Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

861–870 of 957 posts

Re: GDPR: Removing Monal from the EU

#861

Earlier quoted context omitted.

Even if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...

I don't think he can. The DPO may not be assigned any tasks that would result in a conflict of interest between their role as a DPO and their other responsibilities. I suspect that means that the sole proprietor can't be the DPO. But, you know, not a lawyer, not even European, could be wrong. See article 38, paragraph 6, 2nd sentence.

Sole proprietor has to be the DPO in that instance.

Re: GDPR: Removing Monal from the EU

#862
post #189

Earlier quoted context omitted.

Maybe companies that are so flimsy didn't have long left anyway. You're required to have a fire safety officer at these companies too, but it's not a full-time position.

> You're required to have a fire safety officer at these companies too, but it's not a full-time position. AFAIK, most of the "safety committee" regulations usually have waivers for small companies.

Well that's terrifying...

Re: GDPR: Removing Monal from the EU

#863
post #814

Earlier quoted context omitted.

Why not? I have yet to see anyone arguing for data protection legislation actually give a reason that they think a users data belongs to the user.

Equifax.

The Equifax breach was already illegal - I assume you mean you think that websites shouldn't keep user information to prevent future data breaches.

This is a bad solution to that problem. So many people's data was stolen that preventing future data from being stolen isn't the most important thing we should be doing. Last I heard it was 150 million people - that's enough that it no longer really matters to the average person if their data is leaked in the future because there's such a high change it already has.

The real solution is to change our systems so that data leaks aren't a big deal. If people didn't ask for a 9 digit number to identify me, as if that's a reasonable thing to keep secret, then it wouldn't matter if everyone in the world knew it. That's the problem with data breaches like this. That's what we should be fixing in response to it.

Re: GDPR: Removing Monal from the EU

#864
post #643

Earlier quoted context omitted.

No. It is quite definitely not true that you must comply with the laws of countries you are not in. The EU is primarily leveraging the fact that most everyone wants to travel to the EU eventually. While you in your home country you have no need to comply with the GDPR unless a treaty between your home country and the EU exists to mandate it. The EU is also leveraging their trade agreements. What they don’t understand…

The U.S. has been doing this for decades, applying U.S. laws to global citizens who happen to travel to the U.S, and I'm not even talking about kidnapping foreign citizens and taking them to Cuba.

You need to travel to the US. They are applying laws domestically.

The US is quite opposed to extrajurisdictional law enforcement which is why they don’t sign onto things like the International Criminal Court.

Re: GDPR: Removing Monal from the EU

#865
post #629

Earlier quoted context omitted.

You don’t need a lawyer to comply with the law is a weird statement to put out there. You should retract.

What? I don’t need a lawyer to tell me I can’t go out and steal someone’s wallet. It’s perfectly possible to comply with the law without one.

Well, the difference is that theft is a natural law. We are born with an instinct it is wrong.

Having a data processing officer in the EU for some definition of significant business is not a natural law and requires careful parsing of the legal text.

Re: GDPR: Removing Monal from the EU

#866
post #789
post #640

Earlier quoted context omitted.

Yes. You can sell alcohol to Saudi Arabians from Canada. You cannot ship to Saudi Arabia. The buyer may pick up in another location where alcohol is legal including in person in Canada. What they do with the alcohol once in their possession is their business.

Selling to Saudi Arabians and selling to Saudi Arabia are two entirely different things. In one you're doing conducting business in the Saudi Arabian market, and therefore under the umbrella of their government and in the other you're conducting business in whatever market the person you're selling your alcohol is located at, and under the umbrella of that market's laws.

When an EU business buys a service from an American operating in America from their website hosted in America how is this materially different than when a Saudi Arabian citizen visits New York and buys alcohol?

Why would Saudi law apply in New York?

Re: GDPR: Removing Monal from the EU

#867
post #639

Earlier quoted context omitted.

Legitimate interests is not defined. So good luck with that. Also you are responsible for downstream guarantees of legitimate interest. He is right that open P2P protocols like XMPP, such as NNTP, IRC, bitcoin, ethereum, etc are not handled clearly. It is a headache for him I can sympathize.

> Legitimate interests is not defined. So good luck with that. Are you expecting GDPR (or any law for that matter) to define an exhaustive list of every definition, that holds true now as well as for the future? Have a rethink about that statement...

Yes. I do expect that. It is a reasonable expectation that the laws are clearly understandable by those subject to the laws.

Just as companies need to be specific about how they use data now the legal-judicial system needs to be specific about what it means and intends.

It is a double standard because the legislators are not interested in the commercial impact.

Re: GDPR: Removing Monal from the EU

#868

Earlier quoted context omitted.

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

You are correct as to a DPO, but if he is, say in the US, and subject to GDPR, he must have an EU Representative, who by all indications would be liable for his violations. That's a significant burden if not a practical impossibility for most in his position. Also, if he's transferring personal data from the EU to the US directly from individuals, his only practical way of making that transfer compliant is likely to be privacy shield certified which is not cost free (although he could maybe rely on consent as a derogation, but relying on that has risk). I can think of many things like this that have, if not a hard cost, then a definite cost in time and resources to comply including keeping up with compliance. Could easily be not worth the effort for a single individual.

Re: GDPR: Removing Monal from the EU

#869

Earlier quoted context omitted.

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

And "large scale" means how many records in DB? How many users? Or records per day?

A UK privacy attorney I know considered 20k records (individuals) to be large scale. I haven't seen much helpful guidance. The WP29 guidance I've read only gives examples at the very extremes of large and small so not too helpful. Practical guidelines will evolve over time.

Re: GDPR: Removing Monal from the EU

#870
post #719
post #645

Earlier quoted context omitted.

That is not true. You do not need to comply with any country’s laws except the one you reside in, except for treaties by your home country that say otherwise or your desire to travel abroad. Just think of what China would do to the Internet if it could.

> You do not need to comply with any country’s laws except the one you reside in. Unless you want to business with another country, in which case you need to follow the laws of that country when you conduct that business. Which is what I've been saying the whole time. > Just think of what China would do to the Internet if it could. If you want to provide a service to China you need to follow Chinese laws or they will…

When the business is being conducted outside the EU but the EU is enforcing GDPR, it is a problem. The GDPR is specifically written for extrajurisdictional enforcement which is a big change in the world of laws.

I am just saying that the EU will not be the only jurisdiction following this model. Be prepared.

Post reply on HN