Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

331–340 of 957 posts

Re: GDPR: Removing Monal from the EU

#331

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

We have spent 3 months and aren't done yet. I would love to know your secret.

Re: GDPR: Removing Monal from the EU

#332

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

> A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US

Such a car cannot be driven on the road within The Netherlands without it being validated as safe (plus some other inspections).

For US, same seems to apply. Per https://www.dmv.org/car-registration.php it mentions: "Pass a vehicle safety inspection.". So again you need to deal with paperwork and read what those safety regulations are.

Re: GDPR: Removing Monal from the EU

#333

Earlier quoted context omitted.

"users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do" I'll let that excerpt speak for itself. And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary.

> And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary Views like this are exactly why we need the GDPR. I find it utterly ridiculous - disgusting even - that you really believe you have the right to do whatever you want with someone else's personal information. When you provide an email addr…

Why not? I have yet to see anyone arguing for data protection legislation actually give a reason that they think a users data belongs to the user.

Re: GDPR: Removing Monal from the EU

#334

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

the laws you refer to preexisted. Did they tear down all the houses that don't comply with contemporary building standards? I dont think so. GDPR is enforced retroactively on everything since the beginning of the internet.

> Did they tear down all the houses that don't comply with contemporary building standards?

No, they fined everyone that owns homes commercially that did not upgrade the homes to comply. And then fined them again. And again, until they complied.

Re: GDPR: Removing Monal from the EU

#335
post #295

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.

You have pointed me to the entire content of the GDPR. It's 11 chapters, with 99 articles. I'm unashamed to admit that I don't consider even skimming such a document "easy". I was imagining something more along the lines of a one pager with 4-8 bullet points, each of which was easy to address.

Re: GDPR: Removing Monal from the EU

#336

Earlier quoted context omitted.

If you are not doing anything shady, if you have your house in order security wise and if you do not collect data that you have no use for you are 95% there. The remainder will maybe require consultation with a lawyer for an hour or two if you want to play it safe but you could also simply wait for a few months to see how it all plays out. If you are respectful of other people's privacy then there is very little chan…

> then you will be warned to become compliant long before you will be fined citation needed > if you do not collect data that you have no use for you are 95% there. I have always been respectful and even never required emails on signups. I am not 95% there because there is a ton more to do. In fact i am at 5% because i have a lot of small scale past projects. Not everyone is a VC-funded startup. That's the kind of em…

> citation needed

Every statement issued by EU regulators to date.

> I have always been respectful and even never required emails on signups.

Good.

> I am not 95% there because there is a ton more to do.

Such as?

> In fact i am at 5% because i have a lot of small scale past projects.

You've had two full years to get this done. The law came into effect the 14th of April 2016. It is now May 2018.

> Not everyone is a VC-funded startup.

If you can build it you can also build it in a way that is compliant with the law and if you built it in a way that requires a lot of work to be compliant with the GDPR then you likely were already riding a very fine line with respect to the DPD which has been in effect for much longer.

> That's the kind of emotional reaction that everyone has to GDPR.

Emotions are a bad guide when it comes to legal stuff.

> Yes we like respecting privacy, it's a good thing, but there is a lot that is problematic with this legislation.

Such as?

Re: GDPR: Removing Monal from the EU

#337
post #295

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.

This is a manual by one particular consulting firm, and the text of the law. While reading the law may be good, it is really not feasible to understand all the repercussions without consulting a lawyer. While this consulting firm may have a good interpretation of key provisions, they are not actually your attorney, and their incentives cannot be known to really align with yours.

I mean, this isn't rocket science. More regulation is always going to lead to businesses leaving the market. This is not a bad thing, if your country is willing to put up with it. My guess is that the EU will not care about monal exiting the IM market, and their legislature has decided that they want to prioritize this regulation over the efficiency of the IM market. That's fine -- that's the EU's choice to make.

Re: GDPR: Removing Monal from the EU

#338

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

Can you send me an email? I am working for a startup and I would like more information about your services . (It’s in my profile).

Re: GDPR: Removing Monal from the EU

#339

Earlier quoted context omitted.

Your first two examples are cute, but your third has the unfortunate side effect of undercutting your argument. A car you built yourself (or more often a motorcycle) actually _can_ be driven on roads in the US, as long as it has the appropriate indicators (brake lights, turn indicators, headlights). There's a crazy subculture around building bikes that would never in a million years pass muster as production vehicles…

You could build and drive a car you built yourself with no regards for your personal safety - it's your car after all, and it's your business if you get injured. But could you sell such a car? You could build and use a service with no regards for your personal privacy - it's your service after all, and it's your business if your data gets leaked. But could you offer such a service?

Yep. You could totally sell it, and in fact that's exactly what Boss Hoss motorcycles does. I believe each vehicle has to be unique, or something. Not sure where the line is between these custom vehicles and "production" cars, but it involves the scale of the production. Exactly the kind of exemption people are suggesting for the GDPR.

Re: GDPR: Removing Monal from the EU

#340

Earlier quoted context omitted.

I obviously wasn't talking in a legal sense, I was talking in a "what's actually right and good" sense. The law doesn't make something right. Rightfully, the information belongs to the webmaster. Under GDPR, users get to put a leash and muzzle on webmasters.

I'm sure the person you're replying to is also talking in the 'rightful' sense. While the data collected technically belongs to you, it can still be a privacy violation. This is extremely important on the web where it's very easy to share that data, make it public or accidentally leak it.

It can be a privacy violation but the idea of a fundamental right to privacy is not universally supported like free speech.

If it is a fundamental right, how far does it go? Should I be able to sue you for watching me walk in a public place? Photographing me? Video taping me? What about a privately owned but still public place?

There are a lot of questions here that I think people tend to skip over about users owning information about them and being able to control it.

Post reply on HN