Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

201–210 of 957 posts

Re: GDPR: Removing Monal from the EU

#201

Earlier quoted context omitted.

Yup, I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases. But, yeah, I'm not a lawyer too. Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion) > CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO?​​​ > Yes. However, you must ensure that other professional duties of this emp…

> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.

> Being the sole owner and manager and being the DPO is clearly a conflict of interest.

Could you clarify why you think this is so? As an owner, my interests would align with the DPO's interests so it's hard to me to find where the conflict of interest would reside in the case of being the sole employee _and_ DPO.

Now if it's a large company where they make money per GDPR policy workaround then I could see it being required another person than the owner, but it could still certainly be an employee.

Re: GDPR: Removing Monal from the EU

#202
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

That's only the case if you store personally identifiable information in your logs. IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP. Plus, if you rotate out your logs and clean them up regularly, you don't really need to worry about it. (That's what the EU lawyers at my work told us.) Database backups are only a problem if you save them fo…

I spent near to $10,000 in 6 lawyers 2 in usa 4 in different european countries and all wrote detailed report for me negating what you just said. IP is one of the most PII identifiable elements of an internet user. Exception is when you can prove such IP is a merely a proxy. please get some other lawyers opinion!!

Re: GDPR: Removing Monal from the EU

#203
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

> The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects. Okay: when you were writing this, you must been either drunk, you forgot how easy it is to find your projects via your HN profile and general googling, or you simply don’t have a single enemy out there who is waiting to hurt you/your business. I hope all of it together!!

My only still active side project to which this applies isn't open for public registration yet, and I fully intend to completely block the EU before going live.

Re: GDPR: Removing Monal from the EU

#204
post #27

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

The burden is if the EU does investigate him, for whatever reason whatsoever, even if he is 100% compliant he needs to spend money to prove he is compliant and deal with the EU.

Why would you think that? If he wanted to be compliant he only needs two things:

1. Some procedure that allows him to answer users privacy requests ("what information about me do you have?", "Please delete my personal data from your servers.")

2. A so called "directory of procedures" which states what data you collect and who's responsible for it.

If your fail to comply with 1. the user can call upon their local data protection agency who will contact you and request the contents of 2..

At no point would he need a lawyer or spend money, even if he were based in the EU. That's not saying it's a bad idea to ask a lawyer for advice if you do handle lots of user data.

Most of this stuff has been law in Germany for years, I've dealt with the German data protection agencies many times (from both sides of the aisle).

- They helped me force my university remove personal information about me from the public uni website (by constructively explaining to them why it's a bad idea to have this information about student online in the first place).

- When someone trolled me by registering me to a dating platform which refused to delete the fake profile and spammed me for a year, one mail to the agency was enough to stop these idiots.

- When I worked with social workers, the data protection agency (after a client accused us of mishandling their data) helped us go through our communication procedures and identified some point where client privacy could easily be improved.

As a US company, if you don't want to deal with this, just don't. If you do handle user data you should, though.

Re: GDPR: Removing Monal from the EU

#205

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?),…

I think you're lumping together too many things.

> I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. > All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data.

What if I didn't want you to visit my website. Sure, by the letter of the law I am collecting PII (your IP address) but I think I can reasonably argue that it's quite a technical feat for a private layperson to go from "sudo apt-get install apache2" to "removing IP addresses from log files".

Sure, this is tongue in cheek - but most of that panicking I read was people concerned about their personal websites, especially with the "might be taken as professional work stuff just because of ads or you're blogging about tech as a tech freelancer.." - didn't really hear anyone with a company panic.

Re: GDPR: Removing Monal from the EU

#206
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> you can make your case

What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.

Re: GDPR: Removing Monal from the EU

#207

Earlier quoted context omitted.

> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.

If you're Zuck or anyone working for FB, that'd be true. But what if one of my interests in running my company is the protection of my users' data?

Can you imagine yourself trying to convince a regulator of that?

Re: GDPR: Removing Monal from the EU

#208
post #63

Earlier quoted context omitted.

Please take the assurance from the 'horses mouth' instead. The ICO is the UK body responsible for policing this. Their site is simple and in plain English. https://ico.org.uk/for-organisations/guide-to-the-general-da...

UK is not the only country that can sue you under GDPR. What if Bulgaria decides 20 million sound pretty good?

Furthermore mark your callendar as 18 of march 2019 is when UK leaves EU and GDPR wont apply anymore.

Re: GDPR: Removing Monal from the EU

#209

Earlier quoted context omitted.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.

Do I misunderstand this section: "Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal dat…

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopholes were found so this is the hammer. As a small company, if you answer and act on actual user complaints, you have no worries no matter what the language. It is not in their interest to go for small offences. And if your story is reasonable, like OP, they will just let it go.

What this gives the EU is the hammer to hit persistent abusers of user data. They want you to be careful with user data and not treat it like you own it; you do not. It is not yours to sell or share or publicize.

Edit; note as well that every country has a compliance office; if they know you are in complaince as in you are ‘good people’ (best effort, no giant holes etc; just best practice in our field which you should do anyway) they will not bother you with every (or any) user complaint after that. I have good experiences with this with far grave (and potentially criminally punishable) matters in a few EU countries.

Re: GDPR: Removing Monal from the EU

#210
post #99

You don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO. You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR). If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the use…

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous.

Are 1 million IPs in my logs 'large scale'?

Post reply on HN