Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

691–700 of 957 posts

Re: GDPR: Removing Monal from the EU

#692

Earlier quoted context omitted.

I don't think you actually answered his point. Sure you could build an IM client that is GDPR compliant, but at what point do the costs become so high that everyone just defaults to using Facebook because (1) they can afford to be compliant and (2) they are trained well enough to not fuck up their encryption. In other words, are we moving towards a world where unless you are VC backed (Signal, Telegram, Whatsapp, etc…

There is an assumption that there is some additional "natural" cost involved because of GDPR, but where does that assumption come from? The cost might currently exist if you are not compliant and you need to convert (or you need to skirt the edge between what is allowed and what not), but if you start with being firmly compliant from the design phase, where does the cost come from?

Eg. the DPO.

Re: GDPR: Removing Monal from the EU

#693

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

I smirked a bit, the EU certainly didn't advertise it in the last two years but it was definitely around. But just like in HGttG there isn't much use in yelling in protest now, grab a towel and grab something safe. (I should sent out my towel reminders to some of my users since I updated a few pages)

Re: GDPR: Removing Monal from the EU

#694
post #493

Earlier quoted context omitted.

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

There is signifiant disagreement to what extent Facebook and Google are compliant.

I'm pretty sure the regulatory bodies are thoroughly and wholly excited to take on Google and Facebook with some hefty fines and clarify the GDPR and how it applies. I can't wait either.

Re: GDPR: Removing Monal from the EU

#695

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

I saw that one coming a mile away, thank you for the quote though :)

And no, this is not about demolishing our way of life, the town we live in or the planet, it's about respecting the privacy of your users, which - for a change - is actually a positive thing. Unless of course you weren't going to do that in the first place you should welcome the development, I imagine that in a just world the Vogons would be on the receiving end of it.

Oh, and in this case the plans were not on display in the locked filing cabinet in a basement of a building where the lights had gone off and where the stairs were missing.

A handy URL has been provided for a long long time and all the debates have been recorded in public as well.

Re: GDPR: Removing Monal from the EU

#696

Earlier quoted context omitted.

as usual, the rebuttal is: there have been this kind of laws in Europe for a decade. For example, if you're operating in Italy and don't provide 2 separate checkboxes for managing personal data directly and indirectly at sign up time you're in breach of the law. Do you remember many people's lifes crippled by this?

It's certainly true that even before the GDPR, almost any nontrivial business could reasonably be argued to be violating some mostly-unenforced law. I don't see that as a reason to shrug, and make the problem one step worse. Selective enforcement of commercial law is a routine tool of unfree states--look at something like the tax charges against The Cambodia Daily. To trust in regulatory discretion is to trust that n…

The EU isn’t a continent, and the dictators you mentioned didn’t control EU countries.

Re: GDPR: Removing Monal from the EU

#697
post #123

> registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance. APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person. Article 6, Paragraph 1, seems to cover those two parts of data collection. Logging a user's IP for…

it covers it ... except when it doesn't. Which is open to 'interpretation' Where is the scale balanced on this ... will it be the same in each of the different countries implemeting it? >as long as it do not conflict with the interest of the data subject in regard to their need for data protection Article 6.1.f >processing is necessary for the purposes of the legitimate interests pursued by the controller or by a thi…

In regard to children I view it as part of two different interpretations. One is that data in regard to children need to be considered with extra care and in those cases that the process is written down or is more formal then that consideration need to addressed.

The other way to see it is a bridge to the US regulation COPPA, where operators in the US and EU now have to follow the same rules in regard to children. In this case Monal would have to move out of both EU and US in order to avoid the regulations in regard to children.

Re: GDPR: Removing Monal from the EU

#698
post #629

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

You don’t need a lawyer to comply with the law is a weird statement to put out there. You should retract.

What? I don’t need a lawyer to tell me I can’t go out and steal someone’s wallet. It’s perfectly possible to comply with the law without one.

Re: GDPR: Removing Monal from the EU

#699

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

Yeah, but the analogy is not good...

* We've known about the GDPR for around 2 years.

* The GDPR text, national regulators' comments, industry opinion, sample docs and a plethora of free resources have been readily accessible on the Internet for about the same length of time.

Having worked on the GDPR docs for a medium-sized business that builds learning management systems for corporate customers (about 100 live systems + dev and testing platforms where we are a processor of their personal data), it took about 3 weeks-worth of time to re-audit our platforms, complete a more detailed risk/impact assessment and write this all up together with some procedures for handling enquiries.

Yes it took time, and we went the extra mile with diagrams and tables because the docs are customer-facing, but handled in a timely fashion, GDPR compliance is not a brick wall to business continuity.

If a business already has in place a baseline level of good information security practice, GDPR compliance is not that hard.

Re: GDPR: Removing Monal from the EU

#700
post #680

Earlier quoted context omitted.

Not the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using cons…

The only problem I see here is needing data based on contract obligations, I have seen lots of sites packing the data collection into privacy policy or some shady contract, thinking that this is legitimate interest. But legitimate interest is actually the hardest part of GDPR, even if most people think it is a workaround. If you can provide the service without some personal data (not due to financial claims) you can'…

There is only two ways of legitimate interest that I considered for my service; "security" and "better user experience".

The data collected under the former is simply the IP and a timestamp in webserver and app logs, usually purged within 7 days and then any user data included in backups, purged after 3 months.

"better user experience" is not really personal data but I included it anyways; browser type (mozilla/edge/etc.), viewport resolution, pageload time, OS. And not stored in a way that allows correlating them.

For analytics that is really all I need.

Post reply on HN