Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

851–860 of 957 posts

Re: GDPR: Removing Monal from the EU

#851

Earlier quoted context omitted.

> extremely shallow interpretation of the GDPR Please elaborate. I was unable to perceive the legal depth of interpretation. > you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away Businesses limit liability and legal exposure all the time. It's a tradeoff, as all things are.

> Please elaborate. As you wish: > I frequent Europe and do not want to get into legal trouble on vacation. There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here). Worst case you would be warned to become compliant, then if you persist in not being compliant you might b…

There's two kinds of "free service" on the internet. There's the Facebook / Google kind of free, where the herd of non-paying users is being aggressively monetised in other ways by a very profitable business. It's perfectly reasonable to expect this kind of free service to jump through the GDPR hoops as just another cost of doing business.

This is the other kind of free, where it genuinely is being done out of interests sake as a public service, like guerilla gardeners. In this case, it's perfectly reasonable to say that you got into this because you're interested in solving the technical challenges, not because you enjoy wading through bureaucratic rules, and decide to stop offering that free service in the EU because the fun has gone out of it.

Probably you're completely right about how easy complying would actually be, and in that case you could certainly take this code and run your own push server that serves EU clients.

Re: GDPR: Removing Monal from the EU

#852
post #833

Earlier quoted context omitted.

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

Perhaps more important, dpo is just another hat - if he's ceo,cfo,cto - he can be dpo too?

No, because you wouldn't be independent enough. A CFO or a CTO would tell its board things are okay because it isn't in its interest to do otherwise.

That's why some independent DPO jobs are appearing.

But the DPO is a small cog in the machine. Updating the processes is the most time and resource consuming regarding the GDPR.

Re: GDPR: Removing Monal from the EU

#853

Earlier quoted context omitted.

Because European courts and regulatory authorities are not run by gibbering morons. The Data Protection Directive was materially similar to the GDPR and was enforced by the same supervisory authorities. The DPD gave member states total discretion as to the level of fines, with no upper limit. I have found no evidence whatsoever of irrationally large or unreasonable fines under the DPD. You could be breaking the law i…

Well usually they aren't any kind of social or economic hubs, so I don't really worry if I can't enter or do business with north korea in my day to day life. The EU on the other hand... Also almost all laws stay in one jurisdiction, they don't go beyond their own country.

So your preferred way would be to have 28 different data protection laws?

Re: GDPR: Removing Monal from the EU

#854

Earlier quoted context omitted.

There's no "UK Interpretation", this is the whole point of the EU. The rules apply across the block.

EU law doesn't work like that. Each country has to pass their own local law to enforce the GDPR. For the UK that was the Data Protection Bill 2017.

I'm not sure why people are downvoting this so hard: https://webcache.googleusercontent.com/search?q=cache:eMV5_l...

Re: GDPR: Removing Monal from the EU

#855

Earlier quoted context omitted.

It is reasonable to assume overreach by governing bodies will occur; this is no less true for the EU than for any national government. The EU is no less likely to misuse that hammer, intentionally or not.

"It is reasonable to assume overreach by governing bodies will occur" No its not as they now have regulations in place to prevent that, before GDPR you could. You can only be sued to the poor house from it if you do something like leave your patients health information on the bus.

Even then you probably won't. If it's an incident that happened despite of having taken the necessary precautions, you would probably get only a small fine or a warning.

Re: GDPR: Removing Monal from the EU

#856

Earlier quoted context omitted.

It can be a privacy violation but the idea of a fundamental right to privacy is not universally supported like free speech. If it is a fundamental right, how far does it go? Should I be able to sue you for watching me walk in a public place? Photographing me? Video taping me? What about a privately owned but still public place? There are a lot of questions here that I think people tend to skip over about users owning…

I'm sorry, but I cannot buy the argument that this is in any way, shape, or form related to "free speech".

I wasn't trying to say it was - I was simply saying that when you base an argument on free speech, you don't have to explain why free speech is a good thing because it's generally accepted by everyone to be a good thing.

In this case, a lot of people base their argument on a fundamental right to privacy which is not generally accepted by everyone and therefore it has to be explained because it's an important part of the discussion.

Re: GDPR: Removing Monal from the EU

#857
post #806

Earlier quoted context omitted.

There is a big cost to regulating the internet and we know that. If the internet was regulated in the 90s we 'd still be watching Teletext.

In other words: "protecting people's rights is expensive, therefore we shouldn't do it". That's your argument? Really?

no it is not. please dont make strawmen

Re: GDPR: Removing Monal from the EU

#858
post #473

Earlier quoted context omitted.

Well whoever took the picture is the one that holds the copyright usually so it's more or less that person's data. Pictures probably aren't a good example because they are covered by intellectual property laws.

Then let's move on to credit card details. You gave them to me for payment purposes in the course of doing normal business. Months later, I discover that I can sell my stock of credit card information on the darknet for some nice extra income. Should I be allowed to do that? What if it weren't credit card details but just postal addresses?

Yes, you should be able to do that, unless you are reasonably certain that the information might be used to commit credit card fraud/identity theft.

If you think they might be used illegally, I believe there are already laws to charge you with that relate to facilitating a crime.

If you don't think they will be used illegally, then what's the harm in selling them to someone else?

Re: GDPR: Removing Monal from the EU

#859

Earlier quoted context omitted.

I guess if you have to ask that question you are not a large scale.

I don't think an argument of such kind would stand in your communication with regulators, or (especially) in courts.

This is "what will you do if the lightning strikes you" thinking. Only about less probable things.

Re: GDPR: Removing Monal from the EU

#860
post #369

Earlier quoted context omitted.

It can be a privacy violation but the idea of a fundamental right to privacy is not universally supported like free speech. If it is a fundamental right, how far does it go? Should I be able to sue you for watching me walk in a public place? Photographing me? Video taping me? What about a privately owned but still public place? There are a lot of questions here that I think people tend to skip over about users owning…

There are lots of laws against following someone and observing/recording every move they make. Making some observations out your window of cars passing by is something no one ever had a problem with. Taking down every single identifier you could and coordinating with others to track that person, for a profit, is something that would not be kosher in meat space. Why this different just because it's on a computer?

The laws you talk about are, I think, laws about stalking. I'm not aware of any laws that apply to that kind of thing if it happens on a massive scale. Singling someone out is an important part of stalking.

Keeping detailed information about everyone that enters your store isn't illegal, as far as I know. Especially not information that is gained from observation (what color shirt they're wearing, their IP address) and information that is submitted willingly (their name given for a reservation at a restaurant, their username).

Post reply on HN