Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

491–500 of 957 posts

Re: GDPR: Removing Monal from the EU

#491

Earlier quoted context omitted.

That's not exactly a new insight, Richelieu beat you to that one a couple of centuries ago. But that's just trying to stretch what we are discussing here: that it is possible to comply with the law in principle. That some overzealous prosecutor with a grudge could nail you might happen - in Russia, maybe even the USA. But frankly where I live I have not yet seen a case like that. We probably have them but not frequen…

Not the point. You’re making the case that you’re always fully compliant with all laws and have been for 30 years, because it’s just so damn effortless. It’s almost more work to NOT be compliant!! And I’m saying that’s bullshit. You’re breaking laws left and right, but you just don’t get caught because enforcement of those laws is so inconsistent. And the GDPR is so much worse; I’m sure you’re not compliant with GDPR…

> You’re breaking laws left and right, but you just don’t get caught because enforcement of those laws is so inconsistent.

Well, you know my business better than I do I guess.

> And the GDPR is so much worse; I’m sure you’re not compliant with GDPR given how vague and over-reaching the law is, but you’re probably mostly compliant and you’re too small for anyone to care.

And my business is about 100x the size of the one of the person writing the article. And I'm not worried. So I see the article writer as someone who uses the opportunity to make a whole bunch of fuss over something that (1) most likely would never impact him and (2) has indicated clearly that despite his opening sentence he probably doesn't give a damn about his users privacy.

So as far as I can see the law is working as intended.

Re: GDPR: Removing Monal from the EU

#492

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

This is such a terrible argument. You’re essentially arguing that any business of any kind should never complain or choose not to do business in a jurisdiction if the reason is regulatory burden, no matter how onerous, expensive, ambiguous, and offensive that regulation is. That’s illogical and not the way that any business evaluates what activities to pursue or forgo. You’re casting aspersions on this one guy and im…

> if the reason is regulatory burden, no matter how onerous,

No, what we're saying is OP can't complain about the burden of this onerous regulation when the fact is that almost none of it is relevant to OP and he'll have to make only minor changes to be compliant.

Several of the claims OP made are flat wrong and it's trivial to show they're wrong by simple web searches.

Re: GDPR: Removing Monal from the EU

#493

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

There is signifiant disagreement to what extent Facebook and Google are compliant.

Re: GDPR: Removing Monal from the EU

#494
post #447

Earlier quoted context omitted.

Unlike your examples, GDPR bans neither messenger apps nor Monal in particular.

Indeed. And the prohibition on raw milk does not ban cheese. Many cheeses from France are still available, because they do not involve raw milk. The EU has passed a law, perhaps it is a worthwhile law. This is one of the consequences. The ban on raw milk in cheese making exists thanks to (presumably) the best intentions, and the end result is that there are many cheeses I would like to buy, that I cannot. An American…

Running further with a bad analogy doesn't make the analogy any better or more relevant to the GP comment.

Re: GDPR: Removing Monal from the EU

#495
post #473

Earlier quoted context omitted.

Well whoever took the picture is the one that holds the copyright usually so it's more or less that person's data. Pictures probably aren't a good example because they are covered by intellectual property laws.

Then let's move on to credit card details. You gave them to me for payment purposes in the course of doing normal business. Months later, I discover that I can sell my stock of credit card information on the darknet for some nice extra income. Should I be allowed to do that? What if it weren't credit card details but just postal addresses?

The credit card example was already illegal by other, more targeted legislation.

Nobody likes getting a lot of junk mail, but it's not the end of the world. I actually got my first credit card from a pre-approved offer found in junk mail.

Re: GDPR: Removing Monal from the EU

#497

Earlier quoted context omitted.

> extremely shallow interpretation of the GDPR Please elaborate. I was unable to perceive the legal depth of interpretation. > you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away Businesses limit liability and legal exposure all the time. It's a tradeoff, as all things are.

> Please elaborate. As you wish: > I frequent Europe and do not want to get into legal trouble on vacation. There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here). Worst case you would be warned to become compliant, then if you persist in not being compliant you might b…

re: DPO

i think you are being a bit naive and dismissive. the law could easily be interpreted as his endeavor requiring a Data Protection Officer. the guidelines (http://ec.europa.eu/newsroom/document.cfm?doc_id=44100) for the DPO require that processing "special categories of data" needs a DPO. those categories include tings as benign as "trade union membership."

so if his chat app has someone in the EU chatting about trade union membership while this chat service then "processes" that data, they might be held liable to the DPO requirement.

Re: GDPR: Removing Monal from the EU

#498

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Indeed, this did not drop out of the sky. It has been in the works for years. I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. My country's data protection agency made no attempt at raising awareness despite having my email address on file :-D It's only been frequently hitting non-EU industry news and places like HN since late 2017…

I'm probably a bit more in touch with this stuff than most because of the nature of my business but in the last year or so I've seen more and more companies that made real work of their GDPR impact studies (companies with vast amounts of data and/or sensitive data were further along). For all but the largest the impact has been very low, the longer ago they started the lower the amount of work they had to do.

That's the price of sitting in your office with your head down though, you can't ignore changes such as these.

This is one of the oldest HN mentions about the GDPR I could find:

https://news.ycombinator.com/item?id=11764073

But it sank without a trace.

Re: GDPR: Removing Monal from the EU

#499
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

I have a radical idea: don't keep that data.

You can still log accesses and aggregate them into statistics, just don't keep the IP addresses. You can still log IP addresses to detect DOS attacks or whatever, just delete the log when you don't need it anymore, after a day or so. There's no need to get backups from glacier, because you know there is no personal data in them.

Re: GDPR: Removing Monal from the EU

#500
post #494

Earlier quoted context omitted.

Indeed. And the prohibition on raw milk does not ban cheese. Many cheeses from France are still available, because they do not involve raw milk. The EU has passed a law, perhaps it is a worthwhile law. This is one of the consequences. The ban on raw milk in cheese making exists thanks to (presumably) the best intentions, and the end result is that there are many cheeses I would like to buy, that I cannot. An American…

Running further with a bad analogy doesn't make the analogy any better or more relevant to the GP comment.

Apologies, I genuinely don't understand this critique.
Post reply on HN