Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

711–720 of 957 posts

Re: GDPR: Removing Monal from the EU

#711

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

Well many of us find it completely normal to spend days on having a good security, setting up HTTPS, encrypting content to protect privacy. I wonder why GDPR seems so different, it's just more of the same, just less technical.

Re: GDPR: Removing Monal from the EU

#712

Earlier quoted context omitted.

My wording was awkward, but I think the meaning is clear. "...in the EU--the union of countries primarily located in a continent that..." ? And what am I missing? They were dictators of Spain and Greece respectively. There are millions of people who can remember their rule alive in those EU countries today. What changed in the last fifty years to make a recurrence impossible? Turkey narrowly missed joining, and it's…

The threat of being suspended from the EU and the (potential) economic damage from that? You can’t be a dictatorship and keep the same rights in the union, as per the Copenhagen criteria and Article 7. [1] https://en.wikipedia.org/wiki/Copenhagen_criteria#Political_... [2] https://en.wikipedia.org/wiki/Article_7_of_the_Treaty_on_Eur...

And Russia considers itself to be a democracy. There's a big gray zone between good government and a self-admitted dictatorship. Smart modern authoritarians know that they need to maintain the pretense of democracy (for reasons like the one you note), and they do a passable job--look at something like Cambodia. That's what makes tools to exert personal power while still complying with the law as written so important.

Why do you think the GDPR needs to give the government that much power? For a simple example: Why is 20M EUR the right statutory maximum? If the regulators would never enforce it, then why does it need to be so high?

Re: GDPR: Removing Monal from the EU

#713
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

Indeed and TBH when the part about Crashlytics made me glad about GDPR (although the rest of the message does indeed sound like an overreaction). I do not like when applications i use try and do things that are irrelevant to what the application is all about, especially when these "things" involve communicating through the internet and even more so when i am not informed about it.

I think it's a weak argument to suggest that crash reports are not "what the application is about" it contributes to the ongoing development and stability of an application which you use.

That said I do think there should be an expectation that your participation in crash reporting would be voluntary and explicit.

Re: GDPR: Removing Monal from the EU

#714

Earlier quoted context omitted.

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

That's the UK's interpretation of GDPR. What about France or Poland, or any of the other countries?

I suppose it depends where in Europe he would like to visit

Re: GDPR: Removing Monal from the EU

#715
> I do not have the resources to meet the letter of the law for compliance especially with respect to retention and processing these tokens.

Harsh words but I feel they're warranted: If you don't want to treat my private data with the due diligence you should, then we're better off not using your service.

Re: GDPR: Removing Monal from the EU

#716

Earlier quoted context omitted.

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

Yeah, but the analogy is not good... * We've known about the GDPR for around 2 years. * The GDPR text, national regulators' comments, industry opinion, sample docs and a plethora of free resources have been readily accessible on the Internet for about the same length of time. Having worked on the GDPR docs for a medium-sized business that builds learning management systems for corporate customers (about 100 live syst…

Also, needing to have a DPO is not difficult since he already has one employee, himself. It's not ISO2700x, you don't need to fiddle around with rights in small businesses to make sure it fits the narrow perspective of a standardization and exclusiveness.

Re: GDPR: Removing Monal from the EU

#717

Earlier quoted context omitted.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

> For a startup or small company, the cost is prohibitively high. Nonsense. I look at another high tech data driven start-up every week and not a single one has stated that the GDPR costs are 'prohibitively high'. Sure, there are some that need to do more work than others (medical, ad tech). But on the whole companies that were already doing their best to not fuck up with their customers data have very little to do i…

I'd go as far as saying that if you responsibly handled data before GDPR, what you have to do to be GDPR compliant is document the process and make it possible to delete data upon request.

Re: GDPR: Removing Monal from the EU

#718

Earlier quoted context omitted.

I'm sure such businesses exist. But this isn't one of them, the article writer is leaving his EU users for reasons all his own, as in: he made them up.

People are allowed to make up their own opinions, even ones not based in fact, and take actions on things they own regarding them. That is a fundamental human right, last time I checked.

