Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

131–140 of 957 posts

Re: GDPR: Removing Monal from the EU

#131
post #61

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

Reading the FAQ, the only way to really safely ignore the DPO provision would be to hire a law firm with GDPR expertise to parse the vague language in the law and to give written guidance as to whether the law applies to each specific web site, which you can then present to EU authorities in the future to show you performed due diligence to try to meet the requirements of the law.

I can only think you are not familiar with European principle based law vs US rule based law. Where you see 'vague', I see 'flexible' and 'able to move with the times'

Re: GDPR: Removing Monal from the EU

#132
While this developer may be overreacting (he probably doesn't need a DPO), i understand why it might just be easier to block it , at least until there are precedents about how to comply and more info on how the regulation will be enforced.

GDPR can be scary for developers, because nobody actually knows how a website or app is supposed to work (I have yet to see a single example), and it requires a series of steps that are not trivial on the administrative side. The Right to be forgotten is the easy part. Having to document everything you do and introduce data-dumping mechanisms that are both anonymous and secure is administrative burden. Having to do that for every little project that you release, even if it has 10 users, is a bit too much. Many developers cast a wide net, releasing products often, and this is practically unnecessary work unless you have a significant amount of users.

Introducing opt-in forms everywhere is also not great. It didn't work for Windows Vista so why do we expect this to work on the web? Opt-ins for things like cookies should be implemented on the browser. What's the point of warning a person before sharing their email? What's the point of warning them even you 'll install a cookie? IP addresses and cookies etc are integral parts of the HTTP protocol and the browser so why not introduce anti-tracking regulation that targets browser vendors and telcos instead of introducing regulation that targets every developer on the planet? It doesn't seem like an optimal plan imho. The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one.

It's easy for US developers to be positive of GDPR because they can avoid the overreaching parts, but for us in the EU its something we have to abide by 100% of the time. I 'd like to hear what other people think about those, because otherwise i hear a lot of emotional praise for GDPR which is blind to how problematic it is at day 0.

Re: GDPR: Removing Monal from the EU

#133

Earlier quoted context omitted.

Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…

> If people named Jane are more likely to eat ice cream, you can't target ice cream ads at them and help keep your site free, without asking them. Apart from the fact that people named Jane aren't more likely to eat ice cream, you seem to criticize that it gets harder to target ads? Oh no, that's a real pity. Oh no, poor webmasters.

>Oh no, that's a real pity. Oh no, poor webmasters.

Why are the rights of people who own websites less important to you than the rights of other people?

Regardless, you might not still be saying this once half the websites smaller than Google become subscription-based in the EU or just block the EU altogether.

Re: GDPR: Removing Monal from the EU

#134

Earlier quoted context omitted.

The op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

Do I misunderstand this section: "Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation." That sounds like you can be sued by any subject on their whim?

Re: GDPR: Removing Monal from the EU

#135

Earlier quoted context omitted.

> [...] Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time. You are saying that's a bad thing? Services that require you to sign up, should provide the possibility for users to look at, modify and delete their user data - th…

Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…

The point of GDPR is to switch collecting users’ personal data from being a benefit to being a liability. That will absolutely cause short term pain to some companies that hadn’t expected this, but it ends up as a long term benefit to society, the same as most legislation.

Re: GDPR: Removing Monal from the EU

#136

Earlier quoted context omitted.

But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.

> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

Re: GDPR: Removing Monal from the EU

#137

Earlier quoted context omitted.

How do you know that only Google and Facebook will have problems?

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

Even though that's a personal risk you're willing to take, it might not be one everyone else is willing to. One might question a law that asks everyone to take risks (or pay/pray for peace of mind).

Re: GDPR: Removing Monal from the EU

#138

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

> no, only larger orgs handling lots of personal data need this.

I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?

Re: GDPR: Removing Monal from the EU

#139

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

So when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.

Ask the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

https://ico.org.uk/global/contact-us/advice-service-for-smal...

Re: GDPR: Removing Monal from the EU

#140
post #91

Earlier quoted context omitted.

"Allow removing it" is a pretty big barrier for many.

Then don't keep it ? We're talking about chat.. you shouldn't be logging the contents, at most a bit of metadata to prevent abuse (eg. a connection log to identify and block spammers). If you don't store that metadata longer than needed (a couple of weeks? storing it for years would be hard to defend) you have legitimate reasons to keep it, and don't need to worry about deletion requests

> We're talking about chat..

The comment I replied to seemed to reference far more than chat.

Post reply on HN