Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

881–890 of 957 posts

Re: GDPR: Removing Monal from the EU

#881
post #254

Earlier quoted context omitted.

It really comes down to the definition of "systematically monitoring". On our service we capture behavior (say in FullStory) and Google Analytics at a "large scale". How the DPO clause gets interpreted is going to be a key finding in the next few months. This is imho the most confusing and potentially difficult part of GDPR

Not that's irrelevant in this case. The question is whether you're processing sentive PII on a large scale. DPO is only necessary when processing sensitive PII. Sensitive is very clearly defined in the law as race, religion, medical records or biometric data. And IP addresses certainly do not qualify as sensitive PII (they are PII though) so I don't understand the entire discussion here. Seems to be just a political…

That's fair in this case, at my company we track "pregnancy status" and "due date". It's unclear at this point whether that's considered sensitive PII.

Re: GDPR: Removing Monal from the EU

#882

Earlier quoted context omitted.

You're bringing your US-American assumptions about politics and left vs right into the context of European politics where they are a poor fit. The world is not Democrats vs Republicans. There is no GDPR debate or fight: it's done, it was done six years ago, and the only people pushing back are American companies who are unhappy that Europeans don't want their data hoovered up by corporations they have no control or o…

Sorry, but do you want to say that EU has no left and right in politics (parent post did not mention Democrats or Republicans)? Or that everyone in the EU is unanimously happy with GDPR? Seriously, if a law's getting applied only after a long while it's passed - it's not unheard of to have a debate as people start to actually care. Maybe I'm wrong, but I think that parent example is not US-specific at all and is appl…

First of all, come on, obviously I'm not saying there are left and right in EU politics (and in the national politics of EU countries), but what those left and rights are concerned with don't match 1:1 with the issues under debate in American politics.

Partly because there is a much broader political spectrum -- Democrats in the US roughly line up with, for example, the Conservatives in the UK or the CDU in Germany -- but also because it's just a different set of issues and preoccupations.

I do think it's fair to say that within the EU there is a general consensus about the importance of data privacy, and I also don't detect any resistance to the GDPR in general, or any question that it should be repealed. (That was partly sealed by the revelation of US spying on Europeans a few years ago, which hasn't been forgotten.)

Second, if I'm honest, I find the whole "assumptions about human nature" is a bunch of hokum and quite the opposite of constructive. Nothing about GDPR has to do with "obedience to technocratic elites", and is in fact about rejecting the ability of institutions which are not democratically accountable to gather personal data and monitor people, or make decisions that affect their daily lives, without their informed knowledge and consent.

GDPR is not a "power grab" (hah!), it's about distributing the power that comes from control of information more evenly. The EU has a lot of flaws, but this is one of the most democratic and equalizing bits of regulation that they've produced, and frankly the concessions it makes to large companies are huge.

I don't accept the argument that to be in favor of this I must be in favor of USSR-style totalitarianism. If anything, the inefficient planned economy of VC-funded startups, with their cults of personality around founders, that want to collect data and influence populations with impunity are the petty dictators of the 21st century. Personal rights should trump the rights of corporations, and I am deeply suspicious of people who would equate the two.

But that's all making a mountain out of a molehill: most of what GDPR does is harmonize existing regulation across the EU to make it easier for companies within and outside of Europe to do business here, adds enforcement teeth to the regulatory agencies and harmonizes the penalties, and sets out in actually rather specific detail what is required to be compliant, while giving everyone years to implement this regulation.

If people don't want to comply with GDPR and just block all EU users, then that will make the internet a nicer place for us, so by all means go ahead!

Re: GDPR: Removing Monal from the EU

#883
post #594

Earlier quoted context omitted.

> I am Canadian, my business exists only in Canada, and there are only two types of laws that apply to me. Canadian laws, and treaties that Canada has signed on to comply with. If you decide to sell a couch to someone in America, you have to comply with American tax laws, American import and customs laws, American consumer laws, American patent laws, American copyright laws, American trademark laws, and any other law…

Nope, the buyer has to comply with american tax law. You the seller are not doing business in there.

If you make a profit in America you'd better believe that the US government wants a share of it (there are exceptions if you sign a W8BEN and ask for a tax exemption based on existing international treaties) but the default position is that you pay tax on profits made in foreign countries -- and this applies for any country in the world that has something resembling a capital gains tax.

If you sell electronics that are a fire hazard, you can be punished for breaking consumer laws. I mean, for an extreme example, if you sell an illegal substance in America from overseas you can be punished for breaking those laws too.

Re: GDPR: Removing Monal from the EU

#884
post #866
post #789

Earlier quoted context omitted.

