Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

641–650 of 957 posts

Re: GDPR: Removing Monal from the EU

#641
post #620

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

> if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job how could you "not need" data if the loss "destroyed" the business model?

> > information that you don't need to do the job

For example, my business model might be to ask you for your login and password information for your bank so that I can help myself to the contents of your bank account. In return I'll send you a newsletter on how to get rich quick :-)

I doubt you are asking seriously, but in case you are, the distinction is: if I need the information to complete the contract, then it is under contract basis and I'm allowed to use it for that purpose. If it's not needed for completing the contract, but I have a legitimate reason for using the data anyway (kind of vague, but includes marketing -- basically all the stuff that was legal before GDPR) I can do so, but I need to tell you I'm doing it. You can object and then I have to stop. If I have no legitimate reason for using the data, but I want to anyway, I can still do it. I need to ask for your consent (which has to be opt in). My service can't depend on you opting in (because I have no legitimate reason for needing the data). I can't deny service just because you opt out. You can also withdraw your consent at any time.

So in my silly example at the top, I could literally ask for consent to use your login details for you bank. If you agreed, I could use them. However, since I have no legitimate interest in your bank login details (other than I wanna look at your bank balance), I can't make my service depend on that.

If your business model is based on making money from data that you have no legitimate interest in and you have no consent for... well, I really, truly have no sympathy at all. I understand that some people may have a different opinion, but I don't think mine is really that unreasonable.

Re: GDPR: Removing Monal from the EU

#642
post #420

Earlier quoted context omitted.

Perhaps having legitimate purpose for data collection in the first place helps.

Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?

It's a deflection tactic by people who are emotionally invested into GDPR. Note the extreme emotionalism that GDPR draws out of its supporters. That makes it difficult for some of the supporters to have a rational discussion when it comes to the flaws of GDPR. They don't have a legitimate response to the context in question, so the easy approach is to attack the credibility of the person stating that they've struggled with compliance, rather than engaging in substantive discussion about the problems that GDPR generates for small businesses. The fear for the supporters is that if they admit to there being any flaws in GDPR, that will then act as a threat to GDPR (which they view as a monumental victory for privacy). They don't want to give an inch of ground, no matter the issue, because they're afraid of having GDPR diluted, taken away, and or not spread to the rest of the planet.

This is also why in all cases you'll see the GDPR supporters go after the character of the site/service owner (including always questioning their motives to muddy the waters). It's an attempt to short-circuit any reasoned debate, to destroy the credibility of the opponent. This has happened numerous times on HN in the last month or two.

Re: GDPR: Removing Monal from the EU

#643
post #380

Earlier quoted context omitted.

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

No. It is quite definitely not true that you must comply with the laws of countries you are not in.

The EU is primarily leveraging the fact that most everyone wants to travel to the EU eventually.

While you in your home country you have no need to comply with the GDPR unless a treaty between your home country and the EU exists to mandate it.

The EU is also leveraging their trade agreements.

What they don’t understand is that China is next and they have totally diametrically opposed views on consumer privacy. But when has the EU ever been farsighted?

Re: GDPR: Removing Monal from the EU

#644

Earlier quoted context omitted.

This seems as good a place as any to challenge some of the simplifications that are often given in defence of the GDPR. Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. Fair enough. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that d…

Thank you! This post starts to show some of the huge complexities that GDPR has for business and their understanding of what the terms of the law mean. A point is that often statements of a law are defined not by the language but by the ruling of lawsuits that occur around those statements and that is what most companies and lawyers are waiting for, what do courts rule when these lawsuits happen. The biggest issue th…

I think some of the fear that smaller business have is that this will encourage lawsuits until people understand how the courts will rule on each item.

That concern really is unfounded, though. The primary means of enforcement of the GDPR will be action by national data protection regulators. It isn't some carte blanche for trigger-happy lawyers to start suing every business that gets a little detail wrong or anything like that.

The general concern that the picture is unclear until something happens to clarify it is, unfortunately, much better founded.

Re: GDPR: Removing Monal from the EU

#645
post #489

Earlier quoted context omitted.

> and I don't see why "it's on the internet" appears to be the main counter-argument. Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. Regulations like GDPR are making doing business in more than one country more difficult and encouraging a Balkanized web.

> Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. This has never been true since the internet was international. You have always had to comply with laws of countries you interact with, it's just that most people who ran internet businesses decided to ignore the law (just try hosting some copyright or patent infringing content on the internet and see…

That is not true. You do not need to comply with any country’s laws except the one you reside in, except for treaties by your home country that say otherwise or your desire to travel abroad.

Just think of what China would do to the Internet if it could.

Re: GDPR: Removing Monal from the EU

#646
post #618

Earlier quoted context omitted.

... unsure if troll or just slow. parent was giving an example of how Monal isn't "throwing a silly tizzy" ... instead they have deemed the cost of complying with the regulations (all the items listed in the article) not worth the reward, much like how raw milk cheese companies decided to not sell in America because it was not worth the cost to comply (change practices, open different facility) with the regulations.…

The original comment is about the proportionality of the response, the choice the author is making and what the commenter thinks about it. When something is banned outright, there is no choice and no proportionality. So, no, it's not particularly responsive nor analogous.

Same as the ban on the cheese wasn't a ban on "cheese" it was a ban on "cheese made with this manner" the regulations being shown here aren't a ban on "collecting/using personal information" it's a ban on "collecting/using personal information this manner"

Again cost / benefit is always a valid choice to operate somewhere.

Re: GDPR: Removing Monal from the EU

#647

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

I have started to think that parts of GDPR should have been restricted to large companies - e.g. anyone with more than 100k active users, data describing 100k individuals, or an organization employing more than 100 employees. That would seem like a fair way to protect privacy while keeping barriers low for tech ventures / experiments.

Re: GDPR: Removing Monal from the EU

#648
post #583
post #549

Earlier quoted context omitted.

In Canada they definitely still put toys in the eggs. http://www.ferrero.ca/our-brands/kinder-surprise/moments-of-...

http://fortune.com/2017/05/22/kinder-egg-usa-debut/ Toy is also in US version but different design

I’m in Canada and can confirm that the toy-in-the-egg version was always sold here. As far as I know, this hasn’t changed. E.g. http://www.canada.com/life/Kinder+Surprises+Banned/2353187/s...

Re: GDPR: Removing Monal from the EU

#649

Earlier quoted context omitted.

I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. Likewise. This idea that the GDPR has been in the works for years so it's somehow implausible that very small businesses have only just heard of it doesn't stand up to scrutiny. No owner-run microbusiness is spending the time necessary to keep up with the vagaries of EU debates. Simi…

Thank you for perfectly describing the frustrations I have experienced with GDPR. As the owner of a small SaaS business in the US I don't have the time to follow various EU regulations that closely. I only found out about GDPR earlier this year from a random HN comment. I can't understand the attitude from some HN commenters that everyone should have known about this for years. Where/how should every small business t…

Nobody actually knows what "GDPR compliant" means. As it's up to you to demonstrate, and it's up to your regulator to decide a policy enforcement guideline, basically nobody knows. It's really, really, really burdensome, especially if you have to retrofit it to existing systems.

Re: GDPR: Removing Monal from the EU

#650
post #479

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is an amusing example, since they decided to offer a compliant variant of their product in the US. https://www.today.com/food/kinder-joy-chocolate-eggs-are-com...

They did that in a rather smart way, too, by diverging it enough from the original that they could sell it elsewhere as a new thing.

I mean, it never really took off here, very few people prefer it over the original, but better than not being able to sell it outside of the US at all.

Post reply on HN