Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

791–800 of 957 posts

Re: GDPR: Removing Monal from the EU

#791

Earlier quoted context omitted.

And "large scale" means how many records in DB? How many users? Or records per day?

These are excellent questions that you will have to have shown you've considered if you get audited. If there's disagreement with the regulator, you'll come together to resolve it, and then may need to appoint one.

Well, so it's undefined, at least until practice of legal application establishes. Undefined means risk, and stopping serving EU is a meaningful mitigation, if your profits don't compensate you for all the hassle. Where's "overreaction“ then?

Re: GDPR: Removing Monal from the EU

#792
post #639
post #480

Earlier quoted context omitted.

But OP is wrong. OP is saying GDPR is making it impossible for him to offer the software, but GDPR has almost no effect on him. OP can just rely on "legitimate interests", and describe the data they're processing and why.

Legitimate interests is not defined. So good luck with that. Also you are responsible for downstream guarantees of legitimate interest. He is right that open P2P protocols like XMPP, such as NNTP, IRC, bitcoin, ethereum, etc are not handled clearly. It is a headache for him I can sympathize.

> Legitimate interests is not defined. So good luck with that.

Are you expecting GDPR (or any law for that matter) to define an exhaustive list of every definition, that holds true now as well as for the future? Have a rethink about that statement...

Re: GDPR: Removing Monal from the EU

#793

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

I also don't understand this reaction, because the guy is the developer of a chat program. It seems that if you encrypt communications and user data and do not sell personal data to third parties, then you comply with the GDPR. I don't see where those bureaucratic hoops come into play this developer is bemoaning.

If he's already handling the data securely and only keeping the data necessary for the service (which I doubt but we'll never know) all he has to do is:

- Appoint a data protection officer (himself)

- Write down the processes of how he stores data (we keep it on this database, hosted at x provider; that provider is called the data processor) and how he deletes data whenever the subject of the data requires it.

That's it.

Re: GDPR: Removing Monal from the EU

#794

Earlier quoted context omitted.

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

It is reasonable to assume overreach by governing bodies will occur; this is no less true for the EU than for any national government. The EU is no less likely to misuse that hammer, intentionally or not.

"It is reasonable to assume overreach by governing bodies will occur"

No its not as they now have regulations in place to prevent that, before GDPR you could. You can only be sued to the poor house from it if you do something like leave your patients health information on the bus.

Re: GDPR: Removing Monal from the EU

#795

Earlier quoted context omitted.

And "large scale" means how many records in DB? How many users? Or records per day?

I guess if you have to ask that question you are not a large scale.

I don't think an argument of such kind would stand in your communication with regulators, or (especially) in courts.

Re: GDPR: Removing Monal from the EU

#796

Earlier quoted context omitted.

EU law doesn't work like that. Each country has to pass their own local law to enforce the GDPR. For the UK that was the Data Protection Bill 2017.

From wikipedia: The GDPR replaces the 1995 Data Protection Directive.[4] Because the GDPR is a regulation, not a directive, it does not require national governments to pass any enabling legislation and is directly binding and applicable.[5] So, no local laws. It's a regulation.

Only for the sake of correctness/completeness: GDPR does allow member states to adjust certain details to bring them in line with local regulations (see Chapter 9). These are explicit opening clauses though that must not basically weaken or augment GDPR.

Re: GDPR: Removing Monal from the EU

#797
post #19

Two questions come to mind: 1. Isn't this person allowed to be the Data Protection Officer themselves? 2. Is APNS inherently not compliant or if there something unique about this use-case? What's kind of great about this new regulation is that we get a clear view on businesses that can't adequately protect user's privacy. It's painful for businesses such as these, but ultimately it seems that consumers would come ahe…

This person doesn't need a DPO.

Re: GDPR: Removing Monal from the EU

#798
post #508

Earlier quoted context omitted.

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

Yup, Kinder Eggs have toys inside in the UK

Re: GDPR: Removing Monal from the EU

#799

Earlier quoted context omitted.

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

It is reasonable to assume overreach by governing bodies will occur; this is no less true for the EU than for any national government. The EU is no less likely to misuse that hammer, intentionally or not.

It's also reasonable to see what happened in the last 20+ years that there were DPAs already. I haven't seen overreach by them, did you?

Re: GDPR: Removing Monal from the EU

#800

Earlier quoted context omitted.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

Is a single person running an app as a hobby a business? If I want to put an open source app in the App Store, that’s not a business model for me. It’s more just personal expression.

Your personal expression is writing the open source software and putting it on GitHub. However, once you make it available as a service, you should be responsible for it.
Post reply on HN