Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

531–540 of 957 posts

Re: GDPR: Removing Monal from the EU

#531
A "society" is all about building up information about the people around you and knowing about them. Complete anonymity often leads to the breaking down of people filters and behaviours, they think they can do whatever they want without consequences.

Many countries outlaw face coverings as they imply correlation with lawlessness.

The direct linking of IP address as PII flies in the face of that. If I am logging IP addresses for security and to monitor against abuse, and I in fact determine that an IP address is abusive, it behooves me to have any/all data that ip address used in my system to try to identify them.

The right to be forgotten .. why just online? Why just digital?

What if a shop owner or waiter in small town notes which customer like what, or what client tips well. Which local has annoying kids that she lets wander an vandalize the store.

If that owner/waiter writes that down in a log, and shares with co-worker on next shift ... is that in violation. What if they don't write it down and just have a really good memory ... what if they just 'organically' get a reputation and word gets around.

Is old wives gossip illegal under GDPR , or the "sterotypical" Italians mothers who keep an eye out on all the kids in street and report to each other who is doing what.

Plenty of stores and bars will have a list "don't take personal checks from these people" ... are those types of lists not allowed anymore?

If the GDPR was JUST limited to "customers" or people who have explicitly created accounts that might be one thing, but over reaching to say ANY apache webserver that automatically logs IP addresses had to be GDPR compliant is absurd.

If I post a tech blog with how-tos , personal ramblings, or even example code projects I release as open source that you are completely free to use or not use ... why do I have now have some obligation to you? You chose to walk up to my storefront and look inside ... I'm free to remember whatever I want about you while you looked around.

The US passed pretty broad overreaching Computer Fraud and Abuse Act [https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act] that many have argued is so broad that a violation of TOS could be considered abuse/hacking. If you view my site without agreeing to my TOS, should I be able to have you prosecuted?

Re: GDPR: Removing Monal from the EU

#532

Earlier quoted context omitted.

Wow. There you go again! So if my thinking involves someone else’s information, they have some right to make me change my thinking or punish me if I don’t??

First, you switched from respecting peoples' privacy to taking notes, thinking, and having opinions. I even responded to your comment before you added the notebook in the park example. You probably also noticed that I put »thinking« in quotes. Anyway, it is not the act of having the information about other people that is problematic, it is the act of collecting, using, or sharing it. Do you think I should be able to…

I didn’t write the original comment about the notebook in the park, just FYI.

And your examples are not all the same. If you’re in public, you have no reasonable expectation of privacy. So yeah, take all the notes about me you want. That’s entirely different from my doctor sharing my health info.

Re: GDPR: Removing Monal from the EU

#533
> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.

Lots of people are responding to the DPO side of this sentence, saying that it's not as onerous as the author of this article is making it sound, but as someone who's also not based in the EU it's the "EU Representative" part that I'm more worried about myself.

Article 27 says:

> (1) Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

Article 3(2) is the bit that says the GDPR applies to processing outside the EU of EU citizens' data etc.

> (2) The obligation laid down in paragraph 1 of this Article shall not apply to: > a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or > b) a public authority or body.

It's clear here that not everyone outside the EU needs to have an EU representative, but 2a is wordy and confusing enough that it's real hard for a non-EU non-lawyer to figure out with certainty whether or not they need one. The ambiguous combination of 'and's and 'or's don't help, but 'unlikely to result in a risk to the rights and freedoms of natural persons' sounds like something that's ambiguous enough on its own that you might need an EU lawyer to actually interpret it.

Re: GDPR: Removing Monal from the EU

#534

Earlier quoted context omitted.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

We have spent 3 months and aren't done yet. I would love to know your secret.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using consent lawful basis, you need to get consent in an opt-in manner. You need to record what statement you have shown to the user and any consent that you receive.

If you are using only contract basis for the data it's really easy. You tell them that you are using their data for purposes of fulfilling the contract. The great thing about contract basis is they can't object. The only thing you need to do is to inform the customer of any 3rd parties you send their information to in order to fulfil the contract.

It only gets complicated if you want to use the data for other things. For legitimate interest (which is essentially exactly the same as the laws that are currently on the books) you need to be able to exclude processing the data if someone objects. You also need to make sure that you don't delete their data if they exercise their right of removal (which is completely bass-ackwards, but whatever). Consent is similar actually, but you have to get the consent up front. The other lawful bases are very unlikely to show up in most organisations.

I think the main problem with most organisations (and it's the case with the company I work for at the moment) is that control of private information is very loose. For example, we use several SaaS systems for our marketing. Some of them are clearly unnecessary and so we either have to remove that functionality or get consent. So there's lots of discussions about whether it is worth a huge wad of text thrown at the user in order to have cat emoji's or some stupid thing like that.

The other main problem is that if you want to use something other than contract basis, you need to build something that allows the user to exercise their rights. It can be a manual process, but if you have a lot of users it might threaten the margin.

Anyway, long story short: If you are only gathering the information that you need to do the work you are doing, there is likely very little (or in a lot of cases I bet nothing) to do. If you are gathering the information to use for your own purposes, then there may be a lot that you need to do.

Not to put too fine a point on that, personally I highly approve of this. I really could care less if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job. Even in the company I work for, where we don't actually use the data for nefarious purposes (AFAICT ;-) ), we're finally having some long overdue conversations about what stupid SaaS crap we're using under the hood. Not to be unkind, but I utterly fail to understand how marketing people fall for the same lies that they spew out themselves... "If only we send our customer's data to this service, they will find a way to drive more business our way! And we don't even have to pay them!" Yeah... right...

