Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

71–80 of 957 posts

Re: GDPR: Removing Monal from the EU

#71

I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.

> I'm convinced this is the start where EU citizens become second class Internet users.

This is free market with 550 mil potential users/citizens, void will be filled pretty quickly by other companies/developers that actually spent some time reading about what GDPR is.

Re: GDPR: Removing Monal from the EU

#72

I don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation an…

Essentially: yes, that is the case. (Source: I am a privacy lawyer with >10yrs experience.)

Re: GDPR: Removing Monal from the EU

#73
post #45

I'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.

This might actually be a good thing, as it will open the opportunity for European companies to step up and fill the gaps.

It doesn't have to be European companies, an American (or Japanese or any other place) company can go and fill the role as long as they follow GDPR.

Re: GDPR: Removing Monal from the EU

#74
post #4

Why not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying tha…

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

Why do you think consent is required?

Re: GDPR: Removing Monal from the EU

#75

I'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement. You certainly don't need to hire extra people like author suggests and federation should be just f…

"Allow removing it" is a pretty big barrier for many.

Why?

Re: GDPR: Removing Monal from the EU

#76
post #62

Earlier quoted context omitted.

Companies with less than 250 workers have fewer requirements, but the obligation of a DPO follows a different set of rules https://gdpr-info.eu/art-37-gdpr/ Edit: Art 30 "The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…

This sounds like absolute bullshit.

Yes it is bollocks, but the fact that Monal wouldn't need a DPO if they were based in the EU is true.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

Recording IP addresses in a web server log does not qualify as "regular and systematic monitoring of data subjects on a large scale" by any stretch of any definition.

And that's besides the fact that they don't have any presence in the EU. GDPR's scope only includes companies with at least some presence in the EU. That's not just because it'd be unenforceable - the laws make no attempt to include a wider scope than that.

Re: GDPR: Removing Monal from the EU

#77
post #17

>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations w…

Companies with less than 250 workers have fewer requirements, but the obligation of a DPO follows a different set of rules https://gdpr-info.eu/art-37-gdpr/ Edit: Art 30 "The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…

This was in one of the earlier drafts of the GDPR but was removed, so you can be required to appoint a DPO if you are a small startup as well, but only if one of the conditions mentioned in article 37 applies to you (which I think doesn't to the OP).

Re: GDPR: Removing Monal from the EU

#78

Earlier quoted context omitted.

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

> We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least) So someone having a copy of my data that I wish be removed is trampling on a webmaster's rights? That makes no sense whatsoever. > Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers This isn't even true. They h…

But it's not "their" data. It's the webmaster's data. It rightfully belongs to the webmaster. It just happens to pertain to the user. There is no justification for that information still belonging to the user after the user surrenders it to the website.

Re: GDPR: Removing Monal from the EU

#79
Comments here only show how terrible this law is, as nobody has a clue how to interpret the requirements. EU direction is simple - cripple the internet so that only handful of companies could afford to navigate regulational hurdles and that way it will be easier for bureaucrats to control it. Any small initiative kill with fines. In few years internet will be under full control of socialist regime and people are sleep walking into new reality with the help of do-gooders.

Re: GDPR: Removing Monal from the EU

#80
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

The op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.

No, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.
Post reply on HN