Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

751–760 of 957 posts

Re: GDPR: Removing Monal from the EU

#751

Earlier quoted context omitted.

Why are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?

They struggle with it for the same reason people on the political left always struggle to understand why some people oppose new regulations: the question of whether and how to regulate commercial activities is always a proxy for deeper underlying differences in how people view the world. GDPR is just a proxy fight between the left and the right and is showing all the same characteristics. Consider adventured's siblin…

You're bringing your US-American assumptions about politics and left vs right into the context of European politics where they are a poor fit. The world is not Democrats vs Republicans.

There is no GDPR debate or fight: it's done, it was done six years ago, and the only people pushing back are American companies who are unhappy that Europeans don't want their data hoovered up by corporations they have no control or oversight of, for who-knows-what purpose.

Re: GDPR: Removing Monal from the EU

#752

Earlier quoted context omitted.

That's the law in the EU, I think it's natural to have a hobby that doesn't break any laws.

He's not in the EU.

Indeed but he head a TLD from a self-governing dependency which is implementing the GDPR:

https://www.gov.im/about-the-government/data-protection-gdpr...

So he wants the funky TLD from Europe but he doesn't want European law 'hassle'. Hypocritical.

Re: GDPR: Removing Monal from the EU

#753

Earlier quoted context omitted.

as usual, the rebuttal is: there have been this kind of laws in Europe for a decade. For example, if you're operating in Italy and don't provide 2 separate checkboxes for managing personal data directly and indirectly at sign up time you're in breach of the law. Do you remember many people's lifes crippled by this?

Wait. So, I've had a site where there was only a single checkbox to create an account. Now, if there was someone from Italy (I don't know, the site's gone for years now, highly unlikely but theoretically possible) does this means I'm a possible law offender and should avoid visiting Italy? Oh, it also had no cookie banners, too... Could be, the reason no one was hurt is that those laws weren't actually enforced any m…

the GDPR will be enforced by the same entity that was enforcing this before, so why would it be different?

The truth is that obviously the authorities don't have an incentive to come after a minor player.

Re: GDPR: Removing Monal from the EU

#754
post #711

Earlier quoted context omitted.

>this guy sees the law and runs off without even trying to become compliant This guy quite clearly states that he doesn't have resources to become compliant, while it is too risky to make a mistake here. There are fans of GDPR on this website, who prefer to ignore the fact that the compliance has its cost, and added to that still unknown risks of practical interpretation of legislation which also have their cost. But…

Well many of us find it completely normal to spend days on having a good security, setting up HTTPS, encrypting content to protect privacy. I wonder why GDPR seems so different, it's just more of the same, just less technical.

Exactly. It will take a while before standards and best practices form, but they will.

Re: GDPR: Removing Monal from the EU

#755

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

> Indeed, this did not drop out of the sky. It has been in the works for years. VOGON CAPTAIN: [On Speakers] People of Earth your attention please. This is Prostectic Vogon Jeltz of the Galactic Hyperspace Planet Council. As you no doubt will be aware, the plans for the development of the outlying regions of the western spiral arm of the galaxy require the building of a hyperspace express route through your star syst…

Similar laws have been on the books in most if not all EU countries for literally decades. How Americans can be blind sighted by the way things have been for years is absolutely beyond me.

Re: GDPR: Removing Monal from the EU

#756

Earlier quoted context omitted.

Incredibly out of touch. I can virtually guarantee that a regulator or prosecutor who wanted to make an example of him could tear his business apart finding violations over 30+ years.

That's not exactly a new insight, Richelieu beat you to that one a couple of centuries ago. But that's just trying to stretch what we are discussing here: that it is possible to comply with the law in principle. That some overzealous prosecutor with a grudge could nail you might happen - in Russia, maybe even the USA. But frankly where I live I have not yet seen a case like that. We probably have them but not frequen…

Have you been running a socially controversial business? That's where the specifics of the law start to really matter. The butcher, baker and candlestick maker have little to fear from the most badly drafted of laws; it's the person running a skate park or gay bar in a small town who tends to be on the sharp end.

Re: GDPR: Removing Monal from the EU

#757

Earlier quoted context omitted.

I respect his right to do whatever he would like with his own hobby, but we should be clear that the guy is stating he doesn’t have the resources, based on a series of misunderstandings. So, for example, he says he is required to appoint a DPO. The U.K. Information Commissioner has this to say: >Do we need to appoint a Data Protection Officer? A> Under the GDPR, you must appoint a DPO if: > you are a public authority…

That's the UK's interpretation of GDPR. What about France or Poland, or any of the other countries? I suppose it depends where in Europe he would like to visit

That's the UK's straight-forward unequivocal explanation of the rules. Where there is room for interpretation or uncertainty, the ICO is very good at pointing this out. It doesn't here.

As poisan42 points out - it echoes the words in the actual article, directly.

Bottom line, he doesn't need a DPO.

Re: GDPR: Removing Monal from the EU

#758

> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. A DPO is most certainly not required by all organisations[0], and I would be suprised if it applied to this project. I know lots of blogs are saying it is, but it is simply untrue. I'm not saying that this totally relieves the burden however. [0]: https://ico.org.uk/for-organisations/guide-to-the-general-da…

There are certainly allot large organisations that need a DPO, all these companies will compete on a small number of DPO candidates.

How are they suppose to fill the positions by 25th of May?

Re: GDPR: Removing Monal from the EU

#759

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

I also don't understand this reaction, because the guy is the developer of a chat program. It seems that if you encrypt communications and user data and do not sell personal data to third parties, then you comply with the GDPR. I don't see where those bureaucratic hoops come into play this developer is bemoaning.

Re: GDPR: Removing Monal from the EU

#760
post #594

Earlier quoted context omitted.

"you are required to comply with the laws of any country you do business with." Prove that. Because that's not how "the law" works. I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. No other country in the world can just make some "arbitrary" law that affects me. Unless my country agrees. And t…

> I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. If you decide to sell a couch to someone in America, you have to comply with American tax laws, American import and customs laws, American consumer laws, American patent laws, American copyright laws, American trademark laws, and any other law…

> The key question is what happens if you break those laws. In most cases you will be given a fine, and if you don't pay then you will no longer be allowed to sell goods to consumers in that country. If you continue to break the law then you are probably breaking an international treaty on border control or customs, which means that you could be extradited or tried in your own country. Some of the laws I mentioned above are mediated through international agreements, but the fundamental point is that if you break their laws they can place sanctions against you to stop you from doing business with them.

A foreign country could arbitrarily decide I owed them a certain fine, or was no longer allowed into their country, or that they didn't want to allow my products into their country, at any time, whether or not I followed their laws.

In my daily life I've done, and continue to do, things that are illegal under e.g. Iranian law. That's fine and normal - I have no obligation to comply with Iranian law. Iran can make its own decisions about whether e.g. I'm allowed to enter their country, but that would always be the case.

Post reply on HN