Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

231–240 of 957 posts

Re: GDPR: Removing Monal from the EU

#231

Earlier quoted context omitted.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

I actually think it's entirely the other way round.

A small business or a startup should have a relatively limited amount of data capture, and that data should be stored in a relatively limited number of places. In most cases, it should be straightforward to make sure that this is documented and appropriate controls are in place.

On the other hand, large companies have vast quantities of uncontrolled data gathering that nobody is responsible for.

Re: GDPR: Removing Monal from the EU

#232

Earlier quoted context omitted.

How do you know that only Google and Facebook will have problems?

Just a personal risk I'm willing to take. I don't think they'll come for the small fish first.

You've made many concrete, general statements in this discussion which turn out to be relevant to your personal situation and your personal appetite for risk. Maybe that's not an effective way of holding a conversation about the general issues around the GDPR?

Re: GDPR: Removing Monal from the EU

#233
post #85

Earlier quoted context omitted.

"Allow removing it" is a pretty big barrier for many.

You can just do it manually... I have a feeling deletion requests will be pretty few and far between anyway.

I was going to say the same thing. If you're an individual running an OSS service, or a small business, requests for information or deleting information really are going to be really rare.

This really isn't a burden.

Re: GDPR: Removing Monal from the EU

#234
post #63

Earlier quoted context omitted.

UK is not the only country that can sue you under GDPR. What if Bulgaria decides 20 million sound pretty good?

Furthermore mark your callendar as 18 of march 2019 is when UK leaves EU and GDPR wont apply anymore.

No one in government has announced a plan to repeal the GDPR from UK law.

Re: GDPR: Removing Monal from the EU

#235
post #185
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

GDPR does not require deleting data from backups. http://blog.quantum.com/backup-administrators-the-1-advice-t... "The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations wil…

CNIL is one of ~20 regulatory agencies & this isn’t their “official” stance.

Other opinions have concluded that you must keep an index of requested deletes in the face of backups, for instance.

Re: GDPR: Removing Monal from the EU

#236
post #165

Earlier quoted context omitted.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

That's only the case if you store personally identifiable information in your logs. IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP. Plus, if you rotate out your logs and clean them up regularly, you don't really need to worry about it. (That's what the EU lawyers at my work told us.) Database backups are only a problem if you save them fo…

The GDPR faq disagrees: https://www.eugdpr.org/gdpr-faqs.html

Re: GDPR: Removing Monal from the EU

#237
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

I find your view very interesting. You have a very capitalist and US law based perspective on it. For one, not everything in a society needs to allow to "collect the fruits" of individual work (which is essentially capitalism). Europe has much more socialism mixed into their understanding of their societies than the US.

Further, the US law is based on risks of heavy punishments but few regulations, while the law in many parts of Europe is based on strict regulations but less high fines. It looks like the EU has too many rules, but that is a subject of perspective.

Problem here: The internet gives a shit about borders and society.

Re: GDPR: Removing Monal from the EU

#238
post #165

Earlier quoted context omitted.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

False. If you do any sort of logging of network traffic - think server logs - or even backup your database and a single person comes asking for all their data to be removed from all your backups sitting in cold storage, you're in for a world of hurt. The mere act of pulling all my database backups from glacier at once would cost enough to force me to just shut down my personal projects.

GDPR does not require you to delete PII from backups. This is a misconception.

You do need to have a documented and implemented backup retention policy and communicate this if you receive a request to delete a user's data.

Re: GDPR: Removing Monal from the EU

#239
I'm pretty sure lawyers and "consultants" are the only ones super happy about GDPR. Companies will still harvest user data with updated T&Cs and more buttons for the user to click, because all services will be useless without accepting. Governments will also continue gathering users' data for "the common good".

Re: GDPR: Removing Monal from the EU

#240

Earlier quoted context omitted.

issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.

I actually think it's entirely the other way round. A small business or a startup should have a relatively limited amount of data capture, and that data should be stored in a relatively limited number of places. In most cases, it should be straightforward to make sure that this is documented and appropriate controls are in place. On the other hand, large companies have vast quantities of uncontrolled data gathering t…

Spot on. The biggest problem cases are hospitals, banks, insurance companies, airlines and - funny enough - governments. They all hold mountains of data and the systems are old and in many cases no longer maintained by anybody that was there when the system was first created.
Post reply on HN