Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

601–610 of 957 posts

Re: GDPR: Removing Monal from the EU

#601
Honestly, most small USA businesses take one look at "Up to €20 million, or 4% annual global turnover – whichever is higher." and just run. There's no point in even trying to salvage the situation.

> For the 3.7 million small businesses with 1 to 4 employees, the Census Bureau figures show average annual sales in 2007 were $387,200.

Given that, who wants to risk a 20M fine? All this advice in this thread to do this, run it through a lawyer (lawyers are expensive especially international ones), makes no sense to the majority of the businesses in the USA: there are less than 8M employers in the USA and a very small percentage has a yearly turnover of even a mil not to mention the ~600M USD where the fine changes from a constant to a percentage.

To give you another idea of how much money this is, about a quarter of public companies have less than 25M USD market cap.

As a dual Canadian-EU citizen I am stupefied by this law.

Re: GDPR: Removing Monal from the EU

#602
post #568

Earlier quoted context omitted.

I don't do any real business in the EU, but I'm a fairly succesful online marketer. Being able to flexibly use SaaS businesses is so, so valuable for testing and iterating on marketing plans. I would fight pretty hard against a company policy that limited it, since today's marketing test is tomorrow's major revenue driver.

I think you misunderstand what I was saying. We collect data in our system. We use that data for marketing under legitimate interest. Sometimes marketing would like more analysis done on the data than we have time to implement. They hear about some SaaS business that will take the data and give them a marketing plan (Yay! No work to do!). They ask us to ship over all the data to the SaaS business. Sometimes it's a go…

I really appreciate this detailed response!

Re: GDPR: Removing Monal from the EU

#604

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

[deleted]

Re: GDPR: Removing Monal from the EU

#605

Earlier quoted context omitted.

How do you know that only Google and Facebook will have problems?

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

Regarding that, i wonder how DPAs will handle cases. I can totally think of small businesses or professionals like doctors reporting each other to the DPA. Can DPAs easily dismiss complaints?

Re: GDPR: Removing Monal from the EU

#606

Earlier quoted context omitted.

"Getting to use a website for free in exchange for your browsing data being analyzed is a great deal and a win/win for everybody." Which is why you are perfectly capable of giving consent to other websites to do that. "Surely anyone who disagrees with your feelings on this matter must be a sociopath, though." No, just those who insist on a "take it or leave it" approach.

You're not allowed to "degrade the service" or allow access contingent on consent to targeted ads/tracking, so the practice isn't going to be sustainable for websites when only a tiny percentage of users give consent, seeing how they get to use the site one way or the other - have their cake and eat it too.

> only a tiny percentage of users give consent

Implying that the majority of user's wouldn't just instantly click the largest button that says "make this annoying wall of legal text go away" whether that is agreeing to tracking or not?

While the inability to target ads based on data about you and your search history searches removes some amount of advertising income. Websites would still be allowed to show ads, and I would imagine that those ads can be specific to the article currently being viewed.

This is exactly how conventional TV advertising works, just because you don't know the gender, race, political views and entire life story of a website user, doesn't mean you can't get almost the same effect. You can target ads in general at specific content and hit most of the correct users anyway rather than targeting specific users and the content they have viewed in the past.

Re: GDPR: Removing Monal from the EU

#607
post #492

Earlier quoted context omitted.

This is such a terrible argument. You’re essentially arguing that any business of any kind should never complain or choose not to do business in a jurisdiction if the reason is regulatory burden, no matter how onerous, expensive, ambiguous, and offensive that regulation is. That’s illogical and not the way that any business evaluates what activities to pursue or forgo. You’re casting aspersions on this one guy and im…

> if the reason is regulatory burden, no matter how onerous, No, what we're saying is OP can't complain about the burden of this onerous regulation when the fact is that almost none of it is relevant to OP and he'll have to make only minor changes to be compliant. Several of the claims OP made are flat wrong and it's trivial to show they're wrong by simple web searches.

[deleted]

Re: GDPR: Removing Monal from the EU

#608

Earlier quoted context omitted.

I'm not actually sure he is running this as a business? It seems open source? He even suggests people download and build their own? So all he's done is save himself the time and effort of dealing with the GDPR and cost himself nothing.

The fact that it is open source does not mean it isn't a business. And yes, he has saved himself the time and the effort of dealing with the GDPR, has also managed to position himself as someone who pays lipservice to privacy but who does not care to actually be compliant with privacy legislation when it matters. I wouldn't want my data in his hands after that anyway (not that that would ever happen because I don't h…

[deleted]

Re: GDPR: Removing Monal from the EU

#609
post #528

Earlier quoted context omitted.

Note that I didn't say IPs aren't PII; I said they don't count as long as you are collecting them for the specific purpose of security and don't have any way to identify the person using that IP. Pretty much by definition that is not PII. That came from the legal departments from our German, UK, and French entities.

You contradict yourself, either its PII or not. Common understanding in the industry is that it is. Purpose of security doesn't change if its PII or not. Although security/auditing might allow to hold on for longer because you need the PII as a feature (which you should be transparent about). For pure telemetry you don't need it, I'd claim.

IPs can be PII under certain circumstances, but not the ones I laid out.

> Purpose of security doesn't change if its PII or not.

Security is the legitimate interest, an important part of collection under GDPR.

Re: GDPR: Removing Monal from the EU

#610

Earlier quoted context omitted.

Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.

No, you don't have to close at all. You just need to comply with the law, just like everybody else. You also need to file your taxes, keep the books in order, ensure that you do not pollute the environment, in some cases you need to be licensed in order to be able to practice your trade and so on. Why would this particular regulation suddenly cause you to close your business unless you were doing something really sha…

[deleted]
Post reply on HN