You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
Reading the FAQ, the only way to really safely ignore the DPO provision would be to hire a law firm with GDPR expertise to parse the vague language in the law and to give written guidance as to whether the law applies to each specific web site, which you can then present to EU authorities in the future to show you performed due diligence to try to meet the requirements of the law.
GDPR: Removing Monal from the EU
131–140 of 957 posts
Re: GDPR: Removing Monal from the EU
#132GDPR can be scary for developers, because nobody actually knows how a website or app is supposed to work (I have yet to see a single example), and it requires a series of steps that are not trivial on the administrative side. The Right to be forgotten is the easy part. Having to document everything you do and introduce data-dumping mechanisms that are both anonymous and secure is administrative burden. Having to do that for every little project that you release, even if it has 10 users, is a bit too much. Many developers cast a wide net, releasing products often, and this is practically unnecessary work unless you have a significant amount of users.
Introducing opt-in forms everywhere is also not great. It didn't work for Windows Vista so why do we expect this to work on the web? Opt-ins for things like cookies should be implemented on the browser. What's the point of warning a person before sharing their email? What's the point of warning them even you 'll install a cookie? IP addresses and cookies etc are integral parts of the HTTP protocol and the browser so why not introduce anti-tracking regulation that targets browser vendors and telcos instead of introducing regulation that targets every developer on the planet? It doesn't seem like an optimal plan imho. The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one.
It's easy for US developers to be positive of GDPR because they can avoid the overreaching parts, but for us in the EU its something we have to abide by 100% of the time. I 'd like to hear what other people think about those, because otherwise i hear a lot of emotional praise for GDPR which is blind to how problematic it is at day 0.
Re: GDPR: Removing Monal from the EU
#133Earlier quoted context omitted.
Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…
> If people named Jane are more likely to eat ice cream, you can't target ice cream ads at them and help keep your site free, without asking them. Apart from the fact that people named Jane aren't more likely to eat ice cream, you seem to criticize that it gets harder to target ads? Oh no, that's a real pity. Oh no, poor webmasters.
Why are the rights of people who own websites less important to you than the rights of other people?
Regardless, you might not still be saying this once half the websites smaller than Google become subscription-based in the EU or just block the EU altogether.
Re: GDPR: Removing Monal from the EU
#134Earlier quoted context omitted.
The op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.
No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.
Re: GDPR: Removing Monal from the EU
#135Earlier quoted context omitted.
> [...] Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask in extremely specific detail to do anything with some of that content, and that "consent" can be revoked at any time. You are saying that's a bad thing? Services that require you to sign up, should provide the possibility for users to look at, modify and delete their user data - th…
Yes, I'm saying that's a bad thing. Someone shouldn't have a right to come into my house and tear up a piece of paper in my drawer if I happened to write something about them on it. The problem is that there's no justification for having the right to coerce other people just because they have information you gave them. If users enter names into your website, you're not allowed to run a statistical analysis of what na…
Re: GDPR: Removing Monal from the EU
#136Earlier quoted context omitted.
But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.
> But it's not "their" data. It's the webmaster's data. No > It rightfully belongs to the webmaster. No, you are completely wrong here. The basic point of the legislation (and other privacy legislation in the EU that came before GDPR) is that a users personal data absolutely does not belong to the someone else once collected.
Re: GDPR: Removing Monal from the EU
#137Earlier quoted context omitted.
How do you know that only Google and Facebook will have problems?
Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.
Re: GDPR: Removing Monal from the EU
#138I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…
I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?
Re: GDPR: Removing Monal from the EU
#139Earlier quoted context omitted.
No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.
So when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
https://ico.org.uk/global/contact-us/advice-service-for-smal...
Re: GDPR: Removing Monal from the EU
#140Earlier quoted context omitted.
"Allow removing it" is a pretty big barrier for many.
Then don't keep it ? We're talking about chat.. you shouldn't be logging the contents, at most a bit of metadata to prevent abuse (eg. a connection log to identify and block spammers). If you don't store that metadata longer than needed (a couple of weeks? storing it for years would be hard to defend) you have legitimate reasons to keep it, and don't need to worry about deletion requests
The comment I replied to seemed to reference far more than chat.