There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
GDPR: Removing Monal from the EU
321–330 of 957 posts
Re: GDPR: Removing Monal from the EU
#322You don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO. You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR). If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the use…
I'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?
Re: GDPR: Removing Monal from the EU
#323While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…
Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…
You could build and use a service with no regards for your personal privacy - it's your service after all, and it's your business if your data gets leaked. But could you offer such a service?
Re: GDPR: Removing Monal from the EU
#324Earlier quoted context omitted.
Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.
No, you don't have to close at all. You just need to comply with the law, just like everybody else. You also need to file your taxes, keep the books in order, ensure that you do not pollute the environment, in some cases you need to be licensed in order to be able to practice your trade and so on. Why would this particular regulation suddenly cause you to close your business unless you were doing something really sha…
I feel like your statement here is basically "you are a business, therefore it is impossible for you to run out of money", which -- superficially -- seems very naive.
Re: GDPR: Removing Monal from the EU
#325Earlier quoted context omitted.
Do I misunderstand this section: "Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal dat…
That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…
Re: GDPR: Removing Monal from the EU
#326Earlier quoted context omitted.
He's not monitoring the data. He's not handling sensitive personal data. He doesn't need a DPO. See also the derogation for micro companies: https://gdpr-info.eu/recitals/no-13/ > To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.
> He's not handling sensitive personal data. How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".
Re: GDPR: Removing Monal from the EU
#327This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
Re: GDPR: Removing Monal from the EU
#328This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.
This guy doesn't like regulation and is playing to the crowd for sympathy.
Re: GDPR: Removing Monal from the EU
#329This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
> extremely shallow interpretation of the GDPR Please elaborate. I was unable to perceive the legal depth of interpretation. > you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away Businesses limit liability and legal exposure all the time. It's a tradeoff, as all things are.
As you wish:
> I frequent Europe and do not want to get into legal trouble on vacation.
There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here).
Worst case you would be warned to become compliant, then if you persist in not being compliant you might be fined, then if all that fails there might be a request for extradition but I highly doubt it would even get that far. Time will tell. What will definitely not happen is that out of the blue you will be yanked from your bed in Paris or Barcelona because you decided to refuse a request for deletion.
> The days of someone making something, putting it on the internet and offering it to the world seem to be over.
No, the days of harvesting data and building profiles without consent are over. You can make something just like you did last week and you can offer it to the world just fine. Do take care of your users data, be a good steward and try to do your best not to get hacked.
> do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR.
The GDPR does not have this requirement for the kind of business the article writer has. No need to hire anybody. Pure nonsense.
> Tracking crashes with Crashlytics introduces new issues because it is posted to Fabric from a user’s device, IP addresses are in the logs this is personally identifiable information (PII). Crashlytics is GDPR compliant but the burden is on me to show regulators that I am compliant points back to the need for DPO.
Having a DPA in place with Crashlytics takes care of this, that's all the burden there is, in fact, Crashlytics most likely has a standard form for this because they will be entering into DPA's with a lot of companies in the next couple of weeks/months.
> Even though no message traffic passes through Monal’s sever, registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance.
Everything you do requires GDPR compliance but not everything is impacted by the GDPR. In this case logging the IP is fine, and then when you're done with the data you can get rid of it. No need to keep it indefinitely. And that simple trick: remove data that you no longer need is going to go a long way towards establishing GDPR compliance.
> APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person. However,the fact that it can be combined to identify a person makes it PII.
So do not keep it longer than you need it.
> I believe in privacy but I do not have the resources to meet the letter of the law for compliance especially with respect to retention and processing these tokens.
But he does have the time to write blog posts complaining about having to meet the letter of the law. That time would have been better spent actually reading the law and figuring out the impact.
> Honestly, I do not know if XMPP federation is legal anymore in the EU with GDPR.
Of course it is.
> EU user data is sent out of Europe constantly.
Indeed. And that won't stop because of the GDPR.
> GDPR is written such that a user cannot agree to a user agreement that gives up GDPR requirements it’s not a matter of saying you agree to X by using this service.
Yes, that's the whole point. You can't blackmail your users to opt-out of the law by virtue of withholding your product, which is a very very nasty way of trying to deal with a legal issue, rather than to face it head on and simply attempting to try to comply.
> GDPR compliance is something the XSF is talking about right now.
Good to see not everybody has the same attitude.
The way I read it this person is not trying to limit their liability, they're simply trying to pretend the law doesn't exist, have come to the conclusion that that won't fly and now blame the law for their laziness and negative attitude towards the privacy of their users in general.
If he really cared about the users privacy then he'd at least make a serious attempt. This blog post does not indicate a serious attempt was made, it reads like someone looking for excuses.
Re: GDPR: Removing Monal from the EU
#330This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
Perhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?
If you want to criticize local laws applied internationally, abolish the US.