Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

501–510 of 957 posts

Re: GDPR: Removing Monal from the EU

#501

Earlier quoted context omitted.

Not the point. You’re making the case that you’re always fully compliant with all laws and have been for 30 years, because it’s just so damn effortless. It’s almost more work to NOT be compliant!! And I’m saying that’s bullshit. You’re breaking laws left and right, but you just don’t get caught because enforcement of those laws is so inconsistent. And the GDPR is so much worse; I’m sure you’re not compliant with GDPR…

> You’re breaking laws left and right, but you just don’t get caught because enforcement of those laws is so inconsistent. Well, you know my business better than I do I guess. > And the GDPR is so much worse; I’m sure you’re not compliant with GDPR given how vague and over-reaching the law is, but you’re probably mostly compliant and you’re too small for anyone to care. And my business is about 100x the size of the o…

[deleted]

Re: GDPR: Removing Monal from the EU

#502
post #465

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

The OP is not the site owner. The decision to exclude a portion of your user community should be explained. Unless you personally know the developer you are making a number of assumptions about their resources and time to deal with this issue. Presumably the developer wants to continue to offer this app and service. His understanding of GDPR and how it affects his service will grow over time and he will likely eventu…

> His understanding of GDPR and how it affects his service will grow over time and he will likely eventually take action to reintegrate the EU into his service.

Unless you personally know the developer you are making a number of assumptions about their resources and time to deal with this issue.

Re: GDPR: Removing Monal from the EU

#503

Earlier quoted context omitted.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

did that $250 include an audit to verify that you are actually in compliance?

There is no such thing as a GDPR audit.

Anybody that tries to sell you one is full of it.

Re: GDPR: Removing Monal from the EU

#504
post #456

Earlier quoted context omitted.

The rate of high-quality content being added to the internet has surely been on the increase as the adoption of the web increased, even if the likes of clickbait and spam grew faster, shifting the "average" quality down.

I don't agree with that at all. In the 2000s I frequently could find new and useful websites for learning on every Google search. Now I have to wade through hundreds of sites that only host clickbait or repackage other sites content so they can deliver ads that end up containing malware. The internet has given me a commodity in the form of constant good data that is unequivocally an improvement, but the signal to noi…

I'm not seeing exactly where you disagree there. There's more bad information now, and a higher ratio of bad to good, but I'm saying despite that, there's still more good than there used to be, and probably a higher rate of good being added.

For example, with small numbers for the argument's sake, say in 2000 there were 5 good webpages and 4 bad webpages added to the internet every day. Now there are 10 good webpages and 50 bad webpages added every day. That would mean we're getting more good information per day than before, but the signal to noise ratio has gotten worse, as you said.

Re: GDPR: Removing Monal from the EU

#505
post #492

Earlier quoted context omitted.

This is such a terrible argument. You’re essentially arguing that any business of any kind should never complain or choose not to do business in a jurisdiction if the reason is regulatory burden, no matter how onerous, expensive, ambiguous, and offensive that regulation is. That’s illogical and not the way that any business evaluates what activities to pursue or forgo. You’re casting aspersions on this one guy and im…

> if the reason is regulatory burden, no matter how onerous, No, what we're saying is OP can't complain about the burden of this onerous regulation when the fact is that almost none of it is relevant to OP and he'll have to make only minor changes to be compliant. Several of the claims OP made are flat wrong and it's trivial to show they're wrong by simple web searches.

There are hundreds of comments here on this thread arguing about all of those points and what the law even says. The GDPR is a complete joke.

Re: GDPR: Removing Monal from the EU

#506

Earlier quoted context omitted.

Any laws that have the potential to reach me I am compliant with. If there are countries with laws that strike me as idiotic - such as anti-blasphemy laws - then I will do my level best to be informed of that beforehand and I will not break that law even if I feel that it is idiotic. And as for the 'don't insult the monarch' law, we have that law here in NL and I purposefully broke it as a private individual to make…

You're right, there was never a business behind this. It's free software. Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

Because even free software has to comply with the law. Funny how that works, but not making a profit on something does not absolve you from legal liability.

Re: GDPR: Removing Monal from the EU

#507

Earlier quoted context omitted.

> Please elaborate. As you wish: > I frequent Europe and do not want to get into legal trouble on vacation. There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here). Worst case you would be warned to become compliant, then if you persist in not being compliant you might b…

re: DPO i think you are being a bit naive and dismissive. the law could easily be interpreted as his endeavor requiring a Data Protection Officer. the guidelines ( http://ec.europa.eu/newsroom/document.cfm?doc_id=44100 ) for the DPO require that processing "special categories of data" needs a DPO. those categories include tings as benign as "trade union membership." so if his chat app has someone in the EU chatting a…

Bigger than the DPO issue for processing Article 9 special data is the fact that processing Article 9 special data is generally prohibited outside of enumerated exceptions.

Re: GDPR: Removing Monal from the EU

#508

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Re: GDPR: Removing Monal from the EU

#509

Earlier quoted context omitted.

The indicators are a tiny subset of the actual requirements involved in a production vehicle. In fact, there are examples of European production cars that can't be street legal in the US, and the companies involved chose to simply not sell them here. Smart cars were impacted by this for awhile (no crumple zones), they eventually dealt with the problem though, and as I recall there was a production ferrari that couldn…

It was a Porsche, and Bill Gates owned one. "While most Porsches can import quite easily from Europe to the USA, the 959 had complications abound, making it impossible for US citizens to get their hands on one of these supercars. One of the citizens was Gates, who ordered a 959 from Porsche, only to have it impounded at customs. The reasoning provided to justify the impounding was that the 959 had not yet cleared cra…

Ah yes! That's the one. And he owned it but could never drive it on public roads. Thanks very much.

Re: GDPR: Removing Monal from the EU

#510

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Indeed, this did not drop out of the sky. It has been in the works for years. I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. My country's data protection agency made no attempt at raising awareness despite having my email address on file :-D It's only been frequently hitting non-EU industry news and places like HN since late 2017…

I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017.

Likewise. This idea that the GDPR has been in the works for years so it's somehow implausible that very small businesses have only just heard of it doesn't stand up to scrutiny. No owner-run microbusiness is spending the time necessary to keep up with the vagaries of EU debates.

Similarly, the idea that the GDPR is plainly readable and so that shouldn't be a burden and no-one needs to consult experts makes no sense. The document is many pages long, there are many more pages of guidance and interpretation produced by both the EU itself and the various national regulators, and it's still fundamentally ambiguous on many significant practical points.

It is entirely reasonable for a small business that does relatively little trade with the EU not to want anything to do with this, and it has little if anything to do with how good or bad their practical data protection measures and respect for privacy are. If small businesses are overreacting then that is on the EU for failing to pass better law and provide sufficiently clear, concise and timely publicity and guidance on what it really means.

My business interests are in the UK, so we're stuck with this one. However, if we'd realised ahead of time how much trouble the new EU VAT rules would cause a few years back, we would gladly have sacrificed the modest part of our revenue that comes from other EU member states in order to avoid that mess, and it wouldn't have been a close decision. So I find it very hard to criticise anyone running a small business outside the EU for wanting to avoid the latest round of heavyweight EU regulations if they have a way to put themselves outside of their scope.

Post reply on HN