Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

891–900 of 957 posts

Re: GDPR: Removing Monal from the EU

#891

Earlier quoted context omitted.

The threat of being suspended from the EU and the (potential) economic damage from that? You can’t be a dictatorship and keep the same rights in the union, as per the Copenhagen criteria and Article 7. [1] https://en.wikipedia.org/wiki/Copenhagen_criteria#Political_... [2] https://en.wikipedia.org/wiki/Article_7_of_the_Treaty_on_Eur...

And Russia considers itself to be a democracy. There's a big gray zone between good government and a self-admitted dictatorship. Smart modern authoritarians know that they need to maintain the pretense of democracy (for reasons like the one you note), and they do a passable job--look at something like Cambodia. That's what makes tools to exert personal power while still complying with the law as written so important.…

Because otherwise some companies might conclude that it is cheaper to continue to violate the law and simply to pay the fine. See Volkswagen, which got fined billions for violating the law (and rightly so), and they're still in business and have not withdrawn from the markets where they were fined. But it looks as if they did learn their lesson (for the next 30 years or so, this wasn't the first time they got caught with something like that).

Re: GDPR: Removing Monal from the EU

#892
post #756

Earlier quoted context omitted.

That's not exactly a new insight, Richelieu beat you to that one a couple of centuries ago. But that's just trying to stretch what we are discussing here: that it is possible to comply with the law in principle. That some overzealous prosecutor with a grudge could nail you might happen - in Russia, maybe even the USA. But frankly where I live I have not yet seen a case like that. We probably have them but not frequen…

Have you been running a socially controversial business? That's where the specifics of the law start to really matter. The butcher, baker and candlestick maker have little to fear from the most badly drafted of laws; it's the person running a skate park or gay bar in a small town who tends to be on the sharp end.

> Have you been running a socially controversial business?

For about 20 years, yes.

Re: GDPR: Removing Monal from the EU

#893
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

By law it is enforceable and directed at any entity that tracks European data. There is no clause the limits GDPR to large companies, just like there is no clause that limits or restricts fines outside of the 4%/20M number.

It would be entirely possible for someone to not be compliant with a side project and get fined 20M because there is nothing that explicitly forbids this it is entirely up to interpretation.

Given that US companies have already been targeted in the EU, unfairly [1], I find that law terrifying because I have to trust regulators that don’t have my best interests in mind with possible penalties that are very high.

[1] https://www.treasury.gov/resource-center/tax-policy/treaties...

Re: GDPR: Removing Monal from the EU

#894

Earlier quoted context omitted.

I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. Likewise. This idea that the GDPR has been in the works for years so it's somehow implausible that very small businesses have only just heard of it doesn't stand up to scrutiny. No owner-run microbusiness is spending the time necessary to keep up with the vagaries of EU debates. Simi…

Thank you for perfectly describing the frustrations I have experienced with GDPR. As the owner of a small SaaS business in the US I don't have the time to follow various EU regulations that closely. I only found out about GDPR earlier this year from a random HN comment. I can't understand the attitude from some HN commenters that everyone should have known about this for years. Where/how should every small business t…

You know what? i'm pretty sure you can just talk to one of the european regulator in advance and ask him questions about points you don't understand. They are pretty slow but they do respond.

Re: GDPR: Removing Monal from the EU

#895
post #839

Earlier quoted context omitted.

"The study, which looked at ads run on member networks during 2009, showed that among users who clicked on a behaviorally targeted ad, 6.8% converted. That compared with only 2.8% of those who clicked on a run-of-network ad." https://www.emarketer.com/Article/Behavioral-Targeting-Doubl...

No one's arguing that the targeted ads don't make more money. We are arguing that the extra value from the ads is not worth violating everyone's privacy.

A quote I heard recently is "Some of you may die, but it's a sacrifice I'm willing to make." That's what the tone towards small businesses/websites in relation to GDPR sounds like to me. I can't understand valuing this right to the "privacy" of not having your (often anonymized) identity tied to a marketing profile so much that you'd rather some free small websites no longer exist and others move to subscriptions.

Re: GDPR: Removing Monal from the EU

#896

Earlier quoted context omitted.

> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.

