Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

591–600 of 957 posts

Re: GDPR: Removing Monal from the EU

#591

Earlier quoted context omitted.

> He's not handling sensitive personal data. How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".

You can guarantee that because the messages aren't handled by the server: "Even though no message traffic passes through Monal’s sever".

This is an important point.

Example: Parts of our software run on customer servers and as such they are processing data in their control and not ours, hence can for example used to filter out personal data before they are then sent to our servers, without causing any GDPR related triggering of sending personal information to a third party (our company).

Re: GDPR: Removing Monal from the EU

#592
post #568

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

I don't do any real business in the EU, but I'm a fairly succesful online marketer. Being able to flexibly use SaaS businesses is so, so valuable for testing and iterating on marketing plans. I would fight pretty hard against a company policy that limited it, since today's marketing test is tomorrow's major revenue driver.

I think you misunderstand what I was saying. We collect data in our system. We use that data for marketing under legitimate interest. Sometimes marketing would like more analysis done on the data than we have time to implement. They hear about some SaaS business that will take the data and give them a marketing plan (Yay! No work to do!). They ask us to ship over all the data to the SaaS business. Sometimes it's a good idea because the SaaS business is legitimately providing an analysis service. Almost all of the time the SaaS business is providing nothing beneficial and instead just scooping up personal data that they sell. It's difficult for us technical people to explain why we can't just arbitrarily ship data over to some random SaaS. With GDPR it will be much, much, much better. Essentially I think it will shut down the fly by night operations that are just sucking data and offering nothing in return. But on the flip side it will mean that these analysis operations will have to charge a reasonable fee for their services (instead of selling the data they collect). This, in turn, will prompt the marketing people to have to do due diligence because they actually have to spend money out of their budget. No more "It's free, so why not?"

Similarly we sometimes get asked to incorporate silly things into our service because the marketing people think that it will create engagement. Again, these are free SaaS businesses that are scooping up data and selling it. Although I made up the cat emoji thing, it's not that far off what we sometimes get asked to incorporate. With GDPR, those businesses are going to have to charge for their services and that's going to have to come out of our budget. We don't have to argue "We're not shipping our whole customer database over to a SaaS just so we can have cat emojis on the the system". Similarly, it makes our systems simpler because if they really want cat emojis, we can implement them -- it's just not "free" (it never was, but it's hard to have that conversation sometimes).

I probably should have left the SaaS thing out of my explanation because it's confusing and only slightly related to what I was talking about :-). Like I said, we use some great services for marketing and will continue to do so under GDPR.

Re: GDPR: Removing Monal from the EU

#593
post #58

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

which clause would apply to require a DPO? clause a: not a public body clause b: not systematically monitoring (eg. installing video cameras all over the streets) clause c: not processing large scale sensitive or criminal information. doesn't look to me like a DPO is needed based on this article?

XMPP does have presence functionality so I'd consider that to be systematic monitoring. I don't know if his service is doing that, but it's one of the most useful aspects and definitely seems to fit the definition to me.

Re: GDPR: Removing Monal from the EU

#594
post #380

Earlier quoted context omitted.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

"you are required to comply with the laws of any country you do business with." Prove that. Because that's not how "the law" works. I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees. And t…

> I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with.

If you decide to sell a couch to someone in America, you have to comply with American tax laws, American import and customs laws, American consumer laws, American patent laws, American copyright laws, American trademark laws, and any other laws involved with doing a financial transaction with someone in America. The same logic applies for Australia, the United Kingdom, Germany, Belgium, South Korea, Japan, etc. Pretending otherwise is naive, and if you don't believe me then try to sell something patented in America to an American.

The key question is what happens if you break those laws. In most cases you will be given a fine, and if you don't pay then you will no longer be allowed to sell goods to consumers in that country. If you continue to break the law then you are probably breaking an international treaty on border control or customs, which means that you could be extradited or tried in your own country. Some of the laws I mentioned above are mediated through international agreements, but the fundamental point is that if you break their laws they can place sanctions against you to stop you from doing business with them.

Of course, for a couch business things would probably never reach that level. And for an internet business you probably would just be IP blocked or something similar.

> No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees.

But it only affects you if you make the positive decision to do business with a country that has those laws. If you don't decide to do that, then you don't have to follow those laws (obviously). You can't have it both ways though (the benefit of having access to a market without having to follow the laws of that market).

In the case of enforcement you're right that they wouldn't have the right to compel to you to pay a fine, but they can in theory place sanctions against you. So if you continue to do business with sanctions in place then there is a process for extradition through international treaties.

Re: GDPR: Removing Monal from the EU

#595
If a similar law to GDPR was introduced in other countries such as the US, complying now would probably cost considerably less than dumping business in every country that does it and complying with all the laws only once you can't operate sustainably as a business anymore.

Re: GDPR: Removing Monal from the EU

#596

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

This seems as good a place as any to challenge some of the simplifications that are often given in defence of the GDPR.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect.

Fair enough.

You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data.

Right, but probably the most practically relevant basis for anything non-trivial will be legitimate interests, which of course involves balancing tests. Even today, just a week before this all comes into effect, there is little guidance about where regulators will find that balance.

If you are using consent lawful basis, you need to get consent in an opt-in manner. You need to record what statement you have shown to the user and any consent that you receive.

But this is retrospective and stronger than the previous requirement. Even if you have always been transparent about your intentions and acquired genuine opt-in from willing users, you are now likely to be on the wrong side of the GDPR if you can't produce the exact wording that was on your web site or double opt-in email a decade ago. The most visible effect of the GDPR so far seems to be an endless stream of emails begging people to opt in to continue receiving things, even where people had almost certainly genuinely opted in already before.

