Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

51–60 of 957 posts

Re: GDPR: Removing Monal from the EU

#51
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

No. That article says you only need a DPO if you're a public authority or if you're processing certain data or you're processing very large amounts of data.

I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?

Re: GDPR: Removing Monal from the EU

#52

Does GDPR have any non-monetary enforcement? For a site with no revenue, can they take any action other than a $0 fine?

It has a maximum, not a minimum: The higher of 4% turnover OR €20m. That means even with 0 revenue, your fine can be up to €20m (It won't, because if you're not making money your small fry to them, but still, the fine can be greater than 0)

Re: GDPR: Removing Monal from the EU

#53
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

BetOnSports, an AIM listed UK company took sports bets over the internet, including from US customers:

> In July 2006, their then-CEO, David Carruthers, was arrested while changing planes in Texas on the way to Costa Rica from the U.K. In April 2009 he pleaded guilty to federal racketeering charges, and in January 2010 was sentenced to 33 months in prison.

Re: GDPR: Removing Monal from the EU

#54

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

Regardless of what you log, here is a minimum cost of compliance, from the article: > I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. I do not have designated EU contacts. If a single user decides to send him/her the letter ( https://www.linkedin.com/pulse/nightmare-letter-subject-acce... ), he/she would either have to spend an enormous amount of resources…

Implying that every company operating in the EU needs to hire someone to be a DPO is as ridiculous as it is completely false.

Re: GDPR: Removing Monal from the EU

#55

Earlier quoted context omitted.

these assurances from internet forums are great and all, but hwy take such risk?

Sure, feel free to "leave", really, no offense. We talked to a lawyer in Germany regarding this (we are a small software company with 5 people). His response was: If you don't do shady shit with customer data, you'll probably don't have to worry. Also, if you are in a "contractual agreement" (e.g. EULA), you can apparently justify most data collection without any change at all.

If he really said "probably", then he’s the one who doesn’t have to worry about the advice he gave you being incorrect.

Re: GDPR: Removing Monal from the EU

#56
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

First of all, you're saying "core business". Is this even a business?

And I copy-pasted direct text from the regulation. Note how it says "large scale". Twice. If he is actually processing personal data on a large scale, then maybe it is not unreasonable to have a DPO.

Re: GDPR: Removing Monal from the EU

#57
This project is completely out of scope for GDPR, not having any presence whatsoever in the EU. You aren't going to be arrested when going on holiday. You wouldn't be breaking the law at all, even if it was possible to enforce anything.

Even if it was in the EU, it wouldn't require a DPO, and your use of IP addresses is very reasonable and within the standard allowances which don't require user consent.

Maybe bother reading _anything_ from an official source before coming to this conclusion? This reads to me more as something you want to have a rant about because you don't like it - rather than as any kind of pragmatic decision.

Re: GDPR: Removing Monal from the EU

#58
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/

which clause would apply to require a DPO?

clause a: not a public body

clause b: not systematically monitoring (eg. installing video cameras all over the streets)

clause c: not processing large scale sensitive or criminal information.

doesn't look to me like a DPO is needed based on this article?

Re: GDPR: Removing Monal from the EU

#59
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

As it seems that we are making society-wide sweeping statements here, I'll add mine:

In a society where the webmasters have shown that they can't uphold their duty to secure PII (or any kind of data really), as evidenced by ~monthly high-profile data leaks, they deserve to be restricted in their "rights to the fruits of their labor".

Re: GDPR: Removing Monal from the EU

#60
Please be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.
Post reply on HN