Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

681–690 of 957 posts

Re: GDPR: Removing Monal from the EU

#681
post #99

You don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO. You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR). If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the use…

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?

It's not defined. It was left intentionally ambiguous in the GDPR so member states have some flexibility in definition.

I've got a call with a lawyer on Monday to clarify some bits of the GDPR. Number one Q for me is "how far can you take legitimate interests?".

Some lawyers are advising that marketing data and usage falls under legitimate interest, in a way that these higes drives for consent seem unnecessary.

If anyone else has any questions, I can ask and feedback. I'm sure I'll have those questions too.

Re: GDPR: Removing Monal from the EU

#682

Earlier quoted context omitted.

He is a 1 person team. Given him a break vs. being so aggressive in your comment. There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. All these things don't drop from the sky. And they are a business. And as a business they have decided to get out of Europe as th…

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

[deleted]

Re: GDPR: Removing Monal from the EU

#683

Earlier quoted context omitted.

This is the furthest thing from true, like almost every single question about this terrible law. Vague law + faceless bureaucracies + universal application + crippling penalties...sounds like a brilliant combo to destroy people’s lives.

as usual, the rebuttal is: there have been this kind of laws in Europe for a decade. For example, if you're operating in Italy and don't provide 2 separate checkboxes for managing personal data directly and indirectly at sign up time you're in breach of the law. Do you remember many people's lifes crippled by this?

It's certainly true that even before the GDPR, almost any nontrivial business could reasonably be argued to be violating some mostly-unenforced law. I don't see that as a reason to shrug, and make the problem one step worse.

Selective enforcement of commercial law is a routine tool of unfree states--look at something like the tax charges against The Cambodia Daily. To trust in regulatory discretion is to trust that no government in the EU--a continent that within living memory hosted Francisco Franco, Giorgios Papadopoulos, and much worse--will ever be run by people you disagree with. In the extreme, a dictator can always ignore or rewrite the law; but somewhere in the slide from our present democracy to that, I don't think it's unimaginable that the GDPR could be abused.

I support privacy regulation. I don't see why it requires us to abandon the rule of law.

ETA: Downvote if you trust Viktor Orban, I guess? I'm presuming a strong case of "it can't happen here"....

Re: GDPR: Removing Monal from the EU

#685
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

Younneed a DPO if you 10 employees or more. Fornhiavcase, he most likely just needs to update his privacy policy and have a form to collect users requests (like TypeForm) and make sure that he handles them (event if it's manually deletion in database).

Re: GDPR: Removing Monal from the EU

#686

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

GDPR compliance takes resources. I would say for a small business it takes about 1 or 2 days. Not hard work but tedious. In the end you will have around 5 documents that will show your processes, what you do to keep data save, a plan how you deal with questions from customers and regulators, that you trained your employees and that you choose your subs carefully.

Essentially that's it.

I am no lawyer but I am a CPO.

Pro tip: Speak with the regulators they are on your side.

Re: GDPR: Removing Monal from the EU

#687

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings.

So, for example, he says he is required to appoint a DPO.

The U.K. Information Commissioner has this to say:

>Do we need to appoint a Data Protection Officer?

A> Under the GDPR, you must appoint a DPO if:

> you are a public authority (except for courts acting in their judicial capacity);

> your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking);

> * or your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.

Re: GDPR: Removing Monal from the EU

#688

Earlier quoted context omitted.

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?

Possibly but they are not "sensitive data" (aka "special categories of personal data"). Article 9 of the GDPR outlines what these special categories are: "personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, [...] genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concernin…

Oddly, GDPR gives 3 reasons why you would need a DPO:

1. you're a public authority (NHS practices are an example)

2. Large scale processing

3. Large scale processing of sensitive data

They don't specify what large scale means. They also haven't specified how sensitive data qualifies the third statement. One can assume the threshold is lower but the GDPR doesn't specify any thresholds with regards to this.

Re: GDPR: Removing Monal from the EU

#689
post #392

Earlier quoted context omitted.

Schufa (the biggest consumer credit reporting agency in Germany) and article 35 can certainly co-exist. In fact you can write to Schufa and request that they delete all your data. However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that.

> However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that. How does that work for people who never had a Schufa history? If for instance I decided to move today from Brazil to Germany, would I be unable to do all these things there, since they would have "no…

The reports for people who are just new in the system and for people who had their data deleted by request are different.

Re: GDPR: Removing Monal from the EU

#690

Earlier quoted context omitted.

Thank you for those detailed links. They are kind of eye opening, and I am German. However, it is hard to understand how stuff like GEZ, Schufa and article 35 can exist concurrently in the same country.

Schufa (the biggest consumer credit reporting agency in Germany) and article 35 can certainly co-exist. In fact you can write to Schufa and request that they delete all your data. However, if you do that, good luck ever getting a mortgage, credit card or other post-paid services ever again if all credit report requests come back with the reponse "no data available". So I wouldn't recommend that.

There are thosuands of horror stories how the Schufa isn't able or willing to correct wrong data. And no data protection agency in Germany did ever brought such a case to a court.
Post reply on HN