Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

311–320 of 957 posts

Re: GDPR: Removing Monal from the EU

#311

Earlier quoted context omitted.

You are making a claim to one of 2 things: - the ip addresses never uniquely identify someone or - you have a legitimate interest to collecting this data. Neither provides carte blanche for collecting IP address.

I'm actually saying that both are a requirement for logging IPs in the circumstances being discussed here, but I certainly don't mean to suggest that either would grant you "carte blanche" to collect and log IPs.

I suspect that logging IP only for security purposes is fine, but the idea that it is a bulletproof defense is just wrong, we have no idea. Current indicators are that regulators think IP is personal & that legitimate interest defenses are suspect.

Re: GDPR: Removing Monal from the EU

#312

Earlier quoted context omitted.

If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.

Is a single person running an app as a hobby a business? If I want to put an open source app in the App Store, that’s not a business model for me. It’s more just personal expression.

> If I want to put an open source app in the App Store, that’s not a business model for me. It’s more just personal expression.

Try convincing a regulator of that.

But it doesn't matter, you're still logging PII. GDPR doesn't make any distinction of profit vs. non-profit vs. personal ownership. You're as liable as an individual as an organization.

Re: GDPR: Removing Monal from the EU

#313

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Why not compare it with heart surgery while you are at it.

Re: GDPR: Removing Monal from the EU

#314

Earlier quoted context omitted.

IANAL, but that is not the requirement I've heard. It is perfectly valid to insulate one's other assets from corporate creditors. One must voluntarily commingle those assets with corporate assets in order to justify a piercing. It's not always obvious to the careless what will constitute commingling, but this is kind of the point of corporations. Frankly this post has prompted me to reevaluate your other legal advice…

My exposure to this is limited to cases in Europe and ones that I was a direct witness to and in all those cases it was pretty clear that the company was created with the express purpose to commit bankruptcy fraud and the result was the owner of those companies lost his shirt. All other attempts to pierce the corporate veil that I've seen failed.

Presumably that fraud involved assets that belonged to the corporation (or were represented to creditors as such) being transferred outside the corporation to other entities controlled by the owner? That will pierce. Imagine instead someone who builds a store in a location with insufficient commercial traffic and whose corporation fails for that reason alone: her creditors can't take away her house, her retirement account, or some unrelated business.

Re: GDPR: Removing Monal from the EU

#315

Earlier quoted context omitted.

I keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. That person doesn't own those bits on that hard drive.

They don't own the bits. They own the data those bits represent. The person/company who does own the bits has to comply with the rights of the owner of the data. How you decide to store it makes little difference as long as it's digital. Fun aside: if you store it on paper you're not beholden to GDPR. Crazy.

They don't own the data either.

Think about. A person doesn't own the random bits (data) about them that goes through and is stored on various systems they interact with. Under the GDPR in the EU, they might have a right to know what is stored about them on various systems, but they don't "own" that data.

That's impossible and doesn't make sense.

Re: GDPR: Removing Monal from the EU

#316

Earlier quoted context omitted.

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

Well, the "appropriate indicators" would need to meet the "required standards" mentioned in the parent post. I think the example is ok.

The indicators are a tiny subset of the actual requirements involved in a production vehicle. In fact, there are examples of European production cars that can't be street legal in the US, and the companies involved chose to simply not sell them here. Smart cars were impacted by this for awhile (no crumple zones), they eventually dealt with the problem though, and as I recall there was a production ferrari that couldn't be driven here because ferrari chose to simply not sell in the US rather than conduct two crash tests or something like that. Can't recall the details.

Re: GDPR: Removing Monal from the EU

#317

Earlier quoted context omitted.

You can be respective of privacy without complying with GDPR. It requires a lot more than simply being privacy-conscious. (E.g. I don't think Hacker News is doing anything unethical even though they blatantly violate GDPR) > Legal compliance is a requirement for any business You are required to comply with the laws of your country, not those of other countries.

If you are not doing anything shady, if you have your house in order security wise and if you do not collect data that you have no use for you are 95% there. The remainder will maybe require consultation with a lawyer for an hour or two if you want to play it safe but you could also simply wait for a few months to see how it all plays out. If you are respectful of other people's privacy then there is very little chan…

> then you will be warned to become compliant long before you will be fined

citation needed

> if you do not collect data that you have no use for you are 95% there.

I have always been respectful and even never required emails on signups. I am not 95% there because there is a ton more to do. In fact i am at 5% because i have a lot of small scale past projects. Not everyone is a VC-funded startup.

That's the kind of emotional reaction that everyone has to GDPR. Yes we like respecting privacy, it's a good thing, but there is a lot that is problematic with this legislation.

Re: GDPR: Removing Monal from the EU

#318

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

No need to be snarky - you do have a good point that can stand on its own. However the issue is not black and white. And just because you think the GDPR is a step forward, some people disagree. Even the Monal guy might agree with you - he just doesn't think it is worth it. And why wouldn't we expect strictly enforced food safety regulations to prevent meals being shared? It might be worth it, but it doesn't mean ther…

My comment is not intended to be snarky. I am aware that it sounds otherwise and I thought about adding a few more sentences to counter that, but there is just not much I have to add, it would just make the comment longer. So I decided to keep it short even if it might sound a bit snarky hoping that everybody is able to infer that I wanted to say that this is not some unique burden thrown at software developers but that we were some kind of exception not having to deal with that much regulation as other industries.

Re: GDPR: Removing Monal from the EU

#319
post #60

Please be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

There doesn't need to be a GDPR opt-out. They just need to ask for permission to use the data.

Re: GDPR: Removing Monal from the EU

#320
post #111

Earlier quoted context omitted.

Monal is an XMPP chat system. User's messages are user data, and everything it does is processing that data, in the form of broadcasting it. I suppose as long as the data doesn't count as "very large", that'd be fine, but what does very large mean?

He's not monitoring the data. He's not handling sensitive personal data. He doesn't need a DPO. See also the derogation for micro companies: https://gdpr-info.eu/recitals/no-13/ > To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.

For some reason, I can't reply to Max_aaa's question directly.

> How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".

You guarantee it by reading the rest of GDPR. It defines sensitive personal data separately than personal data. Sensitive personal data is defined by GDPR to be things that can be used to discriminate against the individual, such as race, ethnicity, religion, health information, credit information, age, etc.

EDIT: And what I mean to say is that if the messages aren't passing through the server or being stored on the servers, then the only info being handled by the server is the meta-data including IP address, which is not included in GDPR's definition of _sensitive_ personal data.

Post reply on HN