Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

941–950 of 957 posts

Re: GDPR: Removing Monal from the EU

#941

Earlier quoted context omitted.

If you read the article, you would find out that this is the essence basically. "As GDPR approaches, I get the impression that it is an end of an era for the internet. The days of someone making something, putting it on the internet and offering it to the world seem to be over. " And this particular thing GDPR ruins pretty goddamn well.

Bullshit. That era existed before everything was analyzed and monetized and PII was packaged and sold as a commodity. GDPR ruins invasion of privacy for profit.

and open source.

Re: GDPR: Removing Monal from the EU

#942
post #941

Earlier quoted context omitted.

Bullshit. That era existed before everything was analyzed and monetized and PII was packaged and sold as a commodity. GDPR ruins invasion of privacy for profit.

and open source.

Nothing about open source depends on invasion of privacy, unless what you’re open sourcing is data mining the public, in which case... blow.

Re: GDPR: Removing Monal from the EU

#943
post #41

Earlier quoted context omitted.

That makes a valid point: You should open a bug with Apache to remove IP address and User-Agent from the default log formats, as they should not be logged by default or else GDPR issues arise.

You can log IP addresses if there is a legitimate use for them. You just need to ensure that they are protected and that you do not keep them for any longer than is necessary (= use logrotate).

Logging them by default is a silent opt-in to a scenario where you are legally obligated to protect data you may not even know exists.

Anyone whose software logs IPs by default should stop, so that the admins who choose to log IPs must voluntarily choose to log protected information and handle it appropriately.

Re: GDPR: Removing Monal from the EU

#944

Earlier quoted context omitted.

I think it can simply be GDPR compliant if you inform your users that you are saving that data in your database, and they give you the explicit OK to do to. Explicit consent meaning they tick a checkbox saying "I understand that page x is saving the data y in a database and I am OK with it". If you have a site where users can make posts, I'd say they pretty much give you consent by signing up. IANAL, though.

The consent has to be explicit. Of course, you can always just require consent in order to sign up. Just as long as it's clear what's going on and you can remove/anonymise the data if the user decides to revoke their consent and leave the service.

OK, but explicit in what sense? Does it have to refer to the GDPR, as in "I agree my dta will be stored according to GDPR"? I must admit I have trouble understanding it - how could anybody sign up anywhere without data being stored?

Re: GDPR: Removing Monal from the EU

#945

Earlier quoted context omitted.

GDPR compliance takes resources. I would say for a small business it takes about 1 or 2 days. Not hard work but tedious. In the end you will have around 5 documents that will show your processes, what you do to keep data save, a plan how you deal with questions from customers and regulators, that you trained your employees and that you choose your subs carefully. Essentially that's it. I am no lawyer but I am a CPO.…

I guess you are EU-based, unlike the guy whose text we are debating here.

Yes - I guess having an EU contact is something not easy to come by on the other hand there might soon be a service for it.

I guess an XMPP Server could be considered a communication service an could be subject not to the GDPR but to regulations concerning ISPs and Phone companies.

Re: GDPR: Removing Monal from the EU

#946

Earlier quoted context omitted.

Free speech of a webmaster being infringed by not allowing them to repeat information that their users gave them. Easy.

Nope. That is not a free speech issue. It is an irresponsible business issue. Also, no one who actually does this stuff for a living uses the term "webmaster".

>Also, no one who actually does this stuff for a living uses the term "webmaster".

Have I been hallucinating my workplace this whole time?

Re: GDPR: Removing Monal from the EU

#947
post #935

Earlier quoted context omitted.

> very narrow set of legal reasons that need 10 years of archiving Invoices for VAT MOSS have to be archived for ten years. And until today nobody really knows (it is another EU law disaster) which information you have to keep to prove the origin of your customer.

Why do you need to keep more information than the invoice itself? All invoices should include the invoice recipients name and address, and thus the country of origin. In many countries invoices below a certain amount can omit the recipient, but you don't need to omit it. Do you invoice for a different country than the recipients country? Why?

From https://europa.eu/youreurope/business/vat-customs/moss-schem...:

> the information used to determine the place where the customer is established or has their permanent address or usually resides.

Sadly this regulation doesn't specify which kind of information this could be.

Your customer could try to get a better price by pretending to be from a country without VAT. Therefore the address given by the customer is more or less worthless in this regards. One more realistic information is the IP address. But as this also is pretty easy to spoof it might be reasonable to also keep information about the country were the cc card was issued, if possible.

Re: GDPR: Removing Monal from the EU

#948

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

It is impossible to sell raw-milk cheese in the United States. Are French cheese makers overreacting by simply choosing not to do business here rather than change their centuries-old production techniques? It is illegal to sell kinder eggs in the US, because of some law that involves children accidentally swallowing toys. Is Kinder overreacting by refusing to sell those candies here? You cannot buy Bovril in the US,…

> It is impossible to sell raw-milk cheese in the United States

No, it's not, but it is legally imposible to import them, and trade them in interstate commerce (many—I think still a majority—of states allow raw milk and raw milk products, though the FDA prohibits most directly and sets standards which effectively prohibit the rest in interstate commerce, including foreign imports.)

Not that that really changes the point you are illustrating.

Re: GDPR: Removing Monal from the EU

#949
post #218

Earlier quoted context omitted.

I suspect it's going to be a bit like IR35 in the UK. Menacing on first glance, but so broad in it's definition that any court is going to struggle to draw the hard conclusions for anything that isn't what the law was explicitly created to prevent.

Having to rely so much on the discretion of the courts is not a good thing. Generally, it is better if all people who agree on what happened agree about the legality of that. When instead it is up for interpretation, that comes with issues. The first is selective enforcement, there is also the chilling effect on both sides. Those who ought to be protected worry about the slack given to their potential predators. Mean…

I don’t agree. All laws are up for interpretation. That’s why we have the judiciary. Law makers draft laws, courts decide where those laws fit into the wider body of law.

The kind of law making you’re implicitly advocating is tantamount to despotism. Drafting a law that outlaws islam might well be clear in it’s wording, but it needs to be tested against the law that allows freedom of religion, freedom from persecution, and a ton of other laws no doubt. The claritiy of language with which a ban on islam is articulated is all for nought if it’s contradicted by, and incompatible with other laws.

Although, GDPR has been explained very clearly. And we’ve been given a loooong time to digest, understand, implement, and question it. I don’t think any reasoable person can make a compelling case against GDPR. But unreasonable people can, and as we’re seeing, they will.

Re: GDPR: Removing Monal from the EU

#950

Earlier quoted context omitted.

I guess I am a fan of GDPR, certainly compliance to anything has a cost. I personally don't find the costs of GDPR compliance onerous unless you have already built up lots of non compliant systems that now need to be fixed, in which case the free ride is over. Anyway, this guy is pulling out of the EU but if he allows anyone from the EU to use his service from a non-EU location anyway he would be risking non-complian…

no. gdpr applies only to people in the eu. if you are an eu person in canada it does not apply to you.

you're right, it seems a few people have been making the same mistake about eu citizens that I've made.
Post reply on HN