Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

931–940 of 957 posts

Re: GDPR: Removing Monal from the EU

#931
post #905

Earlier quoted context omitted.

You're right, there was never a business behind this. It's free software. Why should the creator of free software spend their own money to support users in a region that imposes extra regulations?

>Why should the creator of free software spend their own money to support users in a region that imposes extra regulations? If I create free software that concretely and demonstrably aids in worldwide human trafficking and has negligible utility elsewhere, would you still consider my refusal to comply with regulation reasonable because my software was free? How free the software is not a determining factor, either mo…

Nice strawman. If sometime in the future you want to talk about Monal, let me know.

Re: GDPR: Removing Monal from the EU

#932
post #864

Earlier quoted context omitted.

The U.S. has been doing this for decades, applying U.S. laws to global citizens who happen to travel to the U.S, and I'm not even talking about kidnapping foreign citizens and taking them to Cuba.

You need to travel to the US. They are applying laws domestically. The US is quite opposed to extrajurisdictional law enforcement which is why they don’t sign onto things like the International Criminal Court.

And a US citizen who chooses to break EU law has very little to worry about unless they travel to an EU country, where that country's law will be applied.

Re: GDPR: Removing Monal from the EU

#933
post #750

Earlier quoted context omitted.

Is that £250 each just for GDPR compliance? That's one law in one region. Now multiply it by the number of legislative bodies worldwide and the number of relevant laws passed by each - how much does that cost?

If a business doesn't want to be compliant with the laws of all ~200 sovereign states in the world, they're most welcome to just select a single one and do business there (not the US though, as laws often change for each state so that's right out the door). I'm sure the competitors in the space will love having one fewer competitor.

Complying with the laws of 200 countries is negligible for a big business like Google, a significant burden for a small startup, and a prohibitive expense for a new open source project.

Re: GDPR: Removing Monal from the EU

#934

Earlier quoted context omitted.

Indeed. And the prohibition on raw milk does not ban cheese. Many cheeses from France are still available, because they do not involve raw milk. The EU has passed a law, perhaps it is a worthwhile law. This is one of the consequences. The ban on raw milk in cheese making exists thanks to (presumably) the best intentions, and the end result is that there are many cheeses I would like to buy, that I cannot. An American…

> the prohibition on raw milk does not ban cheese. It bans "raw-milk cheese", which is a distinct kind of product, not one way of many to make a particular product ("cheese"). If you ban raw milk, you ban certain types of product entirely, and there is no workaround. It would be like saying a prohibition on planes does not ban automobiles, and after all, both are a kind of vehicle. True, but not really relevant. Back…

No analogy is perfect. In this case, there are questions that legitimately have no definitive answer (like what is "large scale"), so it is more like the cheese maker genuinely doesn't know whether their milk would be audited as raw-milk or not, and even if they consult with a lawyer they still don't have confidence that they would know.

Re: GDPR: Removing Monal from the EU

#935
post #406

Earlier quoted context omitted.

You are talking about a very narrow set of legal reasons that need 10 years of archiving. This has nothing to do with the GDPR and these archives should really not be created from normal daily/... backups. If you fall into that category you need a lawyer even without the GDPR and this lawyer will tell you exactly what and how to archive. "Nobody really knows" does not apply here because your lawyer knows.

> very narrow set of legal reasons that need 10 years of archiving Invoices for VAT MOSS have to be archived for ten years. And until today nobody really knows (it is another EU law disaster) which information you have to keep to prove the origin of your customer.

Why do you need to keep more information than the invoice itself? All invoices should include the invoice recipients name and address, and thus the country of origin. In many countries invoices below a certain amount can omit the recipient, but you don't need to omit it.

Do you invoice for a different country than the recipients country? Why?

Re: GDPR: Removing Monal from the EU

#936
post #370

Earlier quoted context omitted.

I don't see the problem here (for small companies). If you have a database with user data, and a user deletes his account, you delete the data from production. At this moment, you have a live system without this users data, and some backups with the data. The moment you make a new backup, you have a dataset to restore from that does not include the user data. You keep daily backups for 1 week, and after one week the…

You have a very narrow view about what backups are used for. Which is fine for your business, but for many others, the backups are important business records. What if an employee is stealing from the company, and does it for longer than the time that your business keeps backups? You might say "oh but I keep logs", in which case you have the same problem with keeping the logs that you think you dodged by not keeping t…

Yes and no... the GDPR is all about purpose, and if you keep a log for the purpose of logging unauthorized access to data this is fine if you state this fact in the contract with the employee and only store and access the logs for this purpose.

You just can not keep backups of everything for the purpose of everything.

My example can not include all cases and was written in the spirit of "we are a bunch of devs with a small project". As is monal.im .

Re: GDPR: Removing Monal from the EU

#937
post #817

Earlier quoted context omitted.

https://www.google.com/amp/s/www.xda-developers.com/facebook... Mind you Belgium us 1/30 the size of the US

This lawsuit doesn't seem to stem from the GDPR, despite the article (mistakenly[1]) mentioning it. I don't even know if the regulatory bodies are enforcing the GDPR yet, much less in February this year, or even worse, 2015. Here's a statement from the CPP, connected to the 2015 lawsuit. They mention Facebook being in breach of Belgian privacy laws from 1992. https://www.privacycommission.be/sites/privacycommission/f…

It doesn’t relate to GDPR specifically other than it’s the same regulatory body.

That lawsuit is being interpreted as a signal that they intend to be very aggressive in their enforcement of GDPR.

Re: GDPR: Removing Monal from the EU

#938
post #909

Earlier quoted context omitted.

The sentiment of a law doesn't always translate to the enforcement of it in practice

Similar laws already exist and have existed for a long time. There’s no evidence of disproportionately and illogically large fines having been handed out in the past, and nothing to suggest regulators will start now.

Show me a law where you need to make half a billion euros before the potential fine becomes proportional of your turnover.

It only takes one opportunistic apparatchik to make your life hell and this GDPR thing is now law in such places like Hungary where I haul from and if they can get away with it, trust me, they will go overboard. Maybe not 20M overboard but still.

Re: GDPR: Removing Monal from the EU

#939

Earlier quoted context omitted.

I'm sorry, but I cannot buy the argument that this is in any way, shape, or form related to "free speech".

Free speech of a webmaster being infringed by not allowing them to repeat information that their users gave them. Easy.

Nope. That is not a free speech issue. It is an irresponsible business issue.

Also, no one who actually does this stuff for a living uses the term "webmaster".

Re: GDPR: Removing Monal from the EU

#940

Earlier quoted context omitted.

Well, I'd say it's also not at all rightful in a "what's actually right and good" sense. And as others have pointed out, no the users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do with personal information about their users. But feel free to argue that it is your moral right to sell user's e-mail addresses to some spammer o…

"users don't get to put a leash on webmasters, it just allows the users to retain some degree of control over what the webmasters are allowed to do" I'll let that excerpt speak for itself. And yes, I'm arguing it's anyone's moral right to profit off information voluntarily entered into their website unless a specific agreement was made on the website to the contrary.

A bunch of 3rd party trackers collecting every move you make with your cursor probably won't fit most people's definition of 'voluntarily entered into a website'.
Post reply on HN