Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

671–680 of 957 posts

Re: GDPR: Removing Monal from the EU

#671

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Bovril could easily comply. They would simply have to open a manufacturing facility that did not use UK beef. The French cheese makers could sort of comply, by pasteurizing their milk. Kinder, I admit, has a more difficult problem, and has, in fact attempted to comply, by creating a completely different product with the same name.

"The French cheese makers could sort of comply, by pasteurizing their milk"

And why should the French cripple a delicious and traditional product, which is gladly gobbled up by millions of happy consumers to sell their product in the US?

Re: GDPR: Removing Monal from the EU

#672

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

I agree with you, but in this particular case, it seems to be a free chatting app, not a revenue-making business. From the looks of it, I think the author's motivation for writing and maintaining this are ideological, to provide privacy to users. "This app has no ads, no user behavior tracking and all messages are exchanged directly with the XMPP chat server". Doesn't look like a business to me.

https://itunes.apple.com/us/app/monal-free-xmpp-chat/id31771...

Re: GDPR: Removing Monal from the EU

#674

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

It's a reasonable action based on shifting tides and uncertainty, particularly for a project with no revenue to speak of. If the EU wants to do arbitrary things, that's on them.

Re: GDPR: Removing Monal from the EU

#675
This makes little sense. There is nothing in the GDPR that you shouldn't already have done. Besides, even if you don't operate in the EU, it makes sense to have a basic privacy setup anyway, and GDPR compliance is just that...

https://gdprchecklist.io (was on HN a few days ago IIRC)

On top of that, this isn't american lawyering. If you make a mistake or are simply trying but not having a good time at it, you're not automatically destroyed, put in jail, fined for billions of euros etc.

The GDPR is beneficial to everyone, except people with bad intentions or bad practises (like having big budgets for PR, Ads and the CEO but not for tech).

The GDPR for basic FOSS and other single-person software boils down to:

- Don't capture data and not ask first - Don't capture data and not tell - Don't capture data and now show - Don't capture data and not say where it is - Don't capture data and not say who can access it - Generally, users should be able to CRUD their data - Delete data on request - Export data on request

Most of that is common sense and in most non-commercial services this is available anyway. You can make it even simpler:

- Only CRUD when a user CRUDS and tell them that is what they are doing while they are doing it - Make sure the delete/opt-out/close account button actually works - Have a line somewhere saying "i'm hosting this on platform XYZ in country ABC"

Since you are likely going to build CRUD + delete account anyway, that's a solved problem. Unsubscribe/Delete account usually already exists, no problems there either. That leaves writing a few lines telling users where you are storing stuff and how to contact for issues.

Don't forget: laws comparable to the GDPR were already in effect long before the EU came up with a EU-wide version. In the UK for example, you could ask a business to send an export of all the data they have on you via mail, and they were bound by law to comply. In the netherlands, if you store PII of people who are not your clients and send them mail/spam/offers, you get fined. Hell, they even had a more universal version where you aren't allowed to put mail in someone's mailbox unless it was addressed specifically to them, and there was one where you weren't allowed to put any ads in if the mailbox was marked for that. And you have a system where cold-calling was not allowed, same for fax-ads.

Re: GDPR: Removing Monal from the EU

#676

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

> For small businesses it’s practically impossible to be in compliance for all laws. This is just ridiculous, patently false and making an excuse for reckless behaviour. Only specific laws apply to your business domain and if you aren't complying with them then you are wilfully breaking the law and putting your customers and the general public at risk. Own a cafe ? You should be cooking in a safe manner. Sell a car ?…

> Own a cafe ? You should be cooking in a safe manner.

Almost no restaurants score a perfect 100% during food inspections.

Many regulations understand that real life works on a gradient. That is why cars have varying safety standards that they have to meet based on their size and class, and why consumers can pay more for cars with a higher safety rating.

Re: GDPR: Removing Monal from the EU

#677
You CANNOT, by any means, consider an IP address to be "personal data". You cannot say "I don't want my IP to lay around in a database somewhere" because ... IT IS NOT YOUR IP. An IP address is used to uniquely identify a device on a network, not a person. This device can be (and usually is) a router, a proxy, a server of some kind, a corporate computer, a public computer and so on. Not to mention the fact that a device can also have multiple IP addresses at the same time. So, an IP address CANNOT be used to uniquely identify a person and it really shouldn't be considered in the context of GDPR. Ah, an IP address + some other identification data, that's another discussion. Depending on the combination, it might be considered personal data.

Re: GDPR: Removing Monal from the EU

#678

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

I'm not following your distinction. The only difference seems to be timing.

Case 1: CompanyA is already doing business in CountryB. CountryB changes regulations. CompanyA pulls out of CountryB because of regulations

Case 2: CountryB has regulations. CompanyA choose not to do business in CountryB because of regulations

am I missing something?

Re: GDPR: Removing Monal from the EU

#679

Earlier quoted context omitted.

He is a 1 person team. Given him a break vs. being so aggressive in your comment. There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. All these things don't drop from the sky. And they are a business. And as a business they have decided to get out of Europe as th…

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years.

VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star system and, regrettably, your planet is one of those scheduled for demolition. The process will take slightly less than two of your Earth minutes thank you very much.

MANKIND: [Yells of protest]

VOGON CAPTAIN:

There’s no point in acting all surprised about it. All the planning charts and demolition orders have been on display at your local planning department in Alpha Centauri for fifty of your Earth years so you’ve had plenty of time to lodge any formal complaints and its far too late to start making a fuss about it now.

From "Hitchhiker's Guide to the Galaxy" by Douglas Adams

sorry I couldn't resist

Re: GDPR: Removing Monal from the EU

#680

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

The only problem I see here is needing data based on contract obligations, I have seen lots of sites packing the data collection into privacy policy or some shady contract, thinking that this is legitimate interest. But legitimate interest is actually the hardest part of GDPR, even if most people think it is a workaround. If you can provide the service without some personal data (not due to financial claims) you can't pack those under "better user expirience" as legitimate interest. I presume, that after 25th, google will stop tracing searches for EU users for example. Legitimate interest has a long recital behind it and is a real problem to do it right unless legalislation requires the data. I would stick to consent for everything else. Just mentioning.
Post reply on HN