Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

761–770 of 957 posts

Re: GDPR: Removing Monal from the EU

#761

Earlier quoted context omitted.

There's no "UK Interpretation", this is the whole point of the EU. The rules apply across the block.

EU law doesn't work like that. Each country has to pass their own local law to enforce the GDPR. For the UK that was the Data Protection Bill 2017.

From wikipedia:

The GDPR replaces the 1995 Data Protection Directive.[4] Because the GDPR is a regulation, not a directive, it does not require national governments to pass any enabling legislation and is directly binding and applicable.[5]

So, no local laws. It's a regulation.

Re: GDPR: Removing Monal from the EU

#762
post #576

Earlier quoted context omitted.

It's you. The original comment says 'The author of Monal misunderstands/misrepresents the regulation and is throwing a silly tizzy'. To which you say 'some laws ban some things. also, cheese is made of milk'. These things are true but not related to the GDRP or messengers.

... unsure if troll or just slow. parent was giving an example of how Monal isn't "throwing a silly tizzy" ... instead they have deemed the cost of complying with the regulations (all the items listed in the article) not worth the reward, much like how raw milk cheese companies decided to not sell in America because it was not worth the cost to comply (change practices, open different facility) with the regulations.…

There are literally no costs for complying if you sell or give away a messenger app, unless you're leaving everything unencrypted or collect tons of unrelated private data, too.

If they sell private information gathered from that messenger app to undisclosed third parties, then there may be additional costs of compliance.

Maybe this developer is complaining because he's running a nefarious business model? In that case it might indeed be easiest for him to shut down his business in the EU.

Re: GDPR: Removing Monal from the EU

#763

Earlier quoted context omitted.

"The French cheese makers could sort of comply, by pasteurizing their milk" And why should the French cripple a delicious and traditional product, which is gladly gobbled up by millions of happy consumers to sell their product in the US?

Because otherwise they can’t sell it there. Their country, their rules. A French cheese maker doesn’t get to dictate the rules abroad. Take it or leave it.

It seems to me that French and other European cheese makers are much more interested in protecting the integrity of their product than opening up the US market for it.

Re: GDPR: Removing Monal from the EU

#764

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

This seems as good a place as any to challenge some of the simplifications that are often given in defence of the GDPR. Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. Fair enough. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that d…

> But what if an online service's business model relies on processing profile data for purposes such as targeting ads to be viable, and regulators decide that a subject's right to object to that processing outweighs its necessity to the financial model?

forgive my frank language, but too fucking bad.

edit: my right always outweigh your profits. Sorry.

Re: GDPR: Removing Monal from the EU

#765
post #355

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some…

GDPR is not about annoying small businesses at all. First, to file a complaint one has to go through several steps, and the fine will be proportional to the offence. No small business owner will have to pay 20M€ for logging an IP (plus keeping IP logs are actually mandatory). Offenders will first be issued a reminder, then be fined if they don't comply after that. If you're a small business owner and you don't comply, then you can't complain.

Secondly and most importantly, GDPR is not about preventing people to get information, but rather about preventing people to track customer. If I use your example, GDPR would prevent you from following someone after they watched you juggling. It would prevent you from following them home, noting where they work, who are their acquaintances, what kind of food they eat and so on: it's technically legal but incredibly creepy. If someone were doing this to you you would be the one to tell them to piss off. You can perfectly write what are the observations of the passer-bys who watched you, as long as the log is anonymized. Which is easy to do and not harming for your business. You didn't want to track them anyway, did you?

Re: GDPR: Removing Monal from the EU

#766
How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?

Re: GDPR: Removing Monal from the EU

#767

Earlier quoted context omitted.

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

And "large scale" means how many records in DB? How many users? Or records per day?

Re: GDPR: Removing Monal from the EU

#768

Earlier quoted context omitted.

Thank you! This post starts to show some of the huge complexities that GDPR has for business and their understanding of what the terms of the law mean. A point is that often statements of a law are defined not by the language but by the ruling of lawsuits that occur around those statements and that is what most companies and lawyers are waiting for, what do courts rule when these lawsuits happen. The biggest issue th…

I think the parent's reply is a good one. We could probably debate some of the finer points, but I think when we get some time to see how it all shakes out in the end we'll have a better vantage point. But to answer your question about the right to erasure, here is the law: https://gdpr-info.eu/art-17-gdpr/ I can't find it right now (and I have to get back to work), but there is a reasonableness requirement for reque…

I think the UK agency had some text on erasure and backups, and it basically boiled down to this:

If a data subject requests their data to be erased, you should remove their data from active systems so that it is no longer being processed, but you don't have to remove it from backups or other passive systems. You should however store some sort of marker so that if you need to restore data from backups, the data subject's data will be re-erased or otherwise stopped from entering active systems again.

And if a data subject asks, you have to tell them how long you store your backups of their personal data.

I think that's perfectly reasonable. And if your backup retention policy is "forever", now might be a good time to re-evaluate that policy.

Re: GDPR: Removing Monal from the EU

#769

Earlier quoted context omitted.

> that means is you just can't blindly collect them Genuinely curious, what about all of the web servers that log every request which usually by default includes the client IP? Not doing anything special with the IP, they are just there in log files and archives.

Personally, I'll activate anonymization of ip addresses in my logs coming next week. There are various solutions for that available. I think you can also log the ip, you just have to get your user's explicit consent. I will also remove Google Analytics, and switch AdSense to contextual ads. I am a bit worried about the latter step, but if the losses are too great I can still try to get consent from my visitors and sw…

Google analytics has an option to anonymize the IP and remove unique user id from the data collection.

Re: GDPR: Removing Monal from the EU

#770

Earlier quoted context omitted.

> For small businesses it’s practically impossible to be in compliance for all laws. This is just ridiculous, patently false and making an excuse for reckless behaviour. Only specific laws apply to your business domain and if you aren't complying with them then you are wilfully breaking the law and putting your customers and the general public at risk. Own a cafe ? You should be cooking in a safe manner. Sell a car ?…

> Own a cafe ? You should be cooking in a safe manner. Almost no restaurants score a perfect 100% during food inspections. Many regulations understand that real life works on a gradient. That is why cars have varying safety standards that they have to meet based on their size and class, and why consumers can pay more for cars with a higher safety rating.

And that includes the GDPR
Post reply on HN