Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

541–550 of 957 posts

Re: GDPR: Removing Monal from the EU

#541
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

> We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it.

Government intelligence organizations like the NSA and foreign equivalents will now have a monopoly on unsolicited data collection. Which, combined with selective enforcement to prevent disruption of gov cartels, is one of the few reasons it went through.

Re: GDPR: Removing Monal from the EU

#542

Earlier quoted context omitted.

You're right, there was never a business behind this. It's free software. Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

Because even free software has to comply with the law. Funny how that works, but not making a profit on something does not absolve you from legal liability.

Funny how that works, but not making a profit on something does not absolve you from legal liability.

But why would someone who is literally giving something away accept that liability, or even any perceived risk of liability, if they have an easier option?

Re: GDPR: Removing Monal from the EU

#543

If this is the sort of enforcement we can expect, this could suck: https://ico.org.uk/action-weve-taken/enforcement/sse-energy-... (there are several others, this one is just interesting because it's a very simple mistake with very minimal PII) Also, my understanding is Germany allows for whistle-blowers to take a cut of fines. Language in the GDPR calls for over-estimating damages for loss of PII when compensating i…

It's a fixed penalty, so ICO didn't have much choice over the amount.

Re: GDPR: Removing Monal from the EU

#544

Earlier quoted context omitted.

If the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?

> Because what is the alternative Wouldn't a better alternative be to design a messenger that complies with GDPR? Simple user accounts that can be deleted at the request of the user, peer-to-peer encryption (and where possible, communication), a "storage cabinet" for each user where encrypted data end in when the user is offline (with an encryption/decryption key that is generated client-side and transmitted while bo…

I don't think you actually answered his point. Sure you could build an IM client that is GDPR compliant, but at what point do the costs become so high that everyone just defaults to using Facebook because (1) they can afford to be compliant and (2) they are trained well enough to not fuck up their encryption.

In other words, are we moving towards a world where unless you are VC backed (Signal, Telegram, Whatsapp, etc) don't bother building an IM client? Also note, I don't think there might be anything wrong with that - if we expect all our communications to be E2E encrypted, maybe Joe Shmoe shouldn't be writing an IM client.

Re: GDPR: Removing Monal from the EU

#545

Earlier quoted context omitted.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

Do I misunderstand this section: "Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal dat…

You do misunderstand it.

The regulator is the effective judicial remedy.

In the UK there's also a First Tier Tribunal and probably an upper tribunal. These are when the regulator has made an error in law.

Re: GDPR: Removing Monal from the EU

#546

Earlier quoted context omitted.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

did that $250 include an audit to verify that you are actually in compliance?

Are you compliant with the copyright laws in your company? Are you sure you have licenses for all the software you use? Have you audited the software you write to ensure that none of the programmers have included code without an appropriate license? How about patents? Are you sure that the software you write does not infringe on patents somewhere? There are people who will happily audit your company in exchange for a truckload of money... For some reason, most people don't think this is necessary.

Your risk in GDPR is similar to your risk in IP law. If you don't comply with the law and someone calls you on it, you might have legal proceedings against you. In most cases it's pretty obvious if you are compliant with the law (Well, to be fair, it's completely unobvious if you are going to get randomly sued for patent infringement, but I digress...) If you are have a very complex situation, then maybe it is worth some legal advice, but it's pretty freaking obvious if you need the data you have collected in order to fulfil the contract or not.

Re: GDPR: Removing Monal from the EU

#547

Earlier quoted context omitted.

Can you imagine yourself trying to convince a regulator of that?

Like Zuck before senate? I imagine when running a business one faces many stupid bureaucrats, this could be another one (or they could be competent and understand and accept the technical explanation of how my imaginary company complies with GDPR). But yeah, why quit because of the n + 1th bureaucrat, when you've dealt with n of them while starting and running of your business?

> Like Zuck before senate?

No, like Google, Microsoft and Intel before the European Commission.

Re: GDPR: Removing Monal from the EU

#548

Earlier quoted context omitted.

Disclaimer: I work on GDPR stuff for a company it certainly applies to, this is my opinion not my companies We’ve spent tons of money & interacted with lots of official sources trying to get opinions about what GDPR means and it just isn’t available. Everything is a risk mitigation technique right now with no real answers in sight. If I had any personal projects serving traffic in the EU right now that weren’t profit…

What are you talking about? There's a ton of information about what GDPR means, both from the EU and the national regulators (particularly the ICO). The best sign that the regulators aren't going to go crazy with this, is that they already have quite significant powers and they're not throwing their weight around now.

https://www.google.com/amp/s/www.xda-developers.com/facebook...

Mind you Belgium us 1/30 the size of the US

Re: GDPR: Removing Monal from the EU

#549
post #508

Earlier quoted context omitted.

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

In Canada they definitely still put toys in the eggs. http://www.ferrero.ca/our-brands/kinder-surprise/moments-of-...

Re: GDPR: Removing Monal from the EU

#550

If this is the sort of enforcement we can expect, this could suck: https://ico.org.uk/action-weve-taken/enforcement/sse-energy-... (there are several others, this one is just interesting because it's a very simple mistake with very minimal PII) Also, my understanding is Germany allows for whistle-blowers to take a cut of fines. Language in the GDPR calls for over-estimating damages for loss of PII when compensating i…

I read that enforcement report. I think it was fully warranted that the 1,000 pound fine was levied against that company. (1) they did not immediately report the fact that they disclosed that customers private information and (2) they did not have appropriate technical measures in place to avoid such problems, specifically: they were tasking their cs reps to cut-and-paste information between screens that could display the information of two unrelated customers, a super stupid and error-prone set up.

The fine, 1000 pounds is proportionate given the size of the entity it is levied against, the resources at their disposal and the turnover of the company, if the company had been much smaller one would hope for leniency but the fine would have not been levied at all or it would have been 1000 pounds, no middle ground there.

You'd hope they learned their lesson.

Post reply on HN