Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

91–100 of 957 posts

Re: GDPR: Removing Monal from the EU

#91

I'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement. You certainly don't need to hire extra people like author suggests and federation should be just f…

"Allow removing it" is a pretty big barrier for many.

Then don't keep it ?

We're talking about chat.. you shouldn't be logging the contents, at most a bit of metadata to prevent abuse (eg. a connection log to identify and block spammers).

If you don't store that metadata longer than needed (a couple of weeks? storing it for years would be hard to defend) you have legitimate reasons to keep it, and don't need to worry about deletion requests

Re: GDPR: Removing Monal from the EU

#92
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

BetOnSports, an AIM listed UK company took sports bets over the internet, including from US customers: > In July 2006, their then-CEO, David Carruthers, was arrested while changing planes in Texas on the way to Costa Rica from the U.K. In April 2009 he pleaded guilty to federal racketeering charges, and in January 2010 was sentenced to 33 months in prison.

From Wikipedia:

> BetonSports plc is a British online gambling company founded by Gary Kaplan in 1995. The company was one of the biggest players in the United States online gaming market, drawing in several billion US dollars in wagers in the early 2000s.[1] In June 2006 US authorities indicted the company and a number of its executives on RICO, mail fraud, and tax evasion charges arising from its supplying online betting to customers in the United States (the alleged crimes took place before the adoption of the Unlawful Internet Gambling Enforcement Act of 2006).

This is about federal crimes committed by executives of a billion-dollar company.

OP seems to be a solo open-source project, and violating the GDPR is not a criminal offense. This isn't even close to being comparable.

Re: GDPR: Removing Monal from the EU

#93

My understanding of GDPR, if the logs remain anonymized... i.e. the IP addresses are not correlated with user records, then the solution is compliant. The IP addresses are not considered PII.

When I worked with GDPR compliance we tried and tried but still ended up with the opnion that IP adresses are considered personal information.

Article 4 point 1 in the GDPR indicates this (unless you can somehow prove that the IP is not related to the person, which I think we all know it effectively is in most cases)

Re: GDPR: Removing Monal from the EU

#94

Earlier quoted context omitted.

One misconception about GDPR is that you can ignore it if your company is small. And that's basically what you're saying. And then the next would be that it's inexpensive to "make your case" if you get reported.

No - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.

So when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.

Re: GDPR: Removing Monal from the EU

#95
post #25

> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. Is there any actual requirement within the GDPR that this needs to be a dedicated person, or does being a DPO just need to be someone's responsibility, e.g. in the case of a one-man open source project the guy who runs the project?

https://gdpr-info.eu/art-38-gdpr/

> The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

I guess you could say that it is literally impossible for the DPO to not have conflicts of interest if the DPO is also the owner and manager of the company.

More:

https://ico.org.uk/for-organisations/guide-to-the-general-da...

> The DPO must be independent, an expert in data protection, adequately resourced, and report to the highest management level.

Re: GDPR: Removing Monal from the EU

#96
post #20

>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the…

Are you really can't imagine what state is capable of doing? Not so long ago they packed people on trains to gas them on an industrial scale, and there were people questioning whether this actually happened. Do you think jailing people for not complying with GDPR is not possible? Bookmark this comment and check in 5 years... if this site will even exist by then.

Re: GDPR: Removing Monal from the EU

#97
Many of the comments here are rebutting - saying that a DPO isn't needed or that this guy gave up unnecessarily. But the fact that he had to spend who knows how much of his time to even discover whether he needs to do anything (or what sort of trouble he could get into) is too much of a barrier for many people and their hobby side projects. This is unfortunate and not surprising collateral damage of the GDPR.

Re: GDPR: Removing Monal from the EU

#99
You don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO.

You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR).

If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the user a service and to monitor for app crashes / bugs - both within your legitimate interests.

Many people have interpreted GDPR to be stricter than it is. In fact, those who have to do the most work are those that cause incredible damage to individuals when they lose data - especially those that have had recent, massive data breaches e.g Equifax.

Re: GDPR: Removing Monal from the EU

#100

Earlier quoted context omitted.

these assurances from internet forums are great and all, but hwy take such risk?

Risk is a part of life. Even before GDPR there was a risk that you were violating some privacy law in countries that your customers were connecting from. By putting your product out there, you've taken on most of this risk already.

There was a previous 1995 directive for instance. It didn't have the teeth of GDPR, but was actually rather similar. It would be hard to be compliant with That and in breach of GDPR.

That rather makes the anti GDPR arguement sound like "yes I know that is the law, but I was breaking it over the internet so that doesn't count"

Post reply on HN