> Being the sole owner and manager and being the DPO is clearly a conflict of interest. Could you clarify why you think this is so? As an owner, my interests would align with the DPO's interests so it's hard to me to find where the conflict of interest would reside in the case of being the sole employee _and_ DPO. Now if it's a large company where they make money per GDPR policy workaround then I could see it being r…

No, as an owner your interests do not necessarily align with the DPO. They might, but they do no necessarily.

Re: GDPR: Removing Monal from the EU

#897

Earlier quoted context omitted.

Sorry, but do you want to say that EU has no left and right in politics (parent post did not mention Democrats or Republicans)? Or that everyone in the EU is unanimously happy with GDPR? Seriously, if a law's getting applied only after a long while it's passed - it's not unheard of to have a debate as people start to actually care. Maybe I'm wrong, but I think that parent example is not US-specific at all and is appl…

First of all, come on, obviously I'm not saying there are left and right in EU politics (and in the national politics of EU countries), but what those left and rights are concerned with don't match 1:1 with the issues under debate in American politics. Partly because there is a much broader political spectrum -- Democrats in the US roughly line up with, for example, the Conservatives in the UK or the CDU in Germany -…

You probably haven't looked then. Despite assumptions elsewhere, I'm from Europe and still live there for example. The idea that everyone loves GDPR is naive. Only today I was working next to someone who was trying to figure out how it applied to her (tiny) business, and getting annoyed by the process. She's just copy/pasting the contents of an email she received into her own mail copy to avoid having to do extra work.

Nothing about GDPR has to do with "obedience to technocratic elites"

No? I think you missed by points then.

The GDPR was created, is enforced by and serves the interests of regulators. It specifies so little it is essentially a direct grant of power to those people - they can do whatever they want within its framework and that framework allows nearly anything.

As for 'technocratic elites', did you see political parties campaigning on this issue? I sure as heck did not. Right now the hot topics in European politics are immigration, terrorism and economic growth. Not data protection.

is in fact about rejecting the ability of institutions which are not democratically accountable to gather personal data and monitor people

Of course companies are democratically accountable - outside of monoplies (rare), you can just not trade with them if you don't like their data handling practices.

Re: GDPR: Removing Monal from the EU

#898
post #776

Earlier quoted context omitted.

Article 7 doesn't seem to mean anything does it? Spain just crushed a political movement trying to organise a referendum through force. It arrested the leaders and the rest of the EU is helping them catch the ones that fled. They call it a rebellion and state that Catalonia can never be independent. Not an Article 7 violation, apparently. According to the EU it's merely an internal matter. Hungary elects a government…

You are trying to justify a coup. A coup by a minority of the population that has a distorted view of history as a result of years of astroturfing. So if applying the law is "crushing a political movement", let's crush it all the way. Nobody is above the law.

I didn't actually take sides or try to justify anything, just pointed out the contrast.

However a coup is a military overthrow of a government. What the Catalonians tried to organise is a vote, not a coup.

Re: GDPR: Removing Monal from the EU

#899
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

If there is a complaint against my small software company, are there limits on how much I'm required to spend on defense? Do I have to travel to Europe to defend my company or will investigators from Europe travel to my location at their own expense? Will I be reimbursed for reasonable expenses if the complaint is groundless? Are there parts of the regulation that act like strong anti-SLAPP laws in some states? Can m…

Well, in europe, it work like this:

(1)A random person complain to his regulator that you are not complying with GDPR. If he asked for his personal data, jump to (3)

(2) His regulator contact you, tells you that wht you're doing is bad: you have some stuff in opt-out, not clicking "opt-in" cause a degradation of service, or you are sending him 3rd party cookies he did not accept.

(3) Depending on the complexity and your ressources, you have X months to comply.

(4) You got caught again, you are fined.

Re: GDPR: Removing Monal from the EU

#900
post #571

Earlier quoted context omitted.

> The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one. It is an utter failure but mostly because services try hard to turn it into a travesty and simultaneously manage to deceive their users by attributing blame for the annoying cookie warnings to regulators. "We are required by law to show you this stupid warning because our site u…

But how would you handle logins without cookies? How would you know that a customer has already agreed not to allow cookies without a cookie?

I don't think you need to get explicit agreement when using cookies to implement expected site functionality, as long as you don't use re-purpose them for profiling/targeting purposes. IANAL, though.

See: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm#se... (starting at "Howewer, some cookies are exempt …")

Post reply on HN