minimum requirements.

Re: GDPR: Removing Monal from the EU

#363

Earlier quoted context omitted.

https://de.wikipedia.org/wiki/Bundesdatenschutzgesetz It literally translates to "federal data protection law" and has been German law since 1978. In certain conditions it has also mandated a DPO ( https://de.wikipedia.org/wiki/Datenschutzbeauftragter ) since then, but in fact the first DPO position in Germany was created in 1971. The right to be forgotten is mandated by article 35 BDSG ( https://www.gesetze-im-inter…

Thank you for those detailed links. They are kind of eye opening, and I am German. However, it is hard to understand how stuff like GEZ, Schufa and article 35 can exist concurrently in the same country.

Schufa (the biggest consumer credit reporting agency in Germany) and article 35 can certainly co-exist. In fact you can write to Schufa and request that they delete all your data.

However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that.

Re: GDPR: Removing Monal from the EU

#364

Earlier quoted context omitted.

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?

It really should be defined by company size or revenue. If I my site goes viral and a small web app suddenly has 2M lines of logs, but my revenue is small/non-existent, then there's no reason to comply. If that pushes my revenue over 1M euros a year, you now get pushed into a zone where you should be compliant, and you have enough revenue to afford it as well.

Another comment in this thread indicated that "large scale" was any business in which 5 employees or more had access to the data in the course of normal business operations.

Not exactly an ironclad source, but better than nothing, hopefully.

Re: GDPR: Removing Monal from the EU

#365

Earlier quoted context omitted.

> And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary Views like this are exactly why we need the GDPR. I find it utterly ridiculous - disgusting even - that you really believe you have the right to do whatever you want with someone else's personal information. When you provide an email addr…

And I find it equally disgusting that you think users' feelings are more important than webmasters' property rights.

Holy shit man, did you come right out of "Atlas Shrugged"?

This isnt even users feelings, this is data that can a:have monetary value and b:can be plain wrong and damage a user.

Do you think that merely by observing data you have right to it? Do you not believe in any IP law? If you agree with any type of IP law then you are just being hypocritical by insisting that webmasters get to take and use whatever data they come across

Re: GDPR: Removing Monal from the EU

#366

Earlier quoted context omitted.

If the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?

I think everyone already knows that more regulations hurt businesses. We don't have to wait for the result to find that out. The question is whether the help done to consumers outweighs that. There are many ways to tackle the privacy issue beyond a large, sweeping law.

> I think everyone already knows that more regulations hurt businesses.

That's not a given. Further, it's more important to look at what's better for society as a whole. Further, less regulation within banking caused some big profits.. but also some hefty problems.

Re: GDPR: Removing Monal from the EU

#367
post #60

Please be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.

Unfortunately every single one of these stories has turned into a long form ad-hominem attack against the site owner and their supposed alterior motives.

Re: GDPR: Removing Monal from the EU

#368

Earlier quoted context omitted.

> then you will be warned to become compliant long before you will be fined citation needed > if you do not collect data that you have no use for you are 95% there. I have always been respectful and even never required emails on signups. I am not 95% there because there is a ton more to do. In fact i am at 5% because i have a lot of small scale past projects. Not everyone is a VC-funded startup. That's the kind of em…

> citation needed Every statement issued by EU regulators to date. > I have always been respectful and even never required emails on signups. Good. > I am not 95% there because there is a ton more to do. Such as? > In fact i am at 5% because i have a lot of small scale past projects. You've had two full years to get this done. The law came into effect the 14th of April 2016. It is now May 2018. > Not everyone is a VC…

> 95% Such as?

Everything. Even if you process just an IP you need to document your procedures, change privacy policies. If at any point you ask for anything you need to implement opt ins, a way for (unauthenticated) users to request their data (even if it's just 1 IP) etc. My point is that having negligible private data is not less of a compliance burden than having a lot of private data.

> You've had two full years

You mean i ve had 2 years to attempt to interpret a vaguely written law. Actionable information is just now coming out, and even that is contradictory (cue this topic). Even the EU parliament's website does not comply yet.

> you likely were already riding a very fine line with respect to the DPD

First, that is a directive, not a law and compliance can vary widely. Second, gdpr requires new procedures which means it requires amendments anyway

> Such as?

I have posted another comment

Re: GDPR: Removing Monal from the EU

#369

Earlier quoted context omitted.

I'm sure the person you're replying to is also talking in the 'rightful' sense. While the data collected technically belongs to you, it can still be a privacy violation. This is extremely important on the web where it's very easy to share that data, make it public or accidentally leak it.

It can be a privacy violation but the idea of a fundamental right to privacy is not universally supported like free speech. If it is a fundamental right, how far does it go? Should I be able to sue you for watching me walk in a public place? Photographing me? Video taping me? What about a privately owned but still public place? There are a lot of questions here that I think people tend to skip over about users owning…

There are lots of laws against following someone and observing/recording every move they make.

Making some observations out your window of cars passing by is something no one ever had a problem with. Taking down every single identifier you could and coordinating with others to track that person, for a profit, is something that would not be kosher in meat space.

Why this different just because it's on a computer?

Re: GDPR: Removing Monal from the EU

#370
post #185

Earlier quoted context omitted.

GDPR does not require deleting data from backups. http://blog.quantum.com/backup-administrators-the-1-advice-t... "The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations wil…

CNIL is one of ~20 regulatory agencies & this isn’t their “official” stance. Other opinions have concluded that you must keep an index of requested deletes in the face of backups, for instance.

I don't see the problem here (for small companies). If you have a database with user data, and a user deletes his account, you delete the data from production. At this moment, you have a live system without this users data, and some backups with the data. The moment you make a new backup, you have a dataset to restore from that does not include the user data.

You keep daily backups for 1 week, and after one week the users data is gone from all backups.

The only possible window for restoring deleted user data is the time window from deletion to backup. To "solve" this you need to make more backups, ideally live backup and replication with really frequent snapshotting. And this is something you would want even without the new law, because you don't want to lose user data in case of a server failure. Why would you restore from an old backup? (And if you really need to restore from an old backup you most likely want to merge this backup with the newest one to reduce data loss. In this case you can reapply all deletes.)

The new laws don't change anything. For me at least. Also my lawyer is totally fine with "only" minimizing the problematic time window. We both know that it will never be zero.

Post reply on HN