GDPR: Removing Monal from the EU
701–710 of 957 posts
Re: GDPR: Removing Monal from the EU
#702Earlier quoted context omitted.
It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…
Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…
Re: GDPR: Removing Monal from the EU
#703Earlier quoted context omitted.
Perhaps having legitimate purpose for data collection in the first place helps.
Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?
Re: GDPR: Removing Monal from the EU
#704This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…
It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…
Re: GDPR: Removing Monal from the EU
#705Earlier quoted context omitted.
Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…
I'm not following your distinction. The only difference seems to be timing. Case 1: CompanyA is already doing business in CountryB. CountryB changes regulations. CompanyA pulls out of CountryB because of regulations Case 2: CountryB has regulations. CompanyA choose not to do business in CountryB because of regulations am I missing something?
Re: GDPR: Removing Monal from the EU
#706Earlier quoted context omitted.
Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.
Is that £250 each just for GDPR compliance? That's one law in one region. Now multiply it by the number of legislative bodies worldwide and the number of relevant laws passed by each - how much does that cost?
Re: GDPR: Removing Monal from the EU
#707Earlier quoted context omitted.
It's certainly true that even before the GDPR, almost any nontrivial business could reasonably be argued to be violating some mostly-unenforced law. I don't see that as a reason to shrug, and make the problem one step worse. Selective enforcement of commercial law is a routine tool of unfree states--look at something like the tax charges against The Cambodia Daily. To trust in regulatory discretion is to trust that n…
The EU isn’t a continent, and the dictators you mentioned didn’t control EU countries.
And what am I missing? They were dictators of Spain and Greece respectively. There are millions of people who can remember their rule alive in those EU countries today. What changed in the last fifty years to make a recurrence impossible? Turkey narrowly missed joining, and it's basically there now. Hungary seems well on its way.
Re: GDPR: Removing Monal from the EU
#708Earlier quoted context omitted.
The EU isn’t a continent, and the dictators you mentioned didn’t control EU countries.
My wording was awkward, but I think the meaning is clear. "...in the EU--the union of countries primarily located in a continent that..." ? And what am I missing? They were dictators of Spain and Greece respectively. There are millions of people who can remember their rule alive in those EU countries today. What changed in the last fifty years to make a recurrence impossible? Turkey narrowly missed joining, and it's…
[1] https://en.wikipedia.org/wiki/Copenhagen_criteria#Political_...
[2] https://en.wikipedia.org/wiki/Article_7_of_the_Treaty_on_Eur...
Re: GDPR: Removing Monal from the EU
#709Earlier quoted context omitted.
That's not possible as the DPO must not have any conflict of interest ( https://gdpr.dpkit.com/gdpr/chapter-iv/section-4/article-38.... ), so he/she cannot be an owner or executive of the company.
That's a big assumption. In an executive/owner role where, say, you are the CTO, surely data protection (and therefore the risks and penalties involved in controlling this data) are a core concern? Owning or being in an executive position seems to me to be an investment of interest, not a conflict. And even if such a conflict does arise, as it surely will somewhere, the text linked states that the controller and proc…
> The absence of conflict of interests is closely linked to the requirement to act in an independent manner. Although DPOs are allowed to have other functions, they can only be entrusted with other tasks and duties provided that these do not give rise to conflicts of interests. This entails in particular that the DPO cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data. Due to the specific organisational structure in each organisation, this has to be considered case by case.
> As a rule of thumb, conflicting positions within the organisation may include senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments) but also other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing. In addition, a conflict of interests may also arise for example if an external DPO is asked to represent the controller or processor before the Courts in cases involving data protection issues.
In summary, if you have power to decide how or for what purposes the processing of the data is to be carried out you're probably not allowed to serve as DPO. Of course in the end it's the company's decision who to give that role to, but not following the guidelines increases the chance of non-compliance.
1: http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_...