Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

661–670 of 957 posts

Re: GDPR: Removing Monal from the EU

#661
post #388
post #237

Earlier quoted context omitted.

I find your view very interesting. You have a very capitalist and US law based perspective on it. For one, not everything in a society needs to allow to "collect the fruits" of individual work (which is essentially capitalism). Europe has much more socialism mixed into their understanding of their societies than the US. Further, the US law is based on risks of heavy punishments but few regulations, while the law in m…

Please don't just say this is a US perspective. This is a sociopaths perspective that the current US legal system promotes due to the machinations of the same group of sociopaths. Every business owner here who would complain about how the GPDR is taking their rights to their personally earned data away would be the same people who launch a lawsuit because one of their competitior's products had a typeface that was va…

I am sorry if I formalized it too general. Like you say, it is purely focused on the law system and unrestricted capitalism, which as an individual you either use or not.

Sociopath is a tough word, but in the original non insulting meaning of deviation from the common society, I think the word is right.

Re: GDPR: Removing Monal from the EU

#662
post #647

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

I have started to think that parts of GDPR should have been restricted to large companies - e.g. anyone with more than 100k active users, data describing 100k individuals, or an organization employing more than 100 employees. That would seem like a fair way to protect privacy while keeping barriers low for tech ventures / experiments.

If you do that then facebook and the other privacy terrorists will happily create 20000 little companies that they outsource their scum to. Also, a very small company with tens of thousands of datasets can still do terrible damage to people.

Re: GDPR: Removing Monal from the EU

#664

Earlier quoted context omitted.

If there is a complaint against my small software company, are there limits on how much I'm required to spend on defense? Do I have to travel to Europe to defend my company or will investigators from Europe travel to my location at their own expense? Will I be reimbursed for reasonable expenses if the complaint is groundless? Are there parts of the regulation that act like strong anti-SLAPP laws in some states? Can m…

What can Europe do to you? Assuming you are American, the only court you need to worry about is American court. Your company is American? Your bank is American? What's the actual liability here? Worst case?

as soon as you have assets or steps foot on EU soil, you may be asked to go to court, or pay a fine or some such.

Re: GDPR: Removing Monal from the EU

#665
One thing I see missing from these discussions is budget - specifically the budgets for the regulatory agencies responsible for enforcing GDPR. Lack of enforcement budget will, I think, make GDPR a non-issue for the vast majority of organizations. And as the EU ramps up its infighting over the new budget, there will be LESS budget allocated for something like this that has no vested constituents who will be helped or harmed by such allocation.

Re: GDPR: Removing Monal from the EU

#666

This is going to sound crazy, but I spun up an instance of a simple open-source comments system[1] for a blog that I write, and I chickened out of deploying it because I wasn't sure if it complied with GDPR. I distrust Disqus over their ad-driven model and deep tracking of users, so for now I’m just doing without comments. Is it possible to self-host something that handles user data (name, comment, IP address) and co…

> Is it possible to self-host something that handles user data (name, comment, IP address) and comply with this regulation?

Yes. There's something called GDPR legitimate interest (a subcategory in the "Lawful basis" someone else mentioned here), which lets you store e.g. IP addresses for security reasons, without asking for permission.

See: http://www.privacy-regulation.eu/en/recital-49-GDPR.htm

I think Talkyard ( = open source comments, no ads, no tracking) is GDPR compliant. For example, people can download their personal data and delete their accounts. (I'm developing it).

https://www.talkyard.io/blog-comments

Re: GDPR: Removing Monal from the EU

#667
post #582

Earlier quoted context omitted.

Actually, I'm pretty sure they still stick the toys inside the eggs everywhere except the US. Perhaps a European can correct me on this assumption. EDIT: Turns out the US-style kinder eggs are indeed available outside the US.

Looks like this now http://fortune.com/2017/05/22/kinder-egg-usa-debut/ I have seen this outside of US also (pretty sure it was doing a Europe trip)

it's just a different product, which shares almost nothing with the original, and is simply sold besides it outside the US.

Re: GDPR: Removing Monal from the EU

#668
You don’t need a DPO if you’re a one man company, or your revenue is under a certain amount of which I can’t remember, because it hasn’t been relevant at our 10.000 employee municipality.

You’re allowed to track ips in your log, if there is a reason for it and you only keep them for a reasonable amount of time.

You do need to gather consent for push messages. But you can do so by simply asking your users, and frankly, you should always ask your users before you spam them, but it’s obviously going to be a little work to implement.

This is an overreaction, especially because no one knows how the GDPR plays out until it’s been tested in the courts.

Re: GDPR: Removing Monal from the EU

#669
post #470

Earlier quoted context omitted.

DPO has been thoroughly refuted in this thread. He doesn't need a DPO; if he wants to hire a DPO that can be him.

This is the furthest thing from true, like almost every single question about this terrible law. Vague law + faceless bureaucracies + universal application + crippling penalties...sounds like a brilliant combo to destroy people’s lives.

as usual, the rebuttal is: there have been this kind of laws in Europe for a decade. For example, if you're operating in Italy and don't provide 2 separate checkboxes for managing personal data directly and indirectly at sign up time you're in breach of the law.

Do you remember many people's lifes crippled by this?

Re: GDPR: Removing Monal from the EU

#670
post #508

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

Kinder is a great example actually on how a company adjusted their product. Now I believe in all markets (even beyond USA) the product is safer and less dangerous for kids to get injured.

I really don't think, it got safer.

It takes some special talent, even as an adult, to take such a big bite off of a classic Kinder egg that you'd have any chance of accidentally swallowing the plastic capsule or somehow else hurting yourself on it.

And with the new egg, I'd be concerned that my kids swallowed that plastic spoon. Like, that's something they actively have to put into their mouth and it's not as interesting as the toy for them to be motivated to not swallow it.

It's also small enough for them to realistically pull this off.

Post reply on HN