Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

721–730 of 957 posts

Re: GDPR: Removing Monal from the EU

#721
post #380

Earlier quoted context omitted.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

If you feel it’s important to comply with the laws of any country you accept HTTP connections from, why would you be upset with this outcome? Restricting your services to familiar jurisdictions until you can afford the legal advice to safely enter new countries is the only reasonable course of action in a world following that philosophy. One should not assume they’re familiar with the laws of 176 countries merely bec…

Collecting personal information and running a business based on that personal information is very different to knowing how to configure nginx. You're putting up a bit of a strawman.

Re: GDPR: Removing Monal from the EU

#722

Earlier quoted context omitted.

Thank you for making a coherent argument. You are missing one point I think: if not for those regulations those companies would love to do business. They are forbidden from doing business, this guy sees the law and runs off without even trying to become compliant. That's a different thing. There is no way that Kinder could be compliant with US law in such a way that they would not be exposed to what - to EU sensibili…

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

I guess I am a fan of GDPR, certainly compliance to anything has a cost. I personally don't find the costs of GDPR compliance onerous unless you have already built up lots of non compliant systems that now need to be fixed, in which case the free ride is over. Anyway, this guy is pulling out of the EU but if he allows anyone from the EU to use his service from a non-EU location anyway he would be risking non-compliance.

Re: GDPR: Removing Monal from the EU

#723
post #640
post #624

Earlier quoted context omitted.

you seem to suggest that you can (for example) sell/distribute canadian alcohol in saudi arabia, even though it's illegal there. do you really think that's accurate? every country has the right to enforce it's own laws within it's own borders. you don't get a pass to do whatever you please in another country without their permission. edit: i noticed "my business exists only in Canada" if you mean to say you aren't do…

Yes. You can sell alcohol to Saudi Arabians from Canada. You cannot ship to Saudi Arabia. The buyer may pick up in another location where alcohol is legal including in person in Canada. What they do with the alcohol once in their possession is their business.

In which case you are doing business with (say) France, which has its own alcohol customs laws that you have to follow.

I never said that you have to follow the laws of the country of nationality of your clients. That'd be a ridiculous thing to say, and I'm not sure why you're arguing against that particular strawman (the GDPR only talks about EU residents and doesn't mention EU citizenship at all).

Re: GDPR: Removing Monal from the EU

#724
post #254
post #58

Earlier quoted context omitted.

which clause would apply to require a DPO? clause a: not a public body clause b: not systematically monitoring (eg. installing video cameras all over the streets) clause c: not processing large scale sensitive or criminal information. doesn't look to me like a DPO is needed based on this article?

It really comes down to the definition of "systematically monitoring". On our service we capture behavior (say in FullStory) and Google Analytics at a "large scale". How the DPO clause gets interpreted is going to be a key finding in the next few months. This is imho the most confusing and potentially difficult part of GDPR

Not that's irrelevant in this case. The question is whether you're processing sentive PII on a large scale. DPO is only necessary when processing sensitive PII. Sensitive is very clearly defined in the law as race, religion, medical records or biometric data. And IP addresses certainly do not qualify as sensitive PII (they are PII though) so I don't understand the entire discussion here. Seems to be just a political kneejerk

Re: GDPR: Removing Monal from the EU

#725
post #295

Earlier quoted context omitted.

"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.

You have pointed me to the entire content of the GDPR. It's 11 chapters, with 99 articles. I'm unashamed to admit that I don't consider even skimming such a document "easy". I was imagining something more along the lines of a one pager with 4-8 bullet points, each of which was easy to address.

HACCP has nice 7 points, are you comfortable with implementing it on your own? Each country has its own regulator making rules. Restaurants are fined on violations all the time. (20M fine for GDPR violation is upper bound, if you have 10K/month revenue, you are not going to be fined with millions)

https://en.wikipedia.org/wiki/Hazard_analysis_and_critical_c...

Re: GDPR: Removing Monal from the EU

#726
post #643
post #380

Earlier quoted context omitted.

> You are required to comply with the laws of your country, not those of other countries. No, you are required to comply with the laws of any country you do business with. This applies to any type of business, and I don't see why "it's on the internet" appears to be the main counter-argument. If I buy something from you (via snail-mail or on the internet) and it doesn't follow the requirements of the consumer law in…

No. It is quite definitely not true that you must comply with the laws of countries you are not in. The EU is primarily leveraging the fact that most everyone wants to travel to the EU eventually. While you in your home country you have no need to comply with the GDPR unless a treaty between your home country and the EU exists to mandate it. The EU is also leveraging their trade agreements. What they don’t understand…

> No. It is quite definitely not true that you must comply with the laws of countries you are not in.

Unless you wish to do business with that country, in which case you need permission from that country in order to do business with its residents. If you break their laws they can place sanctions against you, and if you find a way to break those you can theoretically be punished legally through extradition.

If you don't do business with those countries then you're off the hook. Obviously.

Just look at the recent Project Gutenberg copyright lawsuit for an example of how breaking the law of a country you are not in can cause you legal troubles.

Re: GDPR: Removing Monal from the EU

#727

Earlier quoted context omitted.

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO). This guy doesn't like regulation and is playing to the crowd for sympathy.

Could you contact me at sudhir.j@moviebuff.com - would like a consult.

Re: GDPR: Removing Monal from the EU

#728
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

Having an app that is non compliant out there induces anxiety. Having 10-20 old or fire-and-forget projects out there, it's anxiety multiplied. There is a non negligible chance that One disgruntled or trolling user or competitor will report you to their country's DPA . There are 28 DPAs and they are not all as good and fair as Germany's or the UK's , they may fine you even if there is no good reason. Example: in my c…

Only the DPA of your country will handle complaints against you.

Re: GDPR: Removing Monal from the EU

#729

I'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement. You certainly don't need to hire extra people like author suggests and federation should be just f…

"Allow removing it" is a pretty big barrier for many.

Smartest, most paid profession in the world and now bunch of those people are incapable of running DELETE SQL queries?

Re: GDPR: Removing Monal from the EU

#730

Earlier quoted context omitted.

This is the furthest thing from true, like almost every single question about this terrible law. Vague law + faceless bureaucracies + universal application + crippling penalties...sounds like a brilliant combo to destroy people’s lives.

as usual, the rebuttal is: there have been this kind of laws in Europe for a decade. For example, if you're operating in Italy and don't provide 2 separate checkboxes for managing personal data directly and indirectly at sign up time you're in breach of the law. Do you remember many people's lifes crippled by this?

Wait. So, I've had a site where there was only a single checkbox to create an account.

Now, if there was someone from Italy (I don't know, the site's gone for years now, highly unlikely but theoretically possible) does this means I'm a possible law offender and should avoid visiting Italy?

Oh, it also had no cookie banners, too...

Could be, the reason no one was hurt is that those laws weren't actually enforced any much? If so, I believe GDPR's promised to be different.

Post reply on HN