Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

471–480 of 957 posts

Re: GDPR: Removing Monal from the EU

#471
post #382
post #355

Earlier quoted context omitted.

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some…

>I wouldn't give away my personal observations stemming from something I did publicly and for free. No, you'll just sell it to the highest bidder. And enough people do this in such an underhanded way that the EU decides to regulate the shit out of you. So maybe you should have asked permission before recording identifiable people's behavior or otherwise earned their trust. Instead of being shady and myopic about it.

Maybe he should have asked for permission before looking to identifiable people also?

Re: GDPR: Removing Monal from the EU

#472

Earlier quoted context omitted.

If you're Zuck or anyone working for FB, that'd be true. But what if one of my interests in running my company is the protection of my users' data?

Can you imagine yourself trying to convince a regulator of that?

Like Zuck before senate?

I imagine when running a business one faces many stupid bureaucrats, this could be another one (or they could be competent and understand and accept the technical explanation of how my imaginary company complies with GDPR).

But yeah, why quit because of the n + 1th bureaucrat, when you've dealt with n of them while starting and running of your business?

Re: GDPR: Removing Monal from the EU

#473
post #225

Earlier quoted context omitted.

If I get nude picutures of you, or your mother, daughter etc. is it then "my data"? Am I therefore allowed to do with that data as I wish? I think most people agree that unless those pictures are gathered with very specific consent, subject to many restrictions, they are not "my data". This is obviously an extreme example, but the reasoning extends to more data that is considered sensitive. The point being that "data…

Well whoever took the picture is the one that holds the copyright usually so it's more or less that person's data. Pictures probably aren't a good example because they are covered by intellectual property laws.

Then let's move on to credit card details. You gave them to me for payment purposes in the course of doing normal business.

Months later, I discover that I can sell my stock of credit card information on the darknet for some nice extra income.

Should I be allowed to do that? What if it weren't credit card details but just postal addresses?

Re: GDPR: Removing Monal from the EU

#474
I think the part about rather big enforcement penalties made it easy for various consultants to scare companies and sadly also some individual developers.

I already had to fend off implementing some ridiculous features. I've pushed against misconceptions and use of non-existent terminology that's not even in the law. People are taking info from all kinds of sources, some of them sketchier than others, despite the existence of official EU guides, and the law itself.

But I bet it will be easy to comply for most non-adtech/tracking businesses. And as an internet user, I'm looking forward to better data exports, data removal and more transparency.

Re: GDPR: Removing Monal from the EU

#475
post #219

Earlier quoted context omitted.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

As a webmaster, I have an absolute right to carve '192.0.2.7 requested /foo.html from me' into stone and store it for posterity. The GDPR prohibits me from doing that, and in fact requires that I have the ability to rewrite history by removing that fact if the user who had 192.0.2.7 ever requests it. Some people, on hearing this, say, 'well, that's fine, you can just store 192.0.2 or 192.0 instead.' That seems pretty…

I also would prefer more clarity in the area of logging IP addresses, and would like to have a clearer consensus on what is allowed here. I think we will get a clearer picture after a bit of time.

It appears to me that as long as you don't use the logs for nefarious purposes you'd at least have legitimate interest in processing them (including the IP addresses), and so could keep them. This is the stance I am taking with respect to my personal webserver (together with a time limit after which logs are deleted); if a regulatory body informs me to change my approach, I'll gladly adapt.

Note also that IP addresses can be personal data, but do not have to be. Most claims here seem to relate to a ruling, where the IP address was deemed personal data in the hands of an ISP, who would be able to resolve it to a real person [1]. If you hold an IP address, but can't connect it to a real person (e.g. by having legal means to convince the ISP to give you that name based on the address), then it seems the IP address would not even be personal data in the first place. In the particularly ruling, the operator of the webserver was the German government, which presumably has more legal power to make an ISP turn over identifying data on a customer than a random website would have.

In any case, I hope some more clarity about this will emerge soon. But what you are talking about here would at best be a borderline infraction (and probably just be covered under legitimate interest). OTOH, what the person starting this thread had in mind seems to be that all the data he might collect on his users is fair game to do with as he pleases.

[1] https://www.whitecase.com/publications/alert/court-confirms-...

Re: GDPR: Removing Monal from the EU

#476
post #332

Earlier quoted context omitted.

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

> A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US Such a car cannot be driven on the road within The Netherlands without it being validated as safe (plus some other inspections). For US, same seems to apply. Per https://www.dmv.org/car-registration.php it mentions: "Pass a vehicle safety inspection.". So again you need to deal with paperwork and read what those safety…

Dmv.org is not associated with any government body. Its advice should be taken with a grain of salt as such matters are not uniform across the US. Moreover their state specific info is often a paraphrased summary that only represents best practices and not the full scope of the applicable law.

Re: GDPR: Removing Monal from the EU

#477
post #295

Earlier quoted context omitted.

"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.

You have pointed me to the entire content of the GDPR. It's 11 chapters, with 99 articles. I'm unashamed to admit that I don't consider even skimming such a document "easy". I was imagining something more along the lines of a one pager with 4-8 bullet points, each of which was easy to address.

Should add to that that the law (which is generally abstract) will be interpreted by 28 different legal systems. EU legal system is not homogeneous and there are definitely different sensitivities between countries (e.g. Germans seem very happy about GDPR - the Poles less so). That's an extra risk factor imho.

Re: GDPR: Removing Monal from the EU

#478

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

[deleted]

Re: GDPR: Removing Monal from the EU

#479

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is an amusing example, since they decided to offer a compliant variant of their product in the US.

https://www.today.com/food/kinder-joy-chocolate-eggs-are-com...

Re: GDPR: Removing Monal from the EU

#480

Earlier quoted context omitted.

> For small businesses it’s practically impossible to be in compliance for all laws. I've been in continuous operation with my businesses since 1986 and I guarantee you that I've been compliant with the laws as much as I'm aware of them. The major transgressions involving business assets were parking tickets, speeding tickets ( Running a small business in a way that is compliant with the law is stupidly easy: know th…

That is the OPs exact point. Did you read the article? He mentioned that "The days of someone making something, putting it on the internet and offering it to the world seem to be over". And here you are talking about knowing the laws while the OP sits in a different country trying to run his business. You might be from Europe and to you it may just seem sensible but 1-5 person companies often have to make tradeoffs l…

But OP is wrong. OP is saying GDPR is making it impossible for him to offer the software, but GDPR has almost no effect on him.

OP can just rely on "legitimate interests", and describe the data they're processing and why.

Post reply on HN