Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

11–20 of 957 posts

Re: GDPR: Removing Monal from the EU

#12
I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.

Re: GDPR: Removing Monal from the EU

#14

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

That makes a valid point: You should open a bug with Apache to remove IP address and User-Agent from the default log formats, as they should not be logged by default or else GDPR issues arise.

Re: GDPR: Removing Monal from the EU

#15
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

When it's a one man show, you can't afford these kinds of unknowns. And by afford, I don't just mean monetary, I also mean mental costs, like your mind spinning at night wondering of the ways you might be harmed, or the ways you might develop a solution to the problem, etc.

Re: GDPR: Removing Monal from the EU

#16
> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.

A DPO is most certainly not required by all organisations[0], and I would be suprised if it applied to this project. I know lots of blogs are saying it is, but it is simply untrue. I'm not saying that this totally relieves the burden however.

[0]:https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: GDPR: Removing Monal from the EU

#17
>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.

>1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.

I thought this guy was a single person who put something on Github. How is he required to appoint a DPO? What kind of large-scale processing of personal information is he doing?

Re: GDPR: Removing Monal from the EU

#18
I'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement.

You certainly don't need to hire extra people like author suggests and federation should be just fine. (it's essential to what the service does)

Re: GDPR: Removing Monal from the EU

#19
Two questions come to mind:

1. Isn't this person allowed to be the Data Protection Officer themselves? 2. Is APNS inherently not compliant or if there something unique about this use-case?

What's kind of great about this new regulation is that we get a clear view on businesses that can't adequately protect user's privacy. It's painful for businesses such as these, but ultimately it seems that consumers would come ahead of it.

If the weak link in this case may not have been the developer themselves, but external factors but it's still a pretty interesting data point.

Re: GDPR: Removing Monal from the EU

#20
>... I frequent Europe and do not want to get into legal trouble on vacation.

Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that.

The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the Sherman Act.

Post reply on HN