Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

441–450 of 957 posts

Re: GDPR: Removing Monal from the EU

#441

Earlier quoted context omitted.

Thanks for clearing that up - I can't stand people who think they are above the law. Here in France and Germany, this law is creating a lot of jobs too. I hope more laws like that in the future so that even more jobs can be created. I love the EU :-)

For jobs to be created (presumably in startups) , there must be startups first. Startups won't be started if you need to hire 1 full time accountant (for the VAT mess), 1 privacy person and 1 lawyer before you even lay down your idea. I get it that GDPR is creating some nice jobs these months, but it won't last long. I wonder if this guy would even make the app if he was in the EU today. I am all for fair taxation an…

You don't need a 'full time accountant' for the VAT mess, I've been doing this for years (decades) and it took about 2500 euros / year / company for the full administrative burden, including payroll for up to 25 employees.

You don't need a privacy person either (I suspect you mean DPO), but you do need to know what you are doing.

> I am all for fair taxation and privacy, but the EU should start creating the mechanisms that make it easy and automatic for startups to comply with stringent requirements instead of leaving the burden upon them.

That I agree with, it can still be better. But VAT/MOSS took the sting out of the VAT reporting and the privacy law is entering a shake out period now and will also end up to be manageable.

Re: GDPR: Removing Monal from the EU

#442

Earlier quoted context omitted.

> I guarantee you that I've been compliant with the laws as much as I'm aware of them. All the laws, worldwide? Are you in compliance with anti-blasphemy laws? Laws that forbid insulting the monarch? The tax regime of every country in the world? The creator of Monal has decided the easiest way to be compliant with another country's laws is simply not to do business there, and I think you're underestimating the diffic…

Any laws that have the potential to reach me I am compliant with. If there are countries with laws that strike me as idiotic - such as anti-blasphemy laws - then I will do my level best to be informed of that beforehand and I will not break that law even if I feel that it is idiotic. And as for the 'don't insult the monarch' law, we have that law here in NL and I purposefully broke it as a private individual to make…

You're right, there was never a business behind this. It's free software.

Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

Re: GDPR: Removing Monal from the EU

#443
post #8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

What do you imagine that fixed cost to be? Delete your logs and don't, you know, make an entire business out of misrepresenting your revenue model and you're most of the way there.

Any business that is shut down by GDPR is, to me, a good business to shut down.

Re: GDPR: Removing Monal from the EU

#444

Earlier quoted context omitted.

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

It is reasonable to assume overreach by governing bodies will occur; this is no less true for the EU than for any national government. The EU is no less likely to misuse that hammer, intentionally or not.

Actually DPAs are national. So there is one for each state, not a "central" one for the whole EU.

Re: GDPR: Removing Monal from the EU

#445
post #388

Earlier quoted context omitted.

Please don't just say this is a US perspective. This is a sociopaths perspective that the current US legal system promotes due to the machinations of the same group of sociopaths. Every business owner here who would complain about how the GPDR is taking their rights to their personally earned data away would be the same people who launch a lawsuit because one of their competitior's products had a typeface that was va…

Targeted ads hardly qualify as abuse to me. Getting to use a website for free in exchange for your browsing data being analyzed is a great deal and a win/win for everybody. Surely anyone who disagrees with your feelings on this matter must be a sociopath, though.

It's not just targeted ads. We see a new data breaches every week that leaks customer data and is used in identity theft that causes actual, quantifiable damages to users. The entire internet, and increasingly physical goods in our homes, has become the equivalent of a ghetto where every single person has to have bars on their doors and look over their shoulders constantly to avoid having shit stolen from them or their privacy violated.

The GDPR didn't arise out of some feeling that companies we're making too much money. It arose out of the fact that the industry refused to self regulate. They were given years to do this and the standard operating procedure for security around data right now is to lol because who cares if you have a breach, that's a problem for the people you harvested data from, not you.

The bad side effects from this data harvesting are called negative externalities. A similar set of negative externalities is pollution.

Do you think it's immoral for regulations to make certain business model that rely on dumping poison into the water or air unprofitable, just because those companies could have made some money if only they could do what they liked regardless of the harm to others?

Re: GDPR: Removing Monal from the EU

#446

Earlier quoted context omitted.

I'm not actually sure he is running this as a business? It seems open source? He even suggests people download and build their own? So all he's done is save himself the time and effort of dealing with the GDPR and cost himself nothing.

The fact that it is open source does not mean it isn't a business. And yes, he has saved himself the time and the effort of dealing with the GDPR, has also managed to position himself as someone who pays lipservice to privacy but who does not care to actually be compliant with privacy legislation when it matters. I wouldn't want my data in his hands after that anyway (not that that would ever happen because I don't h…

From my POV, he definitely positioned himself as someone that doesn't give a damn about user privacy

Re: GDPR: Removing Monal from the EU

#447

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Unlike your examples, GDPR bans neither messenger apps nor Monal in particular.

Re: GDPR: Removing Monal from the EU

#448

Earlier quoted context omitted.

Targeted ads hardly qualify as abuse to me. Getting to use a website for free in exchange for your browsing data being analyzed is a great deal and a win/win for everybody. Surely anyone who disagrees with your feelings on this matter must be a sociopath, though.

"Getting to use a website for free in exchange for your browsing data being analyzed is a great deal and a win/win for everybody." Which is why you are perfectly capable of giving consent to other websites to do that. "Surely anyone who disagrees with your feelings on this matter must be a sociopath, though." No, just those who insist on a "take it or leave it" approach.

You're not allowed to "degrade the service" or allow access contingent on consent to targeted ads/tracking, so the practice isn't going to be sustainable for websites when only a tiny percentage of users give consent, seeing how they get to use the site one way or the other - have their cake and eat it too.

Re: GDPR: Removing Monal from the EU

#449

Earlier quoted context omitted.

The GDPR faq disagrees: https://www.eugdpr.org/gdpr-faqs.html

It doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.

Hello, not a lawyer, but mine said you're wrong.

You might be thinking of this pseudonymization stuff. My advice is not to play with it. Just delete your logs after a month unless you have a demonstrable and immediate security need for them.

Re: GDPR: Removing Monal from the EU

#450

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

did that $250 include an audit to verify that you are actually in compliance?
Post reply on HN