Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

521–530 of 957 posts

Re: GDPR: Removing Monal from the EU

#521
post #494

Earlier quoted context omitted.

Running further with a bad analogy doesn't make the analogy any better or more relevant to the GP comment.

Apologies, I genuinely don't understand this critique.

GDRP doesn't ban the milk from which messengers are churned at the messenger mills either.

Re: GDPR: Removing Monal from the EU

#522
post #489

Earlier quoted context omitted.

> and I don't see why "it's on the internet" appears to be the main counter-argument. Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. Regulations like GDPR are making doing business in more than one country more difficult and encouraging a Balkanized web.

> Because by default any web site has, in the past, been open to people from any country that doesn't censor the web. This has never been true since the internet was international. You have always had to comply with laws of countries you interact with, it's just that most people who ran internet businesses decided to ignore the law (just try hosting some copyright or patent infringing content on the internet and see…

The fundamental properties of doing business overseas have changed. What used to be a prohibitively expensive enterprise is now within the reach of everyone.

And the cost of regulation, which used to be negligible compared to the cost of the enterprise itself, has now become a significant barrier for small businesses.

Re: GDPR: Removing Monal from the EU

#523
post #355

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some…

Everyone seems to have latched on to this 20mm € fine part, but missed the surrounding paragraphs that require that fines are proportionate to the offending, and only to be used after, on in conjunction with other methods of enforcement.

It's most certainly not a blanket "Everybody who is not in compliance with the GDPR will get a 20 million Euro fine".

Re: GDPR: Removing Monal from the EU

#524

Earlier quoted context omitted.

did that $250 include an audit to verify that you are actually in compliance?

There is no such thing as a GDPR audit. Anybody that tries to sell you one is full of it.

How could this possibly be true?

You claim to know a lot about the GDPR, I’m not sure my business is compliant. Can you take a look and tell me?

What’s that called if not an audit?

Re: GDPR: Removing Monal from the EU

#525
post #480

Earlier quoted context omitted.

That is the OPs exact point. Did you read the article? He mentioned that "The days of someone making something, putting it on the internet and offering it to the world seem to be over". And here you are talking about knowing the laws while the OP sits in a different country trying to run his business. You might be from Europe and to you it may just seem sensible but 1-5 person companies often have to make tradeoffs l…

But OP is wrong. OP is saying GDPR is making it impossible for him to offer the software, but GDPR has almost no effect on him. OP can just rely on "legitimate interests", and describe the data they're processing and why.

Says random person on the internet. Other random people disagree.

Re: GDPR: Removing Monal from the EU

#526

Earlier quoted context omitted.

You're right, there was never a business behind this. It's free software. Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

Because even free software has to comply with the law. Funny how that works, but not making a profit on something does not absolve you from legal liability.

And the easiest way to comply with the law in this case is simply to block EU users, as was done.

You can hardly complain that someone who gave you something for free wasn't willing to spend their time or money to comply with additional demands.

Re: GDPR: Removing Monal from the EU

#527
post #487

Earlier quoted context omitted.

> 95% Such as? Everything. Even if you process just an IP you need to document your procedures, change privacy policies. If at any point you ask for anything you need to implement opt ins, a way for (unauthenticated) users to request their data (even if it's just 1 IP) etc. My point is that having negligible private data is not less of a compliance burden than having a lot of private data. > You've had two full years…

> you need to implement opt ins, No. This is the myth that "consent is always required". There are several justifications for processing personal data, and consent is just one of them. There are others. https://ico.org.uk/for-organisations/guide-to-the-general-da...

First, notice how things like legitimate interests are not narrowly defined and left up to the DPA to judge. Which makes it hard to know whether you even need consent or not. Second, this is ICO, the British regulator. There are 28 of them one in each country and they won't always agree, so the application of GDPR policies can vary.

Re: GDPR: Removing Monal from the EU

#528

Earlier quoted context omitted.

I spent near to $10,000 in 6 lawyers 2 in usa 4 in different european countries and all wrote detailed report for me negating what you just said. IP is one of the most PII identifiable elements of an internet user. Exception is when you can prove such IP is a merely a proxy. please get some other lawyers opinion!!

Note that I didn't say IPs aren't PII; I said they don't count as long as you are collecting them for the specific purpose of security and don't have any way to identify the person using that IP. Pretty much by definition that is not PII. That came from the legal departments from our German, UK, and French entities.

You contradict yourself, either its PII or not. Common understanding in the industry is that it is. Purpose of security doesn't change if its PII or not. Although security/auditing might allow to hold on for longer because you need the PII as a feature (which you should be transparent about). For pure telemetry you don't need it, I'd claim.

Re: GDPR: Removing Monal from the EU

#529

Earlier quoted context omitted.

Perhaps this isn't obvious to everyone, but other people are actually not obligated to spend their time doing things you want them to.

That's the law in the EU, I think it's natural to have a hobby that doesn't break any laws.

Right... which is why this guy has decided this is no longer going to be his hobby in the EU. While the EU has every right to say 'those who do X for a hobby must do Y to comply' they cannot say 'everybody must have X for a hobby' or 'Bob must continue doing X for a hobby' .

Re: GDPR: Removing Monal from the EU

#530
post #508

Earlier quoted context omitted.

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

I've seen this variety sold in Poland

https://www.candywarehouse.com/assets/item/regular/kinder-jo...

But I'm not sure it's typical.

Post reply on HN