For legitimate interest (which is essentially exactly the same as the laws that are currently on the books) you need to be able to exclude processing the data if someone objects.

Not quite. There also appear to be a balancing aspects here, though with some additional complications involving direct marketing, kids, and various other specific circumstances.

Take a common example of analytics for a web site. These may include personal data because of things like IP addresses or being tied to a specific account. Typically these have relatively low risk of harm for data subjects, but if for example a site deals with sensitive subject matter then that won't necessarily be the case either.

A business might have a demonstrable interest in retaining that data for a considerable period in order to protect itself against fraud, violation of its terms, or other obviously serious risks. Maybe the regulators will consider that those interests outweigh the risk to an individual's privacy if their IP address is retained for several years, at least in some cases. Maybe they will find differently if it's the web site for a drug treatment clinic than if it's an online gaming site.

Even if the subject matter isn't sensitive, where does the line get drawn? A business that offers a lot of free material on its site to attract interest from visitors might itself have a legitimate interest in seeing who is visiting the site and tracking conversion flows that could involve several channels over a period of months. This is arguably less important than protecting against something like fraud, but nevertheless the whole model that provides the free material may only be viable if the conversions are good enough. But equally, maybe it's not strictly necessary for the operation of the site and whatever services it offers for real money, so should the visitor's interest in not having their IP address floating around in someone's analytics database outweigh the site that is offering free content in exchange for little else in return?

That's just one simple, everyday example of the ambiguity involved here, and as far as I'm aware the regulator in my country has yet to offer any guidance in this area. Would any of the GDPR's defenders here like to give a black and white statement about this example and when the processing will or won't be legal under the new regulations?

The other lawful bases are very unlikely to show up in most organisations.

I would think the basis that you have to comply with some other law is also likely to be quite common. It will immediately cover various personal data about identifying customers and recording their transactions for accounting purposes, for example. But again, since that will include the proof of location requirements for VAT purposes in some cases, how much evidence is a merchant required to keep to cover themselves on that front, and when does it cross into keeping too much under GDPR?

The other main problem is that if you want to use something other than contract basis, you need to build something that allows the user to exercise their rights.

And once again, those rights are significantly stronger under the GDPR, particularly around erasure or objecting to processing. Setting up new systems that comply may not be too difficult, but what about legacy systems that were not unreasonable at the time but don't allow for isolated deletion of personal data? To my knowledge, there is still a lot of ambiguity around how far "erasure" actually goes, particularly regarding unstructured data such as emails or personal notes kept by staff while dealing with some issue, or potentially long-lived data in archives that are available but no longer in routine use. And then you get all the data that is built incrementally, from source control systems to blockchain, where by construction it may be difficult or impossible to selectively erase partial data in the middle.

Not to put too fine a point on that, personally I highly approve of this. I really could care less if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job.

But what if an online service's business model relies on processing profile data for purposes such as targeting ads to be viable, and regulators decide that a subject's right to object to that processing outweighs its necessity to the financial model?

It's easy to say a lot of people might not like being tracked, but on the other hand, if services like Google and Facebook all disappeared in the EU as a result of the GDPR, I'm not sure how popular it would be. There are two legitimate sides to this debate, and neither extreme is obviously correct.

Re: GDPR: Removing Monal from the EU

#597

Earlier quoted context omitted.

For jobs to be created (presumably in startups) , there must be startups first. Startups won't be started if you need to hire 1 full time accountant (for the VAT mess), 1 privacy person and 1 lawyer before you even lay down your idea. I get it that GDPR is creating some nice jobs these months, but it won't last long. I wonder if this guy would even make the app if he was in the EU today. I am all for fair taxation an…

You don't need a 'full time accountant' for the VAT mess, I've been doing this for years (decades) and it took about 2500 euros / year / company for the full administrative burden, including payroll for up to 25 employees. You don't need a privacy person either (I suspect you mean DPO), but you do need to know what you are doing. > I am all for fair taxation and privacy, but the EU should start creating the mechanism…

the parent specificly refered to jobs being created for privacy officers or sth. i m replying to that. Also, the too many different VAT regimes can create a huge accounting mess if you are selling in many different EU countries, hence the existence of payment processors and relevant startups.

Re: GDPR: Removing Monal from the EU

#598

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

> Your evaluation of the impact of the law on your project is lazy

That seems a very pejorative way to describe it. You can say the same thing in terms of "you could probably keep operating if you put a lot of effort into understanding the details of the law" which kind of proves the author's point: this creates work for people and why should someone do that work for no return? Where does the presumption that people owe EU citizens these services at a higher standard than the rest of the world is content (legally) to accept?

Re: GDPR: Removing Monal from the EU

#599
post #211

Earlier quoted context omitted.

Where in the law does it say they only do this when ignored? Surely if this were the case, they'd put it in the law like they did punishment limits. Or are you banking on subjective enforcement?

Right here. You get a month to comply with any deletion request and can extend it to 3 months if needed. https://gdpr-info.eu/art-12-gdpr/ "The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into accoun…

thats not it. From my understanding people say that because that is how the UK regulator has dealt with cases in the past. But there is a different regulator in every EU country

Re: GDPR: Removing Monal from the EU

#600

Earlier quoted context omitted.

You're right, there was never a business behind this. It's free software. Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

Because even free software has to comply with the law. Funny how that works, but not making a profit on something does not absolve you from legal liability.

[deleted]
Post reply on HN