Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

611–620 of 957 posts

Re: GDPR: Removing Monal from the EU

#611

Earlier quoted context omitted.

Indeed, this did not drop out of the sky. It has been in the works for years. I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. My country's data protection agency made no attempt at raising awareness despite having my email address on file :-D It's only been frequently hitting non-EU industry news and places like HN since late 2017…

I run a business that follows EU DP best practices (and so was mostly GDPR compliant already) and the first I heard of it was mid 2017. Likewise. This idea that the GDPR has been in the works for years so it's somehow implausible that very small businesses have only just heard of it doesn't stand up to scrutiny. No owner-run microbusiness is spending the time necessary to keep up with the vagaries of EU debates. Simi…

Thank you for perfectly describing the frustrations I have experienced with GDPR. As the owner of a small SaaS business in the US I don't have the time to follow various EU regulations that closely.

I only found out about GDPR earlier this year from a random HN comment. I can't understand the attitude from some HN commenters that everyone should have known about this for years. Where/how should every small business that could be impacted by this regulation be notified?

As you noted, the regulation is readable, but verbose and frustratingly vague. I ended up reading most of it along with countless articles from various third parties debating what it means and how to comply - and I'm still not 100% certain if the steps I've taken mean I'm actually "GDPR compliant."

I too got stuck having to comply since around 30% of my customers are in the EU. However, I gladly would have foregone all of that revenue and focused on non-EU customers only if I had known what was coming back then...

Re: GDPR: Removing Monal from the EU

#612
post #123

> registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance. APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person. Article 6, Paragraph 1, seems to cover those two parts of data collection. Logging a user's IP for…

it covers it ... except when it doesn't. Which is open to 'interpretation'

Where is the scale balanced on this ... will it be the same in each of the different countries implemeting it?

>as long as it do not conflict with the interest of the data subject in regard to their need for data protection

Article 6.1.f

>processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

So ... I can retain IP records in my logs , as long as they aren't a child?

Re: GDPR: Removing Monal from the EU

#613
post #420

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Perhaps having legitimate purpose for data collection in the first place helps.

Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data?

You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?

Re: GDPR: Removing Monal from the EU

#614

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Operating a network service is now illegal by default. Yes, the exceptions are large enough to accommodate most legitimate businesses. Yes, the likelihood of enforcement action against a small player is low. But the normal course of websites has so far been miles and miles away from the nearest illegal act. Now they are right up against the letter of the law merely for calling listen(). The only other law to come that close to the normal operation pure-internet entities is copyright, and it’s drawn similar ire. While it’s true that websites have always been prohibited from committing murder, the possibility of committing murder with a website is so remote as to be absurd.

Re: GDPR: Removing Monal from the EU

#615
post #576

Earlier quoted context omitted.

Still in the dark mate. I'm sorry, maybe it's me, maybe it's you, but we seem to be speaking a different language.

It's you. The original comment says 'The author of Monal misunderstands/misrepresents the regulation and is throwing a silly tizzy'. To which you say 'some laws ban some things. also, cheese is made of milk'. These things are true but not related to the GDRP or messengers.

... unsure if troll or just slow.

parent was giving an example of how Monal isn't "throwing a silly tizzy" ... instead they have deemed the cost of complying with the regulations (all the items listed in the article) not worth the reward, much like how raw milk cheese companies decided to not sell in America because it was not worth the cost to comply (change practices, open different facility) with the regulations.

The point being that doing that cost / benefit break down is totally reasonable and it's not "throwing a silly tizzy" to decide if you want to engage in a market that is increasing your costs beyond what you think you'll get in return.

None of this has any judgement on the value/reason/justification of the regulation - simply it increased costs more than this company thought they could get back out of being compliant there so they removed themselves from that market.

Re: GDPR: Removing Monal from the EU

#616

Earlier quoted context omitted.

> I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases Being the sole owner and manager and being the DPO is clearly a conflict of interest.

> Being the sole owner and manager and being the DPO is clearly a conflict of interest. Could you clarify why you think this is so? As an owner, my interests would align with the DPO's interests so it's hard to me to find where the conflict of interest would reside in the case of being the sole employee _and_ DPO. Now if it's a large company where they make money per GDPR policy workaround then I could see it being r…

[deleted]

Re: GDPR: Removing Monal from the EU

#617
post #568

Earlier quoted context omitted.

I don't do any real business in the EU, but I'm a fairly succesful online marketer. Being able to flexibly use SaaS businesses is so, so valuable for testing and iterating on marketing plans. I would fight pretty hard against a company policy that limited it, since today's marketing test is tomorrow's major revenue driver.

I think you misunderstand what I was saying. We collect data in our system. We use that data for marketing under legitimate interest. Sometimes marketing would like more analysis done on the data than we have time to implement. They hear about some SaaS business that will take the data and give them a marketing plan (Yay! No work to do!). They ask us to ship over all the data to the SaaS business. Sometimes it's a go…

Do a lot of SaaS businesses sell personal data as their business model? When I think of SaaS I think of paid subscription access to a piece of hosted software.

Re: GDPR: Removing Monal from the EU

#618
post #576

Earlier quoted context omitted.

It's you. The original comment says 'The author of Monal misunderstands/misrepresents the regulation and is throwing a silly tizzy'. To which you say 'some laws ban some things. also, cheese is made of milk'. These things are true but not related to the GDRP or messengers.

... unsure if troll or just slow. parent was giving an example of how Monal isn't "throwing a silly tizzy" ... instead they have deemed the cost of complying with the regulations (all the items listed in the article) not worth the reward, much like how raw milk cheese companies decided to not sell in America because it was not worth the cost to comply (change practices, open different facility) with the regulations.…

The original comment is about the proportionality of the response, the choice the author is making and what the commenter thinks about it. When something is banned outright, there is no choice and no proportionality. So, no, it's not particularly responsive nor analogous.

Re: GDPR: Removing Monal from the EU

#619

Earlier quoted context omitted.

If a business blocks EU citizens what will happens is that either another one who cares about GDPR will pop up and be able to work with both EU and non-EU citizens, or the business in question wont be that important in the first place. In either case, nothing will change for most people.

Maybe, but imagine if Google, Microsoft, Facebook, Amazon, etc. had decided to pull out of the EU. Not that any of them aren't replaceable, but providing the suite of functionality that any one of them does to their customers would not be a simple feat. "Second class citizens" might not be the right term, but would "segregation" be an appropriate term?

What would most likely happen is that companies that act as "middle men" would pop up that provide the functionality those sites do. But TBH i doubt that would ever happen in the first place, even with much stricter rules. There are way too big of an audience to be lost.

Re: GDPR: Removing Monal from the EU

#620

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

> if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job

how could you "not need" data if the loss "destroyed" the business model?

Post reply on HN