Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

701–710 of 957 posts

Re: GDPR: Removing Monal from the EU

#702

Earlier quoted context omitted.

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

They're not forbidden to so business, they're forbidden to so business unless they adapt their product or practices. I'd say that is pretty much the same as this case?

Re: GDPR: Removing Monal from the EU

#703
post #420

Earlier quoted context omitted.

Perhaps having legitimate purpose for data collection in the first place helps.

Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?

[deleted]

Re: GDPR: Removing Monal from the EU

#704

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

Your argument makes no sense. If it's illegal to sell something in the US, then those companies are not "refusing" to sell their products there, they are complying with the law.

Re: GDPR: Removing Monal from the EU

#705

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

I'm not following your distinction. The only difference seems to be timing. Case 1: CompanyA is already doing business in CountryB. CountryB changes regulations. CompanyA pulls out of CountryB because of regulations Case 2: CountryB has regulations. CompanyA choose not to do business in CountryB because of regulations am I missing something?

Except EU has always (well, Sweden since 1973) had regulation, if you would gave followed that, you would not have to change much in most cases. Just write some documents and smaller changes.

Re: GDPR: Removing Monal from the EU

#706

Earlier quoted context omitted.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

Is that £250 each just for GDPR compliance? That's one law in one region. Now multiply it by the number of legislative bodies worldwide and the number of relevant laws passed by each - how much does that cost?

Before it was £250 for each EU country. Now it is £250 to comply in all 28 states (27 soon). So, it saves £6750?

Re: GDPR: Removing Monal from the EU

#707

Earlier quoted context omitted.

It's certainly true that even before the GDPR, almost any nontrivial business could reasonably be argued to be violating some mostly-unenforced law. I don't see that as a reason to shrug, and make the problem one step worse. Selective enforcement of commercial law is a routine tool of unfree states--look at something like the tax charges against The Cambodia Daily. To trust in regulatory discretion is to trust that n…

The EU isn’t a continent, and the dictators you mentioned didn’t control EU countries.

My wording was awkward, but I think the meaning is clear. "...in the EU--the union of countries primarily located in a continent that..." ?

And what am I missing? They were dictators of Spain and Greece respectively. There are millions of people who can remember their rule alive in those EU countries today. What changed in the last fifty years to make a recurrence impossible? Turkey narrowly missed joining, and it's basically there now. Hungary seems well on its way.

Re: GDPR: Removing Monal from the EU

#708

Earlier quoted context omitted.

The EU isn’t a continent, and the dictators you mentioned didn’t control EU countries.

My wording was awkward, but I think the meaning is clear. "...in the EU--the union of countries primarily located in a continent that..." ? And what am I missing? They were dictators of Spain and Greece respectively. There are millions of people who can remember their rule alive in those EU countries today. What changed in the last fifty years to make a recurrence impossible? Turkey narrowly missed joining, and it's…

The threat of being suspended from the EU and the (potential) economic damage from that? You can’t be a dictatorship and keep the same rights in the union, as per the Copenhagen criteria and Article 7.

[1] https://en.wikipedia.org/wiki/Copenhagen_criteria#Political_...

[2] https://en.wikipedia.org/wiki/Article_7_of_the_Treaty_on_Eur...

Re: GDPR: Removing Monal from the EU

#709

Earlier quoted context omitted.

That's not possible as the DPO must not have any conflict of interest ( https://gdpr.dpkit.com/gdpr/chapter-iv/section-4/article-38.... ), so he/she cannot be an owner or executive of the company.

That's a big assumption. In an executive/owner role where, say, you are the CTO, surely data protection (and therefore the risks and penalties involved in controlling this data) are a core concern? Owning or being in an executive position seems to me to be an investment of interest, not a conflict. And even if such a conflict does arise, as it surely will somewhere, the text linked states that the controller and proc…

I don't think it's a big assumption as the law as well as the guidelines clearly state that point (from "Guidelines on Data Protection Officers" [1] by WP29, pages 16 ff.):

> The absence of conflict of interests is closely linked to the requirement to act in an independent manner. Although DPOs are allowed to have other functions, they can only be entrusted with other tasks and duties provided that these do not give rise to conflicts of interests. This entails in particular that the DPO cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data. Due to the specific organisational structure in each organisation, this has to be considered case by case.

> As a rule of thumb, conflicting positions within the organisation may include senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments) but also other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing. In addition, a conflict of interests may also arise for example if an external DPO is asked to represent the controller or processor before the Courts in cases involving data protection issues.

In summary, if you have power to decide how or for what purposes the processing of the data is to be carried out you're probably not allowed to serve as DPO. Of course in the end it's the company's decision who to give that role to, but not following the guidelines increases the chance of non-compliance.

1: http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_...

Post reply on HN