Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

351–360 of 957 posts

Re: GDPR: Removing Monal from the EU

#351

Earlier quoted context omitted.

My exposure to this is limited to cases in Europe and ones that I was a direct witness to and in all those cases it was pretty clear that the company was created with the express purpose to commit bankruptcy fraud and the result was the owner of those companies lost his shirt. All other attempts to pierce the corporate veil that I've seen failed.

Presumably that fraud involved assets that belonged to the corporation (or were represented to creditors as such) being transferred outside the corporation to other entities controlled by the owner? That will pierce. Imagine instead someone who builds a store in a location with insufficient commercial traffic and whose corporation fails for that reason alone: her creditors can't take away her house, her retirement ac…

Long story short: guy figured out a way to make money: create an LLC, rent some warehouse space, order hardware, sell hardware, pay invoices, order some more hardware, sell hardware, pay invoices. This cycle repeats a couple of times with higher and higher order values and then finally when the orders are really large (millions) holds a clearance sale, pockets the money and defaults on the invoice. Boom, company bankrupt.

He did this several times before the corporate veil was pierced and they took him for all he had.

The other case was one that is probably best described as mismanagement ('onbehoorlijk bestuur') where the CEO/sole shareholder of a company started using the corporate account as though it was his personal account. When the company was unable to meet payroll taxes the taxman seized his private assets after piercing the veil.

Re: GDPR: Removing Monal from the EU

#352

Earlier quoted context omitted.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

There doesn't need to be a GDPR opt-out. They just need to ask for permission to use the data.

The company would still be subject to the GDPR which they may consider an unacceptable risk. I'm specifically asking whether users would like to be able to give permission to ignore the GDPR altogether or if they see that ability as harmful for society in general.

Re: GDPR: Removing Monal from the EU

#353

Earlier quoted context omitted.

I'm not sure what else I should reply to something like your comment before tbh. Neither can I predict the future, nor am I a lawyer. I'm just posting about my opinion, which I got by gathering information online and from consulting with a lawyer. I've stated the conclusion I've come to, based on this information and yes, I believe that to be correct (or as correct as one can be about a law with no reference cases in…

You stated your extremely general conclusions, and only later mentioned that they were relevant to your personal business. And in this particular sub-thread, you made a very general statement about risk, again without qualifying it at all. And you only mentioned the lawyer after you were challenged about a general statement. Maybe you have huge assumptions that people reading what you say will add all kinds of limita…

I'm sorry for making too generic statements, I'm not trying to have a bad discussion, really.

Regarding the personal risk comment, I could've been more clear: From what I got, no lawyer can give you a guarantee at the moment, that what he says is actually what will happen. So in the end you'll have to take action based on recommendations, and take a risk - or, as the op, shut out all European users completely. My personal risk is continuing to do business in the EU, even with this uncertainty. You couldn't have guessed all that from my earlier comment, so I agree it was bad..

I'll try to do better.

Re: GDPR: Removing Monal from the EU

#354

Earlier quoted context omitted.

And it's good that it wasn't allowed. Otherwise we'd just have medium sized companies worrying about GDPR while large companies spawn one-man shell companies that "specialise in data processing".

That is resolved today by subsidiary clauses in laws. If owned or controlled by big-co in an non arms length manner, then it wont be considered a 'small company' in terms of the GDPR. Edit: These corporate control laws have teeth, otherwise every small & large business owner would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done…

> would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done actually in the territory itself

It's not 0, but large corps already do this. https://en.m.wikipedia.org/wiki/Double_Irish_arrangement

Re: GDPR: Removing Monal from the EU

#355

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some of "their" data (which they seem to think is stored on my storage that they never bothered renting from me) or I might have to pay 20 million euros. I tell those users and their government, neither of whom I owe anything, to kindly piss off and then ban all ip addresses from the EU.

To put it another way, I go to Central Park and start to juggle. I don't charge people, I just juggle because I like to juggle. Some people watch; others simply ignore me. I write observations about a couple of the people who watched me perform in my journal. One of those guys was from France. He later looks me up in a phone book and calls me to demand I give him any observations I wrote in my journal. I tell this fellow to piss off. A few months later I get a letter saying I need to pay 20 million euros because I wouldn't give away my personal observations stemming from something I did publicly and for free.

Re: GDPR: Removing Monal from the EU

#356

Earlier quoted context omitted.

I think it's clear that 1 person is not a large scale op. I do agree it should be defined in at least somewhat precise terms though.

The number of employees isn't a factor as far as the scale of data processing is concerned - it's the scale of the actual data processing...

At a certain point, even if you are a single person, if you are processing and tracking enough data then you still shouldn't be allowed to do what you want. Company's could just outsource all liability to single person consultancies then like they outsource a lot of none core jobs to consultancies to get around employment law now

Re: GDPR: Removing Monal from the EU

#357

Earlier quoted context omitted.

And has made his business that much less viable, and opened himself up to competition from a company with a comparable product that does comply with the law. And maybe one day the USA will pass some privacy legislation...

I'm not actually sure he is running this as a business? It seems open source? He even suggests people download and build their own? So all he's done is save himself the time and effort of dealing with the GDPR and cost himself nothing.

The fact that it is open source does not mean it isn't a business.

And yes, he has saved himself the time and the effort of dealing with the GDPR, has also managed to position himself as someone who pays lipservice to privacy but who does not care to actually be compliant with privacy legislation when it matters. I wouldn't want my data in his hands after that anyway (not that that would ever happen because I don't have a smartphone in the first place).

Re: GDPR: Removing Monal from the EU

#358

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Perhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?

Sure, he's entitled to take his ball and go home if he really wants to. That doesn't put him in the right, and it doesn't make his move anything more than whining.

Re: GDPR: Removing Monal from the EU

#359

Earlier quoted context omitted.

That is not how the EU works, in the US i would be very afraid reading that, in the EU nothing will happen if you do not violate in a spectacular way, and that, after many warnings. They are after companies tracking you across real estate and selling relevant data from their vast silos to companies that can market stuff to you. They tried many ways already to prevent this kind of practice in some countries but loopho…

How do you know that a small company will only get warnings. I don't understand the source of your bravado. Perhaps it really is different from US.

Because this will be enforced by the same people who enforce the existing regulations. We've had twenty years experience. We know how they operate.

Re: GDPR: Removing Monal from the EU

#360

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

Your point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.

> I'm having to close my small construction company because the FDA passed harsher food safety requirements.

Is your creative reuse scheme for sawdust and broken drywall bits no longer allowed?

Post reply on HN