Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

451–460 of 957 posts

Re: GDPR: Removing Monal from the EU

#451

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibilities - amount to exorbitant damage claims.

Similar arguments apply to the other examples you use, I see your point and there are valid reasons to not enter a certain market because of the legal climate there but the point I am trying to make is that the OP has not raise any valid point at all other than 'I don't want to comply'. And that's fine by me but then don't bother dressing it up in a bunch of made up requirements.

Re: GDPR: Removing Monal from the EU

#452

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

I have, just not in this comment. See elsewhere in this thread, it's hard to miss.

Re: GDPR: Removing Monal from the EU

#453
post #370

Earlier quoted context omitted.

CNIL is one of ~20 regulatory agencies & this isn’t their “official” stance. Other opinions have concluded that you must keep an index of requested deletes in the face of backups, for instance.

I don't see the problem here (for small companies). If you have a database with user data, and a user deletes his account, you delete the data from production. At this moment, you have a live system without this users data, and some backups with the data. The moment you make a new backup, you have a dataset to restore from that does not include the user data. You keep daily backups for 1 week, and after one week the…

You have a very narrow view about what backups are used for. Which is fine for your business, but for many others, the backups are important business records. What if an employee is stealing from the company, and does it for longer than the time that your business keeps backups? You might say "oh but I keep logs", in which case you have the same problem with keeping the logs that you think you dodged by not keeping the backups.

Re: GDPR: Removing Monal from the EU

#454
post #8

Earlier quoted context omitted.

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

What do you imagine that fixed cost to be? Delete your logs and don't, you know, make an entire business out of misrepresenting your revenue model and you're most of the way there. Any business that is shut down by GDPR is, to me, a good business to shut down.

> What do you imagine that fixed cost to be?

Compliance. It doesn't matter if you delete your logs, if you had them in the first place you're subject to compliance.

Like the example in the article. Not sure why people are still thinking this doesn't happen, this is exactly what is happening in the article.

Re: GDPR: Removing Monal from the EU

#455
post #63

Earlier quoted context omitted.

Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...

UK is not the only country that can sue you under GDPR. What if Bulgaria decides 20 million sound pretty good?

It's very unlikely the EU as a whole will tolerate spurious GDPR lawsuits. They're quite aware that this has made many companies nervous.

Re: GDPR: Removing Monal from the EU

#456
post #379

Earlier quoted context omitted.

Is the internet even a net benefit with this current trend towards turning everything into clickbait or some other psychological experiment to get traffic and harvest data off of it? How useful is the average website now compared to what the internet was like in the 2000's? Even if it would all be a net benefit, why is it ok for all of these companies to be so misleading about it. No one out a simple EULA, for what i…

The rate of high-quality content being added to the internet has surely been on the increase as the adoption of the web increased, even if the likes of clickbait and spam grew faster, shifting the "average" quality down.

I don't agree with that at all. In the 2000s I frequently could find new and useful websites for learning on every Google search. Now I have to wade through hundreds of sites that only host clickbait or repackage other sites content so they can deliver ads that end up containing malware. The internet has given me a commodity in the form of constant good data that is unequivocally an improvement, but the signal to noise ratio on the web has gotten worse every year

Re: GDPR: Removing Monal from the EU

#457

Earlier quoted context omitted.

> you can make your case What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.

"What if you don't want to deal with any of that." What if you don't want to deal with the rules of the road?

There is a big cost to regulating the internet and we know that. If the internet was regulated in the 90s we 'd still be watching Teletext.

Re: GDPR: Removing Monal from the EU

#458

Earlier quoted context omitted.

Perhaps this isn't obvious to everyone, but other people are actually not obligated to spend their time doing things you want them to.

That's the law in the EU, I think it's natural to have a hobby that doesn't break any laws.

He's not in the EU.

Re: GDPR: Removing Monal from the EU

#459
post #369

Earlier quoted context omitted.

There are lots of laws against following someone and observing/recording every move they make. Making some observations out your window of cars passing by is something no one ever had a problem with. Taking down every single identifier you could and coordinating with others to track that person, for a profit, is something that would not be kosher in meat space. Why this different just because it's on a computer?

Would any of that actually be illegal in "meat space" as long as it didn't qualify as harassment?

Would any data collection on the "internet" actually be illegal as long as it didn't qualify as illegal data collection?

That's the whole point of the law is to say it's illegal, the same way laws made stalking people illegal

Re: GDPR: Removing Monal from the EU

#460

Earlier quoted context omitted.

He is a 1 person team. Given him a break vs. being so aggressive in your comment. There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. All these things don't drop from the sky. And they are a business. And as a business they have decided to get out of Europe as th…

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Indeed, this did not drop out of the sky. It has been in the works for years.

I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. My country's data protection agency made no attempt at raising awareness despite having my email address on file :-D It's only been frequently hitting non-EU industry news and places like HN since late 2017 so I can appreciate how non-EU folks might feel blindsided by it.

Post reply on HN