Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

561–570 of 957 posts

Re: GDPR: Removing Monal from the EU

#561

Earlier quoted context omitted.

First, you switched from respecting peoples' privacy to taking notes, thinking, and having opinions. I even responded to your comment before you added the notebook in the park example. You probably also noticed that I put »thinking« in quotes. Anyway, it is not the act of having the information about other people that is problematic, it is the act of collecting, using, or sharing it. Do you think I should be able to…

I didn’t write the original comment about the notebook in the park, just FYI. And your examples are not all the same. If you’re in public, you have no reasonable expectation of privacy. So yeah, take all the notes about me you want. That’s entirely different from my doctor sharing my health info.

Sorry, my fault with that first comment. Then why is your doctor not allowed to share your health information but a website where you search for and read about medical conditions can collect and share what you looked up as they please?

And while you personally may not have any expectations of privacy in the public, that is certainly not true in general for everyone and in every country. Here in Germany the constitutional court ruled just this week that having a dash cam in a car violates the privacy rights of the people you capture.

You are also generally not allowed to take photos of people in the public without their consent. It is not a problem if they randomly appear in a picture you took of a building or whatever, but you are not allowed to take photos were people are the main motive.

Re: GDPR: Removing Monal from the EU

#562
The GDPR is by most accounts and interpretations aimed at "the big players" ... but it is not SPECIFICALLY written to be limited to them.

Two view points to this:

1) If make to specific, big players will find a way to slip through the exceptions and game/lawyer the system

2) So vague , that only the "big players" will have the infrastructure/legal approval to actually guarantee 100% compliance. Smaller fish that the reward just doesn't justify the risk/uncertainty will certainly pull out of the market.

If the law is about "supercookies" and targeting an individual throughout the entire internet ... it should say that.

If its about the transfer/monetization of the aggregation of data ... PII being sold for money or some other in-kind transaction ... say that.

If a single entity uses a cookie and retains data for one single domain and that is ok ... say that.

If retaining logs that contain an IP Address and the logged in credentials are ok to keep for security auditing. .... say that ... if its only ok to store them for a year(??), 6 months(??) , 1 month(??) ... say fucking that!

If a company/site is aggregating PII of over a million unique users is troubling and should be specifically bound by these restrictions and need a DPO ... say that.

If a site only has a few 1,000 - 10,000 Unique PII records/users of note , and is not the focus of these regulations .... say that.

Give concrete examples, lawyer the shit out of it ... leave open for amendments so when abused can be modified.

It's just a shitty law trying to fix an already shitty situation.

Re: GDPR: Removing Monal from the EU

#563

Earlier quoted context omitted.

I can't see any way in which this interpretation can be valid. You'll always be able to "directly or indirectly" identify people from IP addresses. Just because I don't store IP and identity together, doesn't mean there's not many other ways to identify somebody based on an IP address.

How would one identify a person using only an IP address? If you have "other ways to identify somebody based on an IP address" then that wouldn't meet the criteria laid out by the lawyers.

I think the concern of the regulatory agencies (valid or not) is that there are db for sale that allow extremely precise locality information based on IP. Close enough to identify a household, which combined with other data can limit the data to a single person.

Re: GDPR: Removing Monal from the EU

#564
post #520

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

> This is an easy thing to say when you're not personally exposed to the risk. No, it's an easy thing to say because we have over 20 years experiences of regulation around data protection. The regulators send a letter asking you to come back into compliance unless you've been really bad. They only move to fines if you ignore them. Here's a company that was handling sensitive personal data (medical data). They have a…

In fairness, this story is consistent with my own (limited) experience dealing with EU law. A few years ago, I was trying to determine if an EU based company I was advising really needed to offer the now-ubiquitous cookie advisories. I met with some very high profile (and very expensive) lawyers, who told me that although I technically needed to include the various popups and advisories, I was not in any real danger, because of selective enforcement. Eventually, they changed their mind and we added the sliders anyway, but for a time, the law was stricter than the actual enforcement.

But I was an american being advised by a top tier british law firm. How is a random guy releasing free (or cheap) services on the internet supposed to deal with a situation like that? The arbitrary nature of the enforcement is exactly what makes this a problem. If there were strong penalties, but clear ways to remain in compliance, this developer might have made a different call.

If I know I'm technically out of compliance, and I don't have a high powered lawyer telling me it's not a big deal, then I'm not sleeping well. And if I can solve the problem once and for all by taking the unfortunate step of simply cutting EU residents off of the service, then I'm going to at least consider that option, and probably take it in the short term.

If the EU wants to reassure people that "The regulators send a letter asking you to come back into compliance unless you've been really bad. They only move to fines if you ignore them." then they would be well advised to make that very clear. If they don't, you're going to see more of this, and really, if it's true, why wouldn't they?

Re: GDPR: Removing Monal from the EU

#565
post #480

Earlier quoted context omitted.

That is the OPs exact point. Did you read the article? He mentioned that "The days of someone making something, putting it on the internet and offering it to the world seem to be over". And here you are talking about knowing the laws while the OP sits in a different country trying to run his business. You might be from Europe and to you it may just seem sensible but 1-5 person companies often have to make tradeoffs l…

But OP is wrong. OP is saying GDPR is making it impossible for him to offer the software, but GDPR has almost no effect on him. OP can just rely on "legitimate interests", and describe the data they're processing and why.

You say one thing, other people say other things.

It's easier just to say "this tool blocks Europeans" and problem avoided.

Re: GDPR: Removing Monal from the EU

#566
post #521

Earlier quoted context omitted.

Apologies, I genuinely don't understand this critique.

GDRP doesn't ban the milk from which messengers are churned at the messenger mills either.

Still in the dark mate. I'm sorry, maybe it's me, maybe it's you, but we seem to be speaking a different language.

Re: GDPR: Removing Monal from the EU

#567
post #392

Earlier quoted context omitted.

Schufa (the biggest consumer credit reporting agency in Germany) and article 35 can certainly co-exist. In fact you can write to Schufa and request that they delete all your data. However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that.

> However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that. How does that work for people who never had a Schufa history? If for instance I decided to move today from Brazil to Germany, would I be unable to do all these things there, since they would have "no…

You‘ll still have access. Probably at a higher rate.

Re: GDPR: Removing Monal from the EU

#568

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

I don't do any real business in the EU, but I'm a fairly succesful online marketer. Being able to flexibly use SaaS businesses is so, so valuable for testing and iterating on marketing plans. I would fight pretty hard against a company policy that limited it, since today's marketing test is tomorrow's major revenue driver.

Re: GDPR: Removing Monal from the EU

#569
post #380

Earlier quoted context omitted.

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

"you are required to comply with the laws of any country you do business with."

Prove that.

Because that's not how "the law" works. I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with.

No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees. And to my knowledge, Canada has not signed a treaty with the EU regarding enforcement of the GDPR.

Re: GDPR: Removing Monal from the EU

#570

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

> no, only larger orgs handling lots of personal data need this. I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?

https://gdpr-info.eu/recitals/no-13/

> To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. 4In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. 5The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC¹.

Post reply on HN