Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

581–590 of 957 posts

Re: GDPR: Removing Monal from the EU

#581
post #464

Earlier quoted context omitted.

You can be fined if there is international or bilateral law or if somehow else the fine can be domesticated. There is no international regulation (not even consensus) on privacy so the law is not directly enforced here. However you are also not required to apply another country's law to all your customers, and if you don't want to you should (but are not really enforced to) block the EU.

Considering that most online businesses are (effectively) a form of international trade, I wonder whether GDPR fines could be seen as a form of customs fine (which definitely is something that foreign companies can be forced to pay, as you've said).

[deleted]

Re: GDPR: Removing Monal from the EU

#582
post #508

Earlier quoted context omitted.

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

Looks like this now http://fortune.com/2017/05/22/kinder-egg-usa-debut/

I have seen this outside of US also (pretty sure it was doing a Europe trip)

Re: GDPR: Removing Monal from the EU

#583
post #549

Earlier quoted context omitted.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

In Canada they definitely still put toys in the eggs. http://www.ferrero.ca/our-brands/kinder-surprise/moments-of-...

http://fortune.com/2017/05/22/kinder-egg-usa-debut/

Toy is also in US version but different design

Re: GDPR: Removing Monal from the EU

#584

This is going to sound crazy, but I spun up an instance of a simple open-source comments system[1] for a blog that I write, and I chickened out of deploying it because I wasn't sure if it complied with GDPR. I distrust Disqus over their ad-driven model and deep tracking of users, so for now I’m just doing without comments. Is it possible to self-host something that handles user data (name, comment, IP address) and co…

It doesn't apply to personal projects, unless they're commercial.

https://gdpr-info.eu/recitals/no-18/

> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.

Re: GDPR: Removing Monal from the EU

#585

Earlier quoted context omitted.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

I've seen this variety sold in Poland https://www.candywarehouse.com/assets/item/regular/kinder-jo... But I'm not sure it's typical.

Yeah. That's the US version also, not sure how common it is outside US.

Re: GDPR: Removing Monal from the EU

#586
post #361

I'm pretty sure lawyers and "consultants" are the only ones super happy about GDPR. Companies will still harvest user data with updated T&Cs and more buttons for the user to click, because all services will be useless without accepting. Governments will also continue gathering users' data for "the common good".

I'm pretty sure that many ordinary European (and US!) citizen are pretty happy about the GDPR as well. If clicking an extra button is really all it takes. But despite the assurances of many here that it's not hard to comply, I'd probably have shut down the servers of my own hobby non-profitable location data gathering website as well, simply because even reading the GDPR document would be too much effort.

Personal projects are exempt.

https://gdpr-info.eu/recitals/no-18/

> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities.

Re: GDPR: Removing Monal from the EU

#587
post #185

Earlier quoted context omitted.

GDPR does not require deleting data from backups. http://blog.quantum.com/backup-administrators-the-1-advice-t... "The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations wil…

CNIL is one of ~20 regulatory agencies & this isn’t their “official” stance. Other opinions have concluded that you must keep an index of requested deletes in the face of backups, for instance.

That agrees exactly with what CNIL said. Obviously you have to keep an index of requested deletes for the same length of time you keep backups in order to re-delete the relevant data in the event of restoring the backups.

Article 63 of the GDPR specifically covers consistency of enforcement across the regulatory agencies.

Re: GDPR: Removing Monal from the EU

#588
post #540

Earlier quoted context omitted.

The costs of compliance are not a fundamental property of doing international business (after all, governments can change the cost of compliance or make it cost nothing). The fundamental properties I was referring to are that you are transacting with another nation state's people, and you have no fundamental right to do business with them unless that other nation grants you permission. Just because it is easier to do…

It is a departure from the way things have always been online. The EU can certainly demand that web creators jump through hoops, but then they can hardly complain if creators outside the EU decide that interacting with the EU isn't worth the trouble.

Nobody is forcing people to do business with the EU. If you don't like the laws in the EU, then you don't have to do business with the EU. Simple as that.

(My whole point is that a lot of people arguing about GDPR want it both ways, and don't see that it's not strange that countries have rules for doing business with their residents.)

Re: GDPR: Removing Monal from the EU

#589
post #577

Earlier quoted context omitted.

In fairness, this story is consistent with my own (limited) experience dealing with EU law. A few years ago, I was trying to determine if an EU based company I was advising really needed to offer the now-ubiquitous cookie advisories. I met with some very high profile (and very expensive) lawyers, who told me that although I technically needed to include the various popups and advisories, I was not in any real danger,…

I mean, I linked to an article where they do say this. > The ICO said in a statement that it would only consider “enforcement action” if a company failed to register despite ICO advice. And they keep saying this.

So, imagine you're running a free service as a side project. And the state of Idaho introduces a law, that has federal teeth, such that if a resident of Idaho might use your service, you must register with the state of Idaho. Would you be happy about that? Is there any possibility that you might decide to simply block Idaho rather than deal with the hassle?

A better solution would be a webpage, hosted by the state of Idaho saying "Here's what we're after, don't do these things, and you're in no danger." Followed, hopefully, by a list of things that you weren't planning on doing anyway because you're not a jerk, and that are crystal clear so you don't have to speculate about how selective the attorney general of the state of Idaho is in prosecuting these sorts of crimes.

Re: GDPR: Removing Monal from the EU

#590
post #555

Earlier quoted context omitted.

First, notice how things like legitimate interests are not narrowly defined and left up to the DPA to judge. Which makes it hard to know whether you even need consent or not. Second, this is ICO, the British regulator. There are 28 of them one in each country and they won't always agree, so the application of GDPR policies can vary.

But, again, if you're not compliant they'll just write a letter telling you this and asking you to come into compliance. At that point you can check your understanding of the law and what you're doing and write back letting them know why you think you're in compliance; or you can change your process; or you can take it to court.

What happens when that is not possible though? E.g. in the case there is a breach and it is found out because of it that you were not compliant. Do they still write you a letter? Also , is this procedure common for all DPAs or just for the UK?
Post reply on HN