Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

161–170 of 957 posts

Re: GDPR: Removing Monal from the EU

#161
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

I suspect it's going to be a bit like IR35 in the UK. Menacing on first glance, but so broad in it's definition that any court is going to struggle to draw the hard conclusions for anything that isn't what the law was explicitly created to prevent.

Re: GDPR: Removing Monal from the EU

#162
post #56

Earlier quoted context omitted.

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

First of all, you're saying "core business". Is this even a business? And I copy-pasted direct text from the regulation. Note how it says "large scale". Twice. If he is actually processing personal data on a large scale, then maybe it is not unreasonable to have a DPO.

Is "large scale" defined?

Re: GDPR: Removing Monal from the EU

#164

Earlier quoted context omitted.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

"users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do"

I'll let that excerpt speak for itself.

And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary.

Re: GDPR: Removing Monal from the EU

#165

Earlier quoted context omitted.

One misconception about GDPR is that you can ignore it if your company is small. And that's basically what you're saying. And then the next would be that it's inexpensive to "make your case" if you get reported.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt.

The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

Re: GDPR: Removing Monal from the EU

#166
post #125

Earlier quoted context omitted.

You sure? Europe doesn’t have a stellar record when it comes to high tech startups. For many reasons. And I am afraid GDPR has just added another one.

> Europe doesn’t have a stellar record when it comes to high tech startups. For many reasons. For many reasons indeed, this is broad topic and GDPR doesn't change anything if we are talking about big US players and their domination. None of them is getting out of EU. > And I am afraid GDPR has just added another one. I disagree, it's the other way around. Small single person companies/developers that will get out fro…

I fail to see how adding another onerous regulation makes the EU founder more likely to succeed where the US founder decided to give up.

Re: GDPR: Removing Monal from the EU

#167

Earlier quoted context omitted.

So when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.

Ask the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance. https://ico.org.uk/for-organisations/guide-to-the-general-da... https://ico.org.uk/global/contact-u…

Point of order, the ICU is one of many potential regulators & likely not an important one given brexit.

What hav the Danish & Belgian regulators been doing lately?

Re: GDPR: Removing Monal from the EU

#168

You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.

From Article 37 GDPR:

(1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or ....

Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, ...

I would say that messages send via IM are personal data like described in Article 9. I also would check the "large scale" checkbox. So in my interpretation he will need a DPO.

Re: GDPR: Removing Monal from the EU

#169
post #27

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

The burden is if the EU does investigate him, for whatever reason whatsoever, even if he is 100% compliant he needs to spend money to prove he is compliant and deal with the EU.

As a North-American with no legal presence in the EU, how would he be 'investigated'?

Re: GDPR: Removing Monal from the EU

#170
post #21

Earlier quoted context omitted.

Do you think you're going to be slapped with a 20 million euro fine on day three?

how do I know that I will not be? that's the issue

Because European courts and regulatory authorities are not run by gibbering morons. The Data Protection Directive was materially similar to the GDPR and was enforced by the same supervisory authorities. The DPD gave member states total discretion as to the level of fines, with no upper limit. I have found no evidence whatsoever of irrationally large or unreasonable fines under the DPD.

You could be breaking the law in any number of countries. What steps are you taking to comply with the laws of Saudi Arabia or North Korea?

Post reply on HN