Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

461–470 of 957 posts

Re: GDPR: Removing Monal from the EU

#461
post #447

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Unlike your examples, GDPR bans neither messenger apps nor Monal in particular.

Indeed. And the prohibition on raw milk does not ban cheese. Many cheeses from France are still available, because they do not involve raw milk. The EU has passed a law, perhaps it is a worthwhile law. This is one of the consequences. The ban on raw milk in cheese making exists thanks to (presumably) the best intentions, and the end result is that there are many cheeses I would like to buy, that I cannot. An American (unlike me) who supports such a ban rejoices in the fact that we are protected from these dangerous french cheeses. Perhaps you rejoice that you are protected from the dangerous GDPR non-compliant Monal.

Re: GDPR: Removing Monal from the EU

#462

Earlier quoted context omitted.

> [Complying] with the law is stupidly easy: know the law. You're out of touch. Compliance just isn't as simple as you think it is no matter how much you double down in these comments. Laws aren't black and white. Do you not use an accountant, either? Frankly, your advice is terrible.

Incredibly out of touch. I can virtually guarantee that a regulator or prosecutor who wanted to make an example of him could tear his business apart finding violations over 30+ years.

That's not exactly a new insight, Richelieu beat you to that one a couple of centuries ago.

But that's just trying to stretch what we are discussing here: that it is possible to comply with the law in principle. That some overzealous prosecutor with a grudge could nail you might happen - in Russia, maybe even the USA. But frankly where I live I have not yet seen a case like that. We probably have them but not frequently enough to make the news and in general the legal system here works quite well.

Re: GDPR: Removing Monal from the EU

#463

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Bovril could easily comply. They would simply have to open a manufacturing facility that did not use UK beef. The French cheese makers could sort of comply, by pasteurizing their milk. Kinder, I admit, has a more difficult problem, and has, in fact attempted to comply, by creating a completely different product with the same name.

Re: GDPR: Removing Monal from the EU

#464
post #380

Earlier quoted context omitted.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

You can be fined if there is international or bilateral law or if somehow else the fine can be domesticated. There is no international regulation (not even consensus) on privacy so the law is not directly enforced here. However you are also not required to apply another country's law to all your customers, and if you don't want to you should (but are not really enforced to) block the EU.

Considering that most online businesses are (effectively) a form of international trade, I wonder whether GDPR fines could be seen as a form of customs fine (which definitely is something that foreign companies can be forced to pay, as you've said).

Re: GDPR: Removing Monal from the EU

#465

Earlier quoted context omitted.

He is a 1 person team. Given him a break vs. being so aggressive in your comment. There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. All these things don't drop from the sky. And they are a business. And as a business they have decided to get out of Europe as th…

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

The OP is not the site owner.

The decision to exclude a portion of your user community should be explained.

Unless you personally know the developer you are making a number of assumptions about their resources and time to deal with this issue.

Presumably the developer wants to continue to offer this app and service. His understanding of GDPR and how it affects his service will grow over time and he will likely eventually take action to reintegrate the EU into his service.

Re: GDPR: Removing Monal from the EU

#466

Earlier quoted context omitted.

Well, the "appropriate indicators" would need to meet the "required standards" mentioned in the parent post. I think the example is ok.

The indicators are a tiny subset of the actual requirements involved in a production vehicle. In fact, there are examples of European production cars that can't be street legal in the US, and the companies involved chose to simply not sell them here. Smart cars were impacted by this for awhile (no crumple zones), they eventually dealt with the problem though, and as I recall there was a production ferrari that couldn…

It was a Porsche, and Bill Gates owned one.

"While most Porsches can import quite easily from Europe to the USA, the 959 had complications abound, making it impossible for US citizens to get their hands on one of these supercars. One of the citizens was Gates, who ordered a 959 from Porsche, only to have it impounded at customs. The reasoning provided to justify the impounding was that the 959 had not yet cleared crash-testing requirements and did not meet EPA standards. Gates’ German supercar sat idly by for over a decade."

https://blog.dupontregistry.com/celebrity-cars/bill-gates-am...

Re: GDPR: Removing Monal from the EU

#467
post #380

Earlier quoted context omitted.

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

> and I don't see why "it's on the internet" appears to be the main counter-argument.

Because by default any web site has, in the past, been open to people from any country that doesn't censor the web.

Regulations like GDPR are making doing business in more than one country more difficult and encouraging a Balkanized web.

Re: GDPR: Removing Monal from the EU

#468

Earlier quoted context omitted.

You have to respect the privacy of people in the same way you have to respect their lives. You can not harm or kill random people, you can not do arbitrary things with information about them.

It’s alarming that you don’t realize how insane this argument is. Now murder and keeping notes about someone you see in public are the same? You’re headed towards thought-crime with this; it’s basically murder to continue to hold an opinion of someone that they disapprove of, because “privacy”. Ridiculous.

Of course they are not the same but they share a common principle, i.e. you can not do arbitrary things involving other people. And nobody is talking about your opinions, you are free to think whatever you want, just as you are free to harm yourself or even commit suicide. But if your »thinking« involves information about other people, there are limits just as there are limits if you go from killing you to killing others. If something is ridiculous, then the way you twisted what I said.

Re: GDPR: Removing Monal from the EU

#469

Earlier quoted context omitted.

The GDPR faq disagrees: https://www.eugdpr.org/gdpr-faqs.html

It doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.

I can't see any way in which this interpretation can be valid. You'll always be able to "directly or indirectly" identify people from IP addresses. Just because I don't store IP and identity together, doesn't mean there's not many other ways to identify somebody based on an IP address.

Re: GDPR: Removing Monal from the EU

#470

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

DPO has been thoroughly refuted in this thread. He doesn't need a DPO; if he wants to hire a DPO that can be him.
Post reply on HN