Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

511–520 of 957 posts

Re: GDPR: Removing Monal from the EU

#511

Earlier quoted context omitted.

> Please elaborate. As you wish: > I frequent Europe and do not want to get into legal trouble on vacation. There is no precedent for violators of EU law regarding privacy to cause people to be harassed on their vacation (yes, there are examples of this on the US side but that's not what we are discussing here). Worst case you would be warned to become compliant, then if you persist in not being compliant you might b…

re: DPO i think you are being a bit naive and dismissive. the law could easily be interpreted as his endeavor requiring a Data Protection Officer. the guidelines ( http://ec.europa.eu/newsroom/document.cfm?doc_id=44100 ) for the DPO require that processing "special categories of data" needs a DPO. those categories include tings as benign as "trade union membership." so if his chat app has someone in the EU chatting a…

> so if his chat app has someone in the EU chatting about trade union membership while this chat service then "processes" that data, they might be held liable to the DPO requirement.

This is a ridiculous argument. No, someone in the EU chatting about trade union membership does not magically require him to hire a DPO.

Please.

Re: GDPR: Removing Monal from the EU

#512

Earlier quoted context omitted.

It doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.

I can't see any way in which this interpretation can be valid. You'll always be able to "directly or indirectly" identify people from IP addresses. Just because I don't store IP and identity together, doesn't mean there's not many other ways to identify somebody based on an IP address.

How would one identify a person using only an IP address?

If you have "other ways to identify somebody based on an IP address" then that wouldn't meet the criteria laid out by the lawyers.

Re: GDPR: Removing Monal from the EU

#513
post #508

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption.

EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

Re: GDPR: Removing Monal from the EU

#515

Earlier quoted context omitted.

It doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.

Hello, not a lawyer, but mine said you're wrong. You might be thinking of this pseudonymization stuff. My advice is not to play with it. Just delete your logs after a month unless you have a demonstrable and immediate security need for them.

Wrong about what? I wasn't referring to pseudonymization; we thought that wasn't worth trying after the legal teams laid out what it involved. Log rotation is important, like I mentioned.

Re: GDPR: Removing Monal from the EU

#516

Earlier quoted context omitted.

Of course they are not the same but they share a common principle, i.e. you can not do arbitrary things involving other people. And nobody is talking about your opinions, you are free to think whatever you want, just as you are free to harm yourself or even commit suicide. But if your »thinking« involves information about other people, there are limits just as there are limits if you go from killing you to killing ot…

Wow. There you go again! So if my thinking involves someone else’s information, they have some right to make me change my thinking or punish me if I don’t??

First, you switched from respecting peoples' privacy to taking notes, thinking, and having opinions. I even responded to your comment before you added the notebook in the park example. You probably also noticed that I put »thinking« in quotes.

Anyway, it is not the act of having the information about other people that is problematic, it is the act of collecting, using, or sharing it. Do you think I should be able to follow you around and write down every step you make? Should I be able to use that information in every way I want? Do you want me to tell your significant other what you actually did on that »business« trip, tell your coworkers what you got from the sex shop? Should your doctor be able to tell everyone about your health status, your bank about your financial status?

It is just naive to pretend that handling information is inherently without any concerns and therefore no rules should apply at all. And it is just silly to pretend that writing down an observation you made in the park in a notebook is the same and should be treated in the same way as systematically collecting information about every website visitor.

Re: GDPR: Removing Monal from the EU

#517

Earlier quoted context omitted.

> And here you are talking about knowing the laws while the OP sits in a different country trying to run his business. I also have to be compliant with US laws if I deal with US citizens. What's the difference? > You might be from Europe and to you it may just seem sensible but 1-5 person companies often have to make tradeoffs like this. Not the ones that want to stay in business. > It is not right to say just comply…

Again - no substance in your points. Rebut his core points if you understand GDPR so well.

Try not to post the same comment over and over again, especially when you are making a point that has already been addressed elsewhere in the thread.

Re: GDPR: Removing Monal from the EU

#518

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

What exactly did that less than £250 get your customers in return?

Even if you had a business that was whiter than white in terms of compliance with previous data protection laws and had perfect documentation of all its data collection and processing activities, it would surely cost far more than that just for the time to write some basic notes on the extra things you now have to tell data subjects and/or your regulator, get them reviewed by a lawyer, incorporate them into the relevant policies, and send notifications to anyone affected about your updated privacy policy.

Re: GDPR: Removing Monal from the EU

#519
post #470

Earlier quoted context omitted.

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

DPO has been thoroughly refuted in this thread. He doesn't need a DPO; if he wants to hire a DPO that can be him.

This is the furthest thing from true, like almost every single question about this terrible law. Vague law + faceless bureaucracies + universal application + crippling penalties...sounds like a brilliant combo to destroy people’s lives.

Re: GDPR: Removing Monal from the EU

#520

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

> This is an easy thing to say when you're not personally exposed to the risk.

No, it's an easy thing to say because we have over 20 years experiences of regulation around data protection. The regulators send a letter asking you to come back into compliance unless you've been really bad. They only move to fines if you ignore them.

Here's a company that was handling sensitive personal data (medical data). They have a legal obligation to register with ICO. They didn't do so. Imagine what would happen under HIPAA. Now read what happened in EU.

https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...

People freak the fuck out about the big fines, but they don't realise they're conditioned by the pathologicaly dreadful US system which aims to over-charge and over-sentence at every opportunity.

Here's some examples: The UK Criminal Prosecution Service sent some unencrypted DVDs through the postal mail. Those DVDs got lost. They got a fine.

Some time later they did it again - this time the DVDs contained interviews with children who were the victims of sexual abuse.

Think about this for a bit: no encryption, no secure mode of delivery, a repeat offence, incredibly sensitive personal data.

Sure this requires the maximum fine, right?

https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...

No. Only £325,000 out of a possible £500,000.

Post reply on HN