Re: GDPR: Removing Monal from the EU

#535

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

> For small businesses it’s practically impossible to be in compliance for all laws. I've been in continuous operation with my businesses since 1986 and I guarantee you that I've been compliant with the laws as much as I'm aware of them. The major transgressions involving business assets were parking tickets, speeding tickets ( Running a small business in a way that is compliant with the law is stupidly easy: know th…

Running a small business in a way that is compliant with the law is stupidly easy: know the law.

There are professionals who spend their entire careers just "knowing" very specific parts of the law, and who are still frequently found to have misinterpreted it when tested in court.

Is doing your company's annual financial returns also stupidly easy, because you just have to know accountancy?

What about security? Just write all the software you use yourself based on your expert knowledge of cracking and cryptography?

Incidentally: not knowing you are breaking a law is no excuse for breaking the law, ignorance is not a valid defense.

This is possibly the greatest conceit in the history of legal systems. No human being in any Western nation could even read every word of law that applies to them in an entire lifetime, never mind fully understand the implications and the motivations behind those words that might be relevant to interpretation. Ignorance may not be a legal defence, but not being magically aware of the sum of all human knowledge about every legal system that you interact with is certainly a reasonable excuse for doing something illegal but otherwise apparently ethical and sensible.

Re: GDPR: Removing Monal from the EU

#536
If this is the sort of enforcement we can expect, this could suck: https://ico.org.uk/action-weve-taken/enforcement/sse-energy-... (there are several others, this one is just interesting because it's a very simple mistake with very minimal PII)

Also, my understanding is Germany allows for whistle-blowers to take a cut of fines. Language in the GDPR calls for over-estimating damages for loss of PII when compensating individuals as well.

Generally, I appreciate the GDPR. That said, it's a huge burden trying to go through many dozens of workflows, technical or otherwise, where (typically minimal) PII is recorded, catalog them, limit (and purge) intake of data to bare minimums, create documentation supporting said workflows to be able to provide the SA's, create a plan for being able to search ALL those workflows/databases/spreadsheets/apps that have PII to supply that data upon request, and then be able to delete all cases of such data upon request.

Turns out that's actually a mountain of work. It will probably force us to significantly improve workflows and combine data repositories moving forward but it's a large burden up front. Likely many hundreds, if not thousands, of hours for our fairly small enterprise.

Re: GDPR: Removing Monal from the EU

#537

Earlier quoted context omitted.

There is no such thing as a GDPR audit. Anybody that tries to sell you one is full of it.

How could this possibly be true? You claim to know a lot about the GDPR, I’m not sure my business is compliant. Can you take a look and tell me? What’s that called if not an audit?

An audit without certification will never give you anything that you could not have come up with yourself. So feel free to buy a GDPR audit but realize that you are just buying an opinion.

Re: GDPR: Removing Monal from the EU

#538
post #205

Earlier quoted context omitted.

I think you're lumping together too many things. > I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. > All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. What if I didn't want you to visit my w…

If you didn't want visitors to your site you shouldn't have put it on the web. If you want visitors to your site without any strings attached you should serve the content without grabbing and storing anything about the clients. This is called the "technician's responsibility" where I come from. To only track/store/process what is absolutlely necessary, in order to not be liable for the consequences when someone you c…

>If you didn't want visitors to your site you shouldn't have put it on the web.

This feels dishonest. If, for example, I wish to ban certain people by IP Address, your solution is to take my entire service offline?

Re: GDPR: Removing Monal from the EU

#539

Earlier quoted context omitted.

Perhaps this isn't obvious to everyone, but other people are actually not obligated to spend their time doing things you want them to.

Perhaps it's not obvious to the author of that software, but publishing products (even free ones) involves liability. You cannot simply say, "Well I didn't charge you!" A free product can still be the subject of a fraud lawsuit, or a negligence lawsuit, etc. And I think this is as it should be. I'm not sure why people think software meant for use by a broad audience, however cheap, should not be subject to basic safe…

In the United States and under English common law, those giving away something for free are only liable for 'gross' negligence, which is a significantly lower bar than the implied warranties of merchantibility that will arise if you start charging. All these warranties can simply be disclaimed, by licensing the software correctly.

> I'm not sure why people think software meant for use by a broad audience, however cheap, should not be subject to basic safety, security and privacy regulations.

There is a major difference between cheap and free. There is an especially major difference between cheap and open-source, because most open-source licenses include specific text to disclaim any implied warranty. Without contractual consideration, the author's words don't form any kind of contract with those who choose to use his software.

This is not a difficult concept to grasp. If the author made any money off his project, then yes, a very strong warranty is implied, but without that, the warranty is rather weak. Under common law, those giving things away for free can only be held liable for 'gross negligence', which is different from the automatic warranties that arise when you sell things, regardless of price.

Re: GDPR: Removing Monal from the EU

#540
post #489

Earlier quoted context omitted.

> Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. This has never been true since the internet was international. You have always had to comply with laws of countries you interact with, it's just that most people who ran internet businesses decided to ignore the law (just try hosting some copyright or patent infringing content on the internet and see…

The fundamental properties of doing business overseas have changed. What used to be a prohibitively expensive enterprise is now within the reach of everyone. And the cost of regulation, which used to be negligible compared to the cost of the enterprise itself, has now become a significant barrier for small businesses.

The costs of compliance are not a fundamental property of doing international business (after all, governments can change the cost of compliance or make it cost nothing). The fundamental properties I was referring to are that you are transacting with another nation state's people, and you have no fundamental right to do business with them unless that other nation grants you permission. Just because it is easier to do such business without permission or oversight doesn't change that you are doing the same type of business.

You might not think the costs are fair (and in practice that should be taken into account by regulators, to avoid removing all international trade and thus losing the benefits), but that is not really justification for arguing that this is a departure from how things have always been. Nor is it justification for arguing that you shouldn't care about the laws of other countries you do business with because you don't live there (which is what GGGGP was insinuating).

Post reply on HN