Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

281–290 of 957 posts

Re: GDPR: Removing Monal from the EU

#281
post #8
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Directed or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.

If a company’s margins are so razor thin that they can’t compete (with other regulated companies), then they may want to rethink their business model.

Re: GDPR: Removing Monal from the EU

#282

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

the laws you refer to preexisted. Did they tear down all the houses that don't comply with contemporary building standards? I dont think so. GDPR is enforced retroactively on everything since the beginning of the internet.

Re: GDPR: Removing Monal from the EU

#283
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

BetOnSports, an AIM listed UK company took sports bets over the internet, including from US customers: > In July 2006, their then-CEO, David Carruthers, was arrested while changing planes in Texas on the way to Costa Rica from the U.K. In April 2009 he pleaded guilty to federal racketeering charges, and in January 2010 was sentenced to 33 months in prison.

Reading through the indictment, it appears that BetOnSports was actively (and repeatedly) advertising within the US. I feel there's a rather clear line between operating in one jurisdiction and merely accepting customers from overseas , vs. actively seeking out customers and doing business in a jurisdiction where your activities are illegal -- I'm not sure I would categorise it as "completely legal in the jurisdiction you are based in" when you are deliberately doing business, and spending money, in another jurisdiction.

Re: GDPR: Removing Monal from the EU

#284

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.

No, you don't have to close at all. You just need to comply with the law, just like everybody else. You also need to file your taxes, keep the books in order, ensure that you do not pollute the environment, in some cases you need to be licensed in order to be able to practice your trade and so on.

Why would this particular regulation suddenly cause you to close your business unless you were doing something really shady?

Re: GDPR: Removing Monal from the EU

#285

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Building codes vary vastly in quality.

Some prevent loss of life.

Some are pointless or even harmful to society. HN complains constantly about insufficiently dense housing....a situation caused by none other than building codes.

When possible, build in places with good codes, not bad ones.

Re: GDPR: Removing Monal from the EU

#286

Earlier quoted context omitted.

Note that I didn't say IPs aren't PII; I said they don't count as long as you are collecting them for the specific purpose of security and don't have any way to identify the person using that IP. Pretty much by definition that is not PII. That came from the legal departments from our German, UK, and French entities.

PII is not the standard for GDPR compliance.

That's correct, but PII is what the person I replied to was talking about.

Re: GDPR: Removing Monal from the EU

#287

Earlier quoted context omitted.

Corporate veil piercings happen a lot more when your a small or one man shop, and officers can often be directly liable for the actions of the company. It's not as bulletproof as you think.

But the usual requirement for piercing the corporate veil is that the owner/operator of the business is using the business with the sole reason of insulation from having their private assets in the line of fire. If the business is otherwise legit and a fine were levied against the business there would be a fairly strong barrier before the assets of the shareholder become part of the story. A good precaution against t…

IANAL, but that is not the requirement I've heard. It is perfectly valid to insulate one's other assets from corporate creditors. One must voluntarily commingle those assets with corporate assets in order to justify a piercing. It's not always obvious to the careless what will constitute commingling, but this is kind of the point of corporations.

Frankly this post has prompted me to reevaluate your other legal advice in this thread.

Re: GDPR: Removing Monal from the EU

#288

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

He is meeting the required standards... by not having an EU users. In doing that he's as equally compliant as any company who has jumped through the various GDPR hoops.

And has made his business that much less viable, and opened himself up to competition from a company with a comparable product that does comply with the law.

And maybe one day the USA will pass some privacy legislation...

Re: GDPR: Removing Monal from the EU

#289

Earlier quoted context omitted.

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

> A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). They don't do safety inspections in the US? Doesn't the vehicle need to have brakes, a means to change direction, emission checks and so on?

TIL in some states they do emissions checks (although in a lot of states motorcycles are totally exempt from those anyway). And no, they don't do safety inspections of "specially constructed vehicles". And based on the ones I've seen, I can't imagine a world in which they'd pass. [1]

[1] http://bosshoss.com/supersport-bike/

Re: GDPR: Removing Monal from the EU

#290

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Perhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?
Post reply on HN