Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

321–330 of 957 posts

Re: GDPR: Removing Monal from the EU

#321
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

It's just A speculation about what it's directed at. We just can't take any chances given the steep fines.

Re: GDPR: Removing Monal from the EU

#322
post #99

You don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO. You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR). If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the use…

I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?

It really should be defined by company size or revenue. If I my site goes viral and a small web app suddenly has 2M lines of logs, but my revenue is small/non-existent, then there's no reason to comply. If that pushes my revenue over 1M euros a year, you now get pushed into a zone where you should be compliant, and you have enough revenue to afford it as well.

Re: GDPR: Removing Monal from the EU

#323

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

You could build and drive a car you built yourself with no regards for your personal safety - it's your car after all, and it's your business if you get injured. But could you sell such a car?

You could build and use a service with no regards for your personal privacy - it's your service after all, and it's your business if your data gets leaked. But could you offer such a service?

Re: GDPR: Removing Monal from the EU

#324

Earlier quoted context omitted.

Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.

No, you don't have to close at all. You just need to comply with the law, just like everybody else. You also need to file your taxes, keep the books in order, ensure that you do not pollute the environment, in some cases you need to be licensed in order to be able to practice your trade and so on. Why would this particular regulation suddenly cause you to close your business unless you were doing something really sha…

Perhaps it costs money to do so, and the company does not have enough working capital + lines of credit to make the payments necessary?

I feel like your statement here is basically "you are a business, therefore it is impossible for you to run out of money", which -- superficially -- seems very naive.

Re: GDPR: Removing Monal from the EU

#325

Earlier quoted context omitted.

Do I misunderstand this section: "Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal dat…

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

How do you know that a small company will only get warnings. I don't understand the source of your bravado. Perhaps it really is different from US.

Re: GDPR: Removing Monal from the EU

#326
post #111

Earlier quoted context omitted.

He's not monitoring the data. He's not handling sensitive personal data. He doesn't need a DPO. See also the derogation for micro companies: https://gdpr-info.eu/recitals/no-13/ > To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.

> He's not handling sensitive personal data. How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".

You can guarantee that because the messages aren't handled by the server: "Even though no message traffic passes through Monal’s sever".

Re: GDPR: Removing Monal from the EU

#327

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

This guy is not a small business. He's just a guy, doing this for fun, it seems.

Re: GDPR: Removing Monal from the EU

#328

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO).

This guy doesn't like regulation and is playing to the crowd for sympathy.

Re: GDPR: Removing Monal from the EU

#329

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

> extremely shallow interpretation of the GDPR Please elaborate. I was unable to perceive the legal depth of interpretation. > you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away Businesses limit liability and legal exposure all the time. It's a tradeoff, as all things are.

> Please elaborate.

As you wish:

> I frequent Europe and do not want to get into legal trouble on vacation.

There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here).

Worst case you would be warned to become compliant, then if you persist in not being compliant you might be fined, then if all that fails there might be a request for extradition but I highly doubt it would even get that far. Time will tell. What will definitely not happen is that out of the blue you will be yanked from your bed in Paris or Barcelona because you decided to refuse a request for deletion.

> The days of someone making something, putting it on the internet and offering it to the world seem to be over.

No, the days of harvesting data and building profiles without consent are over. You can make something just like you did last week and you can offer it to the world just fine. Do take care of your users data, be a good steward and try to do your best not to get hacked.

> do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.

The GDPR does not have this requirement for the kind of business the article writer has. No need to hire anybody. Pure nonsense.

> Tracking crashes with Crashlytics introduces new issues because it is posted to Fabric from a user’s device, IP addresses are in the logs this is personally identifiable information (PII). Crashlytics is GDPR compliant but the burden is on me to show regulators that I am compliant points back to the need for DPO.

Having a DPA in place with Crashlytics takes care of this, that's all the burden there is, in fact, Crashlytics most likely has a standard form for this because they will be entering into DPA's with a lot of companies in the next couple of weeks/months.

> Even though no message traffic passes through Monal’s sever, registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance.

Everything you do requires GDPR compliance but not everything is impacted by the GDPR. In this case logging the IP is fine, and then when you're done with the data you can get rid of it. No need to keep it indefinitely. And that simple trick: remove data that you no longer need is going to go a long way towards establishing GDPR compliance.

> APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person. However,the fact that it can be combined to identify a person makes it PII.

So do not keep it longer than you need it.

> I believe in privacy but I do not have the resources to meet the letter of the law for compliance especially with respect to retention and processing these tokens.

But he does have the time to write blog posts complaining about having to meet the letter of the law. That time would have been better spent actually reading the law and figuring out the impact.

> Honestly, I do not know if XMPP federation is legal anymore in the EU with GDPR.

Of course it is.

> EU user data is sent out of Europe constantly.

Indeed. And that won't stop because of the GDPR.

> GDPR is written such that a user cannot agree to a user agreement that gives up GDPR requirements it’s not a matter of saying you agree to X by using this service.

Yes, that's the whole point. You can't blackmail your users to opt-out of the law by virtue of withholding your product, which is a very very nasty way of trying to deal with a legal issue, rather than to face it head on and simply attempting to try to comply.

> GDPR compliance is something the XSF is talking about right now.

Good to see not everybody has the same attitude.

The way I read it this person is not trying to limit their liability, they're simply trying to pretend the law doesn't exist, have come to the conclusion that that won't fly and now blame the law for their laziness and negative attitude towards the privacy of their users in general.

If he really cared about the users privacy then he'd at least make a serious attempt. This blog post does not indicate a serious attempt was made, it reads like someone looking for excuses.

Re: GDPR: Removing Monal from the EU

#330

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Perhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?

If that was the case, no one outside the US could use VISA/MasterCard either (they enforce US laws on all international customers), or could make any business with any US company (even HN has to enforce the Iran embargo on all its international users).

If you want to criticize local laws applied internationally, abolish the US.

Post reply on HN