As is calling them out for it (e.g. if they are not based in fact), which is all jacquesm does. That's also a "fundamental human right"

Re: GDPR: Removing Monal from the EU

#719
post #645
post #489

Earlier quoted context omitted.

> Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. This has never been true since the internet was international. You have always had to comply with laws of countries you interact with, it's just that most people who ran internet businesses decided to ignore the law (just try hosting some copyright or patent infringing content on the internet and see…

That is not true. You do not need to comply with any country’s laws except the one you reside in, except for treaties by your home country that say otherwise or your desire to travel abroad. Just think of what China would do to the Internet if it could.

> You do not need to comply with any country’s laws except the one you reside in.

Unless you want to business with another country, in which case you need to follow the laws of that country when you conduct that business. Which is what I've been saying the whole time.

> Just think of what China would do to the Internet if it could.

If you want to provide a service to China you need to follow Chinese laws or they will block you using their firewall. China is a (not very nice) example of how a country has the right to decide who it does business with -- if you won't help them conduct surveillance of their citizens then they won't do business with you and will block you from doing business with their people. You might not agree with their laws or how they act, but it is their right as a sovereign nation to create their own laws.

I never said you need to follow the laws of every country in the world, and I really don't understand how so many people are reading that out of what I said (and keep saying). If you want to do business with a country you will have to obey the laws of that country. That's the way international trade has always worked.

Re: GDPR: Removing Monal from the EU

#720
post #420

Earlier quoted context omitted.

Perhaps having legitimate purpose for data collection in the first place helps.

Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?

They struggle with it for the same reason people on the political left always struggle to understand why some people oppose new regulations: the question of whether and how to regulate commercial activities is always a proxy for deeper underlying differences in how people view the world. GDPR is just a proxy fight between the left and the right and is showing all the same characteristics.

Consider adventured's sibling post - it quite astutely points out that GDPR discussions are much more vitriolic than you'd expect for discussions of the minutiae of data handling. People who say that GDPR compliance is hard are being attacked on a personal level. He explains it as 'emotional investment' in GDPR but I don't think that's a good explanation; the people arguing most strongly for it are also those saying it's not much work, so that seems backwards. You'd expect people who put in the most effort to be most emotionally invested in it.

There's a much better explanation available: your view on GDPR is a direct consequence of your assumptions about human nature. If you believe in the existence of benign and enlightened technocrats then GDPR seems like excellent progress towards building a better world - it's extreme vagueness and severe penalties are exactly what's needed to foster obedience to technocratic elites. People who complain about this are just being unnecessarily awkward ... just be reasonable after all, and you'll be fine! The EU are reasonable so if you're reasonable too, you have nothing to fear! From this perspective, anyone who objects to GDPR or actually decides compliance is impossible must - almost by definition - be being unreasonable. What are they hiding? Why can't they just get on board; the only answer available is that they have flawed characters and any points they make about gray-area debatable things like cost:benefit ratios must be some sort of obfuscation.

If on the other hand you believe the whole idea of wise and beneficent bureaucrats is naive, then GDPR looks like a hell of a lot like a power grab by the very sort of people who shouldn't be able to grab power. Vagueness is of deep concern because it's in the shadows of vagueness that abuse can be found, and when a law is nothing but vagueness, it even makes sense to question to motives of those who created it - that's a problem because lots of self-styled Europeans have bought into the EU's utopian rhetoric and can't separate criticism of the EU from criticism of themselves and their desired future.

There's no real scientific way to prove whose assumptions about human nature are right. The USSR was a rare example of a real-life experiment in who was right and for a long time it proved the American style, conservative, small weak government is better mentality to have superior results. But that was decades ago and many have forgotten or weren't alive back then, so now rule by technocratic dictatorship seems attractive again.

As a consequence GDPR discussions will always have the same flavour as Clinton v Trump debates, or Brexit debates, or whether to restrict spending on political campaigning. They are ultimately about the same issues.

Post reply on HN