Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

631–640 of 957 posts

Re: GDPR: Removing Monal from the EU

#631

Earlier quoted context omitted.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

We have spent 3 months and aren't done yet. I would love to know your secret.

The secret is bald faced lying. The quoted price may barely cover an updated privacy policy from a lawyer. And nothing else. Not one line of code changed.

Let alone full review of every system and legal review of the DPAs you have to sign and or create with every single co and processor.

Re: GDPR: Removing Monal from the EU

#632

Long story short: Monal developer doesn't understand GDPR, makes a bunch of incorrect claims about it, doesn't want to understand it, and so removes his software from the EU. That's his right, go him. He didn't have to write a ton of incorrect nonsense about the GDPR though. He could have just skipped to the last step. GDPR compliance is not actually that hard - I'm in the middle of doing it for a very large company…

> The reaction to this law in the US is rather funny because the rest of the world has been dealing with strange US laws for decades on the web... finally something bites the other direction and people freak out.

i'm quite positive that i've seen people call for europeans to not do business with american businesses on account of said us laws (in other HN threads).

Re: GDPR: Removing Monal from the EU

#633

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

If you see nothing wrong with moving websites into the category of buildings, aircraft, medical devices, etc... what are you doing on HN? The entire ethos of this community is free and casual, sometimes entrepreneurial experimentation with networked software. It may be necessary to end that for the greater good, but that’s not something to take lightly.

US law has surprising respect for the hacker ethos, so that even in highly regulated activities, there is a much less rigorous licensing regime for small-scale practitioners. . Experimental aircraft certificates, private pilot licensing, amateur radio licensing, etc. You can build yourself a car, cook food for a party, etc. without being subject to the laws about those activities under corporate mass manufacture.

Re: GDPR: Removing Monal from the EU

#634

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

This seems as good a place as any to challenge some of the simplifications that are often given in defence of the GDPR. Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. Fair enough. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that d…

Thank you! This post starts to show some of the huge complexities that GDPR has for business and their understanding of what the terms of the law mean.

A point is that often statements of a law are defined not by the language but by the ruling of lawsuits that occur around those statements and that is what most companies and lawyers are waiting for, what do courts rule when these lawsuits happen.

The biggest issue that I have heard of (Im no expert) is what does the right to be forgotten actually mean ? Does that mean all your backups are now illegal as you are retaining the customers information after they asked you to remove their records?

I think some of the fear that smaller business have is that this will encourage lawsuits until people understand how the courts will rule on each item.

Re: GDPR: Removing Monal from the EU

#635
post #620

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

> if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job how could you "not need" data if the loss "destroyed" the business model?

Need to... serve the subject

Vs to package and resell the subject.

It is a matter of making subjects of data collection in control of their data being sold without their consent to the real customer, someone else.

Re: GDPR: Removing Monal from the EU

#636
post #420

Earlier quoted context omitted.

We have spent 3 months and aren't done yet. I would love to know your secret.

Perhaps having legitimate purpose for data collection in the first place helps.

You still have data hygiene policies to enact which are confusingly legislated. Also legitimate interest is a loophole created to appease some lobbyists but the legislators declined to make clear anywhere because they don’t give a shit about commercial needs.

Re: GDPR: Removing Monal from the EU

#637
post #528

Earlier quoted context omitted.

You contradict yourself, either its PII or not. Common understanding in the industry is that it is. Purpose of security doesn't change if its PII or not. Although security/auditing might allow to hold on for longer because you need the PII as a feature (which you should be transparent about). For pure telemetry you don't need it, I'd claim.

IPs can be PII under certain circumstances, but not the ones I laid out. > Purpose of security doesn't change if its PII or not. Security is the legitimate interest, an important part of collection under GDPR.

[deleted]

Re: GDPR: Removing Monal from the EU

#639
post #480

Earlier quoted context omitted.

That is the OPs exact point. Did you read the article? He mentioned that "The days of someone making something, putting it on the internet and offering it to the world seem to be over". And here you are talking about knowing the laws while the OP sits in a different country trying to run his business. You might be from Europe and to you it may just seem sensible but 1-5 person companies often have to make tradeoffs l…

But OP is wrong. OP is saying GDPR is making it impossible for him to offer the software, but GDPR has almost no effect on him. OP can just rely on "legitimate interests", and describe the data they're processing and why.

Legitimate interests is not defined. So good luck with that.

Also you are responsible for downstream guarantees of legitimate interest.

He is right that open P2P protocols like XMPP, such as NNTP, IRC, bitcoin, ethereum, etc are not handled clearly.

It is a headache for him I can sympathize.

Re: GDPR: Removing Monal from the EU

#640
post #624

Earlier quoted context omitted.

"you are required to comply with the laws of any country you do business with." Prove that. Because that's not how "the law" works. I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees. And t…

you seem to suggest that you can (for example) sell/distribute canadian alcohol in saudi arabia, even though it's illegal there. do you really think that's accurate? every country has the right to enforce it's own laws within it's own borders. you don't get a pass to do whatever you please in another country without their permission. edit: i noticed "my business exists only in Canada" if you mean to say you aren't do…

Yes. You can sell alcohol to Saudi Arabians from Canada. You cannot ship to Saudi Arabia. The buyer may pick up in another location where alcohol is legal including in person in Canada. What they do with the alcohol once in their possession is their business.
Post reply on HN