Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

571–580 of 957 posts

Re: GDPR: Removing Monal from the EU

#571

While this developer may be overreacting (he probably doesn't need a DPO), i understand why it might just be easier to block it , at least until there are precedents about how to comply and more info on how the regulation will be enforced. GDPR can be scary for developers, because nobody actually knows how a website or app is supposed to work (I have yet to see a single example), and it requires a series of steps tha…

> The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one.

It is an utter failure but mostly because services try hard to turn it into a travesty and simultaneously manage to deceive their users by attributing blame for the annoying cookie warnings to regulators.

"We are required by law to show you this stupid warning because our site uses advanced features that need cookies to work. Without them, you couldn't even login! (OK)"

Which, of course, is utter bullshit. If you can stop this deception, things might actually work out as intended. Sites may rethink their need for personal data gathering if cookie warnings would have to look more like the following.

"We'd like to analyze your site usage for ad targeting and other things that make us some more money.

Do you agree we use cookies for that? (yes/no)

NOTE: Even if you disagree, standard site functionality like logins will continue to work unharmed."

Re: GDPR: Removing Monal from the EU

#572

Earlier quoted context omitted.

That's the law in the EU, I think it's natural to have a hobby that doesn't break any laws.

Right... which is why this guy has decided this is no longer going to be his hobby in the EU. While the EU has every right to say 'those who do X for a hobby must do Y to comply' they cannot say 'everybody must have X for a hobby' or 'Bob must continue doing X for a hobby' .

The high-tech laws and regulations of the EU are a bit more sophisticated than in the US so it may take some time for the rest of the world to catch on.

Re: GDPR: Removing Monal from the EU

#573
post #171

Earlier quoted context omitted.

There are many other laws where you‘re taking risks. Maybe you‘re violating some US securities statute? Maybe you‘re violating some German accounting rule? Why haven‘t all those doomsayers closed down their businesses long before the GDPR?

I mean, technically I'm taking a risk when I step out of my house every day. So why ever walk? There are varying degrees to which people see laws as affecting them. Small business tech owners, when a law says they have work to do, are going to feel affected. If there was a securities or accounting law that felt similarly overreaching one could expect a similar reaction. This is especially true if there is an alternat…

There is hardly anything more overreaching than US tax, securities and accounting law.

People in other parts of the world have gotten used to that. As a current example, see US threats re: European business with Iran.

Even if the GDPR were overreaching (and I vigorously dispute that notion), it would simply be a taste of America‘s own medicine.

Re: GDPR: Removing Monal from the EU

#574
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

If there is a complaint against my small software company, are there limits on how much I'm required to spend on defense? Do I have to travel to Europe to defend my company or will investigators from Europe travel to my location at their own expense? Will I be reimbursed for reasonable expenses if the complaint is groundless? Are there parts of the regulation that act like strong anti-SLAPP laws in some states? Can m…

What can Europe do to you?

Assuming you are American, the only court you need to worry about is American court. Your company is American? Your bank is American?

What's the actual liability here? Worst case?

Re: GDPR: Removing Monal from the EU

#575

Earlier quoted context omitted.

Perhaps it's not obvious to the author of that software, but publishing products (even free ones) involves liability. You cannot simply say, "Well I didn't charge you!" A free product can still be the subject of a fraud lawsuit, or a negligence lawsuit, etc. And I think this is as it should be. I'm not sure why people think software meant for use by a broad audience, however cheap, should not be subject to basic safe…

In the United States and under English common law, those giving away something for free are only liable for 'gross' negligence, which is a significantly lower bar than the implied warranties of merchantibility that will arise if you start charging. All these warranties can simply be disclaimed, by licensing the software correctly. > I'm not sure why people think software meant for use by a broad audience, however che…

Even in America, if a user can argue that their consent is uninformed you can still end up with a lawsuit. What's more, various states have different rules regarding that liability as well.

Re: GDPR: Removing Monal from the EU

#576
post #521

Earlier quoted context omitted.

GDRP doesn't ban the milk from which messengers are churned at the messenger mills either.

Still in the dark mate. I'm sorry, maybe it's me, maybe it's you, but we seem to be speaking a different language.

It's you. The original comment says 'The author of Monal misunderstands/misrepresents the regulation and is throwing a silly tizzy'. To which you say 'some laws ban some things. also, cheese is made of milk'. These things are true but not related to the GDRP or messengers.

Re: GDPR: Removing Monal from the EU

#577
post #520

Earlier quoted context omitted.

> This is an easy thing to say when you're not personally exposed to the risk. No, it's an easy thing to say because we have over 20 years experiences of regulation around data protection. The regulators send a letter asking you to come back into compliance unless you've been really bad. They only move to fines if you ignore them. Here's a company that was handling sensitive personal data (medical data). They have a…

In fairness, this story is consistent with my own (limited) experience dealing with EU law. A few years ago, I was trying to determine if an EU based company I was advising really needed to offer the now-ubiquitous cookie advisories. I met with some very high profile (and very expensive) lawyers, who told me that although I technically needed to include the various popups and advisories, I was not in any real danger,…

I mean, I linked to an article where they do say this.

> The ICO said in a statement that it would only consider “enforcement action” if a company failed to register despite ICO advice.

And they keep saying this.

Re: GDPR: Removing Monal from the EU

#578
post #345

Earlier quoted context omitted.

the laws you refer to preexisted. Did they tear down all the houses that don't comply with contemporary building standards? I dont think so. GDPR is enforced retroactively on everything since the beginning of the internet.

> GDPR is enforced retroactively on everything since the beginning of the internet. That is not allowed. GDPR is only enforced for things which do not comply after in goes into effect. Further, it's not specific to the internet.

GDPR is already in effect. Enforcement has been deferred until 25 May to allow companies to comply with the legislation.

Re: GDPR: Removing Monal from the EU

#579

Earlier quoted context omitted.

Perhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?

If that was the case, no one outside the US could use VISA/MasterCard either (they enforce US laws on all international customers), or could make any business with any US company (even HN has to enforce the Iran embargo on all its international users). If you want to criticize local laws applied internationally, abolish the US.

i believe they enforce them legally, via international law. there is no such thing about privacy

Re: GDPR: Removing Monal from the EU

#580
post #219

Earlier quoted context omitted.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

As a webmaster, I have an absolute right to carve '192.0.2.7 requested /foo.html from me' into stone and store it for posterity. The GDPR prohibits me from doing that, and in fact requires that I have the ability to rewrite history by removing that fact if the user who had 192.0.2.7 ever requests it. Some people, on hearing this, say, 'well, that's fine, you can just store 192.0.2 or 192.0 instead.' That seems pretty…

> The GDPR prohibits me from doing that,

No it doesn't.

> and in fact requires that I have the ability to rewrite history by removing that fact if the user who had 192.0.2.7 ever requests it.

No it doesn't.

https://gdpr-info.eu/art-17-gdpr/

Post reply on HN