Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

401–410 of 957 posts

Re: GDPR: Removing Monal from the EU

#401

Earlier quoted context omitted.

Perhaps it costs money to do so, and the company does not have enough working capital + lines of credit to make the payments necessary? I feel like your statement here is basically "you are a business, therefore it is impossible for you to run out of money", which -- superficially -- seems very naive.

At that level it doesn't have to cost anything other than your time. And if it's not a business it is a hobby and those cost time (and usually also money). The GDPR is not going to cause any but the weakest businesses to close shop, in fact if the GDPR causes a business to close (which I highly doubt other than people voluntarily throwing in the towel because they can't be bothered) then I am not sure if I'm going to…

The comment I responded to cited environmental regulation. These are oftentimes costly to implement. All regulation costs money to implement. Even if each regulation by itself is cheap, these things add up -- it's death by a thousand cuts.

Re: GDPR: Removing Monal from the EU

#402
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

"We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation"

We still do. Nothing has changed on that front.

"Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time."

As it should have been from the beginning. Having the standard being that the company hoovers up all your data all the time without telling you what they're doing with it or why they need it was a terrible, terrible thing.

"The EU has shot themselves in the foot and more and more companies are going to refuse to do business with them because of it."

I highly doubt it.

Re: GDPR: Removing Monal from the EU

#403
post #343

Earlier quoted context omitted.

Perhaps it costs money to do so, and the company does not have enough working capital + lines of credit to make the payments necessary? I feel like your statement here is basically "you are a business, therefore it is impossible for you to run out of money", which -- superficially -- seems very naive.

Obviously it might cost money (or time, which might mean money). Argument is still the same, it's not out of the ordinary to comply with regulations and laws. It seems more like a cultural difference, whereby some one-man shops from US find privacy not important.

No there's no cultural difference (or perhaps there is, but it's not on display here). It's not out of the ordinary to comply with regulations and laws -- businesses often change to do so. However, it's also not out of the ordinary for businesses to go out of business due to legal situations. Both are signs of a functioning regulatory environment.

Re: GDPR: Removing Monal from the EU

#404

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

He is a 1 person team. Given him a break vs. being so aggressive in your comment. There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. All these things don't drop from the sky.

And they are a business. And as a business they have decided to get out of Europe as the above costs weren't worth it to them.

Re: GDPR: Removing Monal from the EU

#405
post #369

Earlier quoted context omitted.

It can be a privacy violation but the idea of a fundamental right to privacy is not universally supported like free speech. If it is a fundamental right, how far does it go? Should I be able to sue you for watching me walk in a public place? Photographing me? Video taping me? What about a privately owned but still public place? There are a lot of questions here that I think people tend to skip over about users owning…

There are lots of laws against following someone and observing/recording every move they make. Making some observations out your window of cars passing by is something no one ever had a problem with. Taking down every single identifier you could and coordinating with others to track that person, for a profit, is something that would not be kosher in meat space. Why this different just because it's on a computer?

Would any of that actually be illegal in "meat space" as long as it didn't qualify as harassment?

Re: GDPR: Removing Monal from the EU

#406

Earlier quoted context omitted.

GDPR does not require you to delete PII from backups. This is a misconception. You do need to have a documented and implemented backup retention policy and communicate this if you receive a request to delete a user's data.

There are other laws which require you to keep data for up to 10 years. This will require you to split up your backups and clean the ones for the longer storage from all unnecessary PII. That is already costly and challenging. Problem is nobody really knows what data you have to strip of and what do you have to retain for other laws.

You are talking about a very narrow set of legal reasons that need 10 years of archiving. This has nothing to do with the GDPR and these archives should really not be created from normal daily/... backups. If you fall into that category you need a lawyer even without the GDPR and this lawyer will tell you exactly what and how to archive. "Nobody really knows" does not apply here because your lawyer knows.

Re: GDPR: Removing Monal from the EU

#407

Earlier quoted context omitted.

From Wikipedia: > BetonSports plc is a British online gambling company founded by Gary Kaplan in 1995. The company was one of the biggest players in the United States online gaming market, drawing in several billion US dollars in wagers in the early 2000s.[1] In June 2006 US authorities indicted the company and a number of its executives on RICO, mail fraud, and tax evasion charges arising from its supplying online b…

While I agree that violating the GDPR is much less likely to result in being pulled off a plane than running a company that allows people to gasp gamble on the internet, your characterisation of the problem as 'federal crimes' seems to suggest that there was something much more nefarious going on than simply allowing people in another jurisdiction to do something over the internet that is completely legal in the juri…

I don't like government, but companies sucking up everyone's data for sale right now certainly seem like mustache twirlers to me.

Re: GDPR: Removing Monal from the EU

#408
post #380

Earlier quoted context omitted.

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

You can be fined if there is international or bilateral law or if somehow else the fine can be domesticated. There is no international regulation (not even consensus) on privacy so the law is not directly enforced here. However you are also not required to apply another country's law to all your customers, and if you don't want to you should (but are not really enforced to) block the EU.

Re: GDPR: Removing Monal from the EU

#409
post #355

Earlier quoted context omitted.

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some…

You have to respect the privacy of people in the same way you have to respect their lives. You can not harm or kill random people, you can not do arbitrary things with information about them.

It’s alarming that you don’t realize how insane this argument is. Now murder and keeping notes about someone you see in public are the same? You’re headed towards thought-crime with this; it’s basically murder to continue to hold an opinion of someone that they disapprove of, because “privacy”. Ridiculous.

Re: GDPR: Removing Monal from the EU

#410

Earlier quoted context omitted.

At that level it doesn't have to cost anything other than your time. And if it's not a business it is a hobby and those cost time (and usually also money). The GDPR is not going to cause any but the weakest businesses to close shop, in fact if the GDPR causes a business to close (which I highly doubt other than people voluntarily throwing in the towel because they can't be bothered) then I am not sure if I'm going to…

The comment I responded to cited environmental regulation. These are oftentimes costly to implement. All regulation costs money to implement. Even if each regulation by itself is cheap, these things add up -- it's death by a thousand cuts.

> These are oftentimes costly to implement.

Yes, but then again: if you don't implement them society as a whole will end up holding the bag. Polluter pays is a very good principle.

> All regulation costs money to implement.

Yes. But that's called the cost of doing business. And most software based businesses have insane margins anyway because of their ability to scale.

> Even if each regulation by itself is cheap, these things add up -- it's death by a thousand cuts.

That's one way of looking at it. Another way of looking at it is that it levels the playing field between those that ride roughshot over their users rights and those that try to be nice.

Post reply on HN