Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

651–660 of 957 posts

Re: GDPR: Removing Monal from the EU

#652
post #508

Earlier quoted context omitted.

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

They marketed it as a new thing beside the original here in Germany.

Most people seem to prefer the original, though. They lost a lot of charm by going from toy+edible+tinfoil to plastic+toy+plastic+edible+plastic spoon+plastic.

Re: GDPR: Removing Monal from the EU

#653

Earlier quoted context omitted.

How could this possibly be true? You claim to know a lot about the GDPR, I’m not sure my business is compliant. Can you take a look and tell me? What’s that called if not an audit?

An audit without certification will never give you anything that you could not have come up with yourself. So feel free to buy a GDPR audit but realize that you are just buying an opinion.

In the USA, the word "audit" is used to describe any process by which a company tries to determine if it's in compliance with some set of rules. Sometimes that process has special legal consequences, but it usually doesn't. The final deliverable is often literally called an opinion.

No lawyer or accountant has ever given me anything that I couldn't have come up with myself, with sufficient study. I still paid them, because the law is very complex and I have other things to do with my time. That's how any country with a nontrivial legal system works.

You seem to have great confidence that you understand how the GDPR will be enforced. I'd suggest that:

1. Not everyone knows as much about EU law as you do. This is especially true for people who don't live in the EU.

2. You might be wrong. Maybe GDPR compliance really is dead simple, and the lawyers who keep answering "it depends" are just cheating their clients; but from my experience in complying with similarly complex regulations, I wouldn't bet 20M EUR that's the case.

Re: GDPR: Removing Monal from the EU

#654

Earlier quoted context omitted.

Right... which is why this guy has decided this is no longer going to be his hobby in the EU. While the EU has every right to say 'those who do X for a hobby must do Y to comply' they cannot say 'everybody must have X for a hobby' or 'Bob must continue doing X for a hobby' .

The high-tech laws and regulations of the EU are a bit more sophisticated than in the US so it may take some time for the rest of the world to catch on.

Well, if anything, Europe has a history of labeling authoritarians as progressives. Whether that's something to be proud of is something history will decide.

Re: GDPR: Removing Monal from the EU

#655

Earlier quoted context omitted.

In the United States and under English common law, those giving away something for free are only liable for 'gross' negligence, which is a significantly lower bar than the implied warranties of merchantibility that will arise if you start charging. All these warranties can simply be disclaimed, by licensing the software correctly. > I'm not sure why people think software meant for use by a broad audience, however che…

Even in America, if a user can argue that their consent is uninformed you can still end up with a lawsuit. What's more, various states have different rules regarding that liability as well.

You're not wrong in this guy's case, especially since his software is on the App store. However, for most open-source projects, the installation process is sufficiently obtuse that you would be hard pressed to claim you were 'tricked' into installing it

Re: GDPR: Removing Monal from the EU

#656

Earlier quoted context omitted.

I'm not sure what it is you are arguing about. I am in 100% agreement that regulation is necessary for a functioning society. However, the natural result of introducing new regulation is that some businesses will choose to leave the market. This is the cost of doing business. If a society can bear the loss of the business from the market, then things are good. That's about all there is to it. > Another way of looking…

I'm sure such businesses exist. But this isn't one of them, the article writer is leaving his EU users for reasons all his own, as in: he made them up.

People are allowed to make up their own opinions, even ones not based in fact, and take actions on things they own regarding them. That is a fundamental human right, last time I checked.

Re: GDPR: Removing Monal from the EU

#657

Earlier quoted context omitted.

This seems as good a place as any to challenge some of the simplifications that are often given in defence of the GDPR. Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. Fair enough. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that d…

Thank you! This post starts to show some of the huge complexities that GDPR has for business and their understanding of what the terms of the law mean. A point is that often statements of a law are defined not by the language but by the ruling of lawsuits that occur around those statements and that is what most companies and lawyers are waiting for, what do courts rule when these lawsuits happen. The biggest issue th…

I think the parent's reply is a good one. We could probably debate some of the finer points, but I think when we get some time to see how it all shakes out in the end we'll have a better vantage point.

But to answer your question about the right to erasure, here is the law: https://gdpr-info.eu/art-17-gdpr/

I can't find it right now (and I have to get back to work), but there is a reasonableness requirement for requests. So things like backups might be covered by that. I wish there was some direction on that because it's a problem for me at work as well.

My opinion is that the directive's view is that all personal data retention should be temporary. There should be a defined point where the personal data is deleted. Either that's when it's no longer necessary for the contract, or when you no longer have a legitimate interest in it, or when the user asks for the removal.

Up to this point, most of us have been building databases with the intent of retaining the information indefinitely. So we never thought about this. Although I'm a fan of this law, I admit that it's going to be troublesome transitioning from where we were to where we need to go.

And as the parent briefly stated, immutable databases are going to be a serious problem.

Re: GDPR: Removing Monal from the EU

#658
post #647

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

I have started to think that parts of GDPR should have been restricted to large companies - e.g. anyone with more than 100k active users, data describing 100k individuals, or an organization employing more than 100 employees. That would seem like a fair way to protect privacy while keeping barriers low for tech ventures / experiments.

You can't block fire exits at small stores or large ones I see no reason to adopt your suggestions.

Re: GDPR: Removing Monal from the EU

#659
post #508

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Is safety a real concern here? I would have never viewed Kinder Eggs as dangerous in any way.

I haven't found a single case of a child getting hurt in Germany. Only news reports about them being unhealthy (big surprise).

Re: GDPR: Removing Monal from the EU

#660

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

>this guy sees the law and runs off without even trying to become compliant

This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here.

There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But these are real life things.

Post reply on HN