Selling to Saudi Arabians and selling to Saudi Arabia are two entirely different things. In one you're doing conducting business in the Saudi Arabian market, and therefore under the umbrella of their government and in the other you're conducting business in whatever market the person you're selling your alcohol is located at, and under the umbrella of that market's laws.

When an EU business buys a service from an American operating in America from their website hosted in America how is this materially different than when a Saudi Arabian citizen visits New York and buys alcohol? Why would Saudi law apply in New York?

Because the EU business is not located in New York. It's located in the EU. By providing a service to an EU resident you are interacting across the USEU border and thus EU laws restrict what services you can provide across that border. I would recommend thinking about it like shipping products overseas.

Re: GDPR: Removing Monal from the EU

#885
post #850
post #723

Earlier quoted context omitted.

In which case you are doing business with (say) France, which has its own alcohol customs laws that you have to follow. I never said that you have to follow the laws of the country of nationality of your clients. That'd be a ridiculous thing to say, and I'm not sure why you're arguing against that particular strawman (the GDPR only talks about EU residents and doesn't mention EU citizenship at all).

The word choice of citizen vs resident is a red herring. The issue is the extrajurisdictional reach of the law. An EU resident visiting" your business which is hosted and operated in the United States, is the same as a Saudi Arabian coming to the United States to buy alcohol. This is the reason why the GDPR requests an EU designated representative, so there is someone to charge locally.

> An EU resident "visiting" your business which is hosted and operated in the United States

Except the EU resident isn't "visiting" your business, you're providing a service to them across the US-EU border (and just like any cross-border service there are rules). I really don't get why this case is any more complicated than any other kind of consumer law (you can't sell electronics that blatantly catch fire to Australian customers, even if you're based in a country where consumer laws don't exist).

Re: GDPR: Removing Monal from the EU

#886

Earlier quoted context omitted.

> Did they tear down all the houses that don't comply with contemporary building standards? No, they fined everyone that owns homes commercially that did not upgrade the homes to comply. And then fined them again. And again, until they complied.

Where did that happen? There were earthquakes recently in Italy that tore down super-dangerous but not illegal houses. In fact the construction sector is a very bad example here, because old buildings are usually covered by separate regulations , thats not true for software.

In Germany for example with the new environmental regulations. Everyone selling their house, renting it out, etc had to comply.

Re: GDPR: Removing Monal from the EU

#887

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

I built a small shed in my backyard. I didn't follow any building codes. I cooked a meal at home, I didn't follow any food safety standards. I build a gokart from scratch and ride it around my own property. Should any of these be banned? Now if I tell my friend, 'Hey, you can store stuff in my shed/grab a plate of food/take the gokart for a spin', should any of it be banned?

I think you'll find recording a video of your neighbors from your home without their permission will be seen as quite different from your other examples by most people.

Re: GDPR: Removing Monal from the EU

#888

Earlier quoted context omitted.

If I run a soup kitchen and new regulations make it too costly for me to continue, I'm in the right to shut it down if I want. If anyone is against this decision, then they should open their own soup kitchen that meets the new regulations.

That doesn't mean the regulations are bad. Just because the food is given free, doesn't mean you are allowed to poison people

I never said the regulations were bad. I just said that the guy closing his service is just one guy. If one person ran a soup kitchen by themselves and -- because of new regulation -- decided it was too onerous, I would say "Thank you for running the soup kitchen as long as you have. Have a well deserved break." I feel the attitude in this thread is "You ran a service by yourself for X years, and now you're finding it too onerous. You must continue running the service, because i said so". This seems like a weak argument.

Re: GDPR: Removing Monal from the EU

#889

Earlier quoted context omitted.

Why do you feel entitled to invasive tracking of users?

Loaded question. I don't consider targeted ads etc. invasive.

Well it looks like an entire society decided that. Why does your view get to override theirs?

Re: GDPR: Removing Monal from the EU

#890

Earlier quoted context omitted.

> Given him a break vs. trying to me so aggressive in your comment. The article is spreading FUD and inciting others to spread it even further in the comments. > There is a cost associated with trying to figure out GDPR regulations, finding a lawyer, vetting their feedback, acting to hire folks, changing UI to give user an opt out, implementing that in the system etc. The GDPR is online, and has been for a long time,…

Well - you haven't refuted any of his core points wrt DPO, Push & XMPP. All your comments have been stated in an aggressive tone which generally is a negative signal. At this point, I feel you need to provide more context to your core points vs. just saying read the GDPR and comply with it (or that you should have already done 2 yrs back). Even companies like Google and FB are complying with it in the past month.

Google and Facebook have financial impacts in complying due to the very nature of their business.

They comply later than everyone else not because they didn’t see it coming or didn’t prepare for it, just that it wasn’t in their interest to do it earlier

Post reply on HN