Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

801–810 of 957 posts

Re: GDPR: Removing Monal from the EU

#801

Earlier quoted context omitted.

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?

It's not defined. It was left intentionally ambiguous in the GDPR so member states have some flexibility in definition. I've got a call with a lawyer on Monday to clarify some bits of the GDPR. Number one Q for me is "how far can you take legitimate interests?". Some lawyers are advising that marketing data and usage falls under legitimate interest, in a way that these higes drives for consent seem unnecessary. If an…

> Some lawyers are advising that marketing data and usage falls under legitimate interest,

Even ICO says legitimate interests might be okay for some marketing.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: GDPR: Removing Monal from the EU

#802

Earlier quoted context omitted.

Personally, I'll activate anonymization of ip addresses in my logs coming next week. There are various solutions for that available. I think you can also log the ip, you just have to get your user's explicit consent. I will also remove Google Analytics, and switch AdSense to contextual ads. I am a bit worried about the latter step, but if the losses are too great I can still try to get consent from my visitors and sw…

Google analytics has an option to anonymize the IP and remove unique user id from the data collection.

Sure, not saying you can't use Google Analytics, just that my choice is to remove it.

Re: GDPR: Removing Monal from the EU

#803
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> It is cleary directed at large data-tracking corps,

Then the law should say that. For instance when India implemented uniform goods and services tax processes, it explicitly excluded businesses below a certain revenue threshold and gave them a simple % of gross alternative to all the processes. GDPR doesn't make any such distinction, so such decisions to drop EU support are to be expected.

Re: GDPR: Removing Monal from the EU

#804
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

If there is a complaint against my small software company, are there limits on how much I'm required to spend on defense? Do I have to travel to Europe to defend my company or will investigators from Europe travel to my location at their own expense? Will I be reimbursed for reasonable expenses if the complaint is groundless? Are there parts of the regulation that act like strong anti-SLAPP laws in some states? Can m…

> Can my small company be trivially bankrupted by any sociopathic gamer skid with an EU address and a grudge when DDOS attacks fail?

Your dude with a grudge can only lodge a complaint with the relevant regulatory entity, they're the ones who will verify whether you complied or not with his GDRP requests and if they deem that you are in violation fine you after negotiation fails.

This isn't the US: you can't be sued by random people for anything.

Re: GDPR: Removing Monal from the EU

#805
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> you can make your case What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.

If you don't want to follow the law you're welcome not to and will have to deal with the courts when they come knocking. This has always been true for all laws, not just GDPR. Try violating fiscal laws in the US just because "you don't want to deal with any of that" and let us know how well that works out for you.

Re: GDPR: Removing Monal from the EU

#806

Earlier quoted context omitted.

"What if you don't want to deal with any of that." What if you don't want to deal with the rules of the road?

There is a big cost to regulating the internet and we know that. If the internet was regulated in the 90s we 'd still be watching Teletext.

In other words:

"protecting people's rights is expensive, therefore we shouldn't do it".

That's your argument? Really?

Re: GDPR: Removing Monal from the EU

#808

Long story short: Monal developer doesn't understand GDPR, makes a bunch of incorrect claims about it, doesn't want to understand it, and so removes his software from the EU. That's his right, go him. He didn't have to write a ton of incorrect nonsense about the GDPR though. He could have just skipped to the last step. GDPR compliance is not actually that hard - I'm in the middle of doing it for a very large company…

> as long as you're not storing information about users it's almost trivial tbh

This is the part that most people seem to miss.

Re: GDPR: Removing Monal from the EU

#810

Earlier quoted context omitted.

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

It is reasonable to assume overreach by governing bodies will occur; this is no less true for the EU than for any national government. The EU is no less likely to misuse that hammer, intentionally or not.

These laws have been in place since 2016, they are going to start enforcing them starting the 25th. If you actually read anything about it from the source, it's clear it's setup against data abusers. It's not aimed at small businesses. If you don't do anything with user data, you don't even have to do anything. Like in the case of the OP. Aside from that, the EU doesn't have a history of overreaching/abusing power such as this. If this was US legislation your worries would be justified.
Post reply on HN