Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

841–850 of 957 posts

Re: GDPR: Removing Monal from the EU

#841

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Indeed, this did not drop out of the sky. It has been in the works for years. I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. My country's data protection agency made no attempt at raising awareness despite having my email address on file :-D It's only been frequently hitting non-EU industry news and places like HN since late 2017…

But you were obeying PECR (or the e-privacy directive), which came in around 2002, right?

Re: GDPR: Removing Monal from the EU

#843
post #716

Earlier quoted context omitted.

Also, needing to have a DPO is not difficult since he already has one employee, himself. It's not ISO2700x, you don't need to fiddle around with rights in small businesses to make sure it fits the narrow perspective of a standardization and exclusiveness.

The DPO cannot be himself.

He doesn't need a DPO.

Re: GDPR: Removing Monal from the EU

#844

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

Except in this case the Vogons already visited you 15 years ago to tell you about the e-privacy directive and 20 years ago to tell you about the data protection directives.

Re: GDPR: Removing Monal from the EU

#845
post #601

Honestly, most small USA businesses take one look at "Up to €20 million, or 4% annual global turnover – whichever is higher." and just run. There's no point in even trying to salvage the situation. > For the 3.7 million small businesses with 1 to 4 employees, the Census Bureau figures show average annual sales in 2007 were $387,200. Given that, who wants to risk a 20M fine? All this advice in this thread to do this,…

Please actually read the law before you try to argue with “as a...“. The fine scales with the violation and it does -surprise- not mean that arbitrary Github projects will have to pay 20m€...

The sentiment of a law doesn't always translate to the enforcement of it in practice

Re: GDPR: Removing Monal from the EU

#846

Earlier quoted context omitted.

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I guess I am a fan of GDPR, certainly compliance to anything has a cost. I personally don't find the costs of GDPR compliance onerous unless you have already built up lots of non compliant systems that now need to be fixed, in which case the free ride is over. Anyway, this guy is pulling out of the EU but if he allows anyone from the EU to use his service from a non-EU location anyway he would be risking non-complian…

no. gdpr applies only to people in the eu. if you are an eu person in canada it does not apply to you.

Re: GDPR: Removing Monal from the EU

#847

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

In many jurisdictions in the US, you can give away free home-cooked meals to homeless people without the requirement for a certified kitchen.

Some of my friends fought for the right to do so in Connecticut with Food Not Bombs, in fact.

Re: GDPR: Removing Monal from the EU

#848

Long story short: Monal developer doesn't understand GDPR, makes a bunch of incorrect claims about it, doesn't want to understand it, and so removes his software from the EU. That's his right, go him. He didn't have to write a ton of incorrect nonsense about the GDPR though. He could have just skipped to the last step. GDPR compliance is not actually that hard - I'm in the middle of doing it for a very large company…

If you're incorporated, there are crooks running around sending you threatening messages about the GDPR to make you buy their consultancy services.

I suppose the USers would call that "aggressive marketing".

I think this guy fell for it.

Re: GDPR: Removing Monal from the EU

#849
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> 9. Profiling activities always require consent: WRONG! Well that's a disappointment.

Well, it's wrong in the sense that profiling activities require a "lawful basis", consent is one of the possible lawful basis available.

So you can profile without consent IFF you can convincingly justify said profiling via one of the other lawful bases. But those won't really let you do blanket profiling willy-nilly either and come with other strings attached.

Re: GDPR: Removing Monal from the EU

#850
post #723
post #640

Earlier quoted context omitted.

Yes. You can sell alcohol to Saudi Arabians from Canada. You cannot ship to Saudi Arabia. The buyer may pick up in another location where alcohol is legal including in person in Canada. What they do with the alcohol once in their possession is their business.

In which case you are doing business with (say) France, which has its own alcohol customs laws that you have to follow. I never said that you have to follow the laws of the country of nationality of your clients. That'd be a ridiculous thing to say, and I'm not sure why you're arguing against that particular strawman (the GDPR only talks about EU residents and doesn't mention EU citizenship at all).

The word choice of citizen vs resident is a red herring. The issue is the extrajurisdictional reach of the law.

An EU resident visiting" your business which is hosted and operated in the United States, is the same as a Saudi Arabian coming to the United States to buy alcohol.

This is the reason why the GDPR requests an EU designated representative, so there is someone to charge locally.

Post reply on HN