34 ms·
GDPR: Removing Monal from the EU
- viraptor 8y agoI'm both surprised that people react so strongly and... mostly ok with it. Majority of GDPR is pretty reasonable - know what data you have and make sure your users know it as well. Allow removing it, make sure you don't share with parties who don't need it. For normal services it doesn't appear to be a tough retirement. You certainly don't need to hire extra people like author suggests and federation should be just fine. (it's essential to what the service does)
- GalacticDomin8r 8y ago"Allow removing it" is a pretty big barrier for many.
- elephant0xffff 8y agoWhy?
- dbbk 8y agoYou can just do it manually... I have a feeling deletion requests will be pretty few and far between anyway.
- kasey_junk 8y agoThere are already services that are automating them for you. They send to 2-300 companies on your behalf.
- GordonS 8y agoI was going to say the same thing. If you're an individual running an OSS service, or a small business, requests for information or deleting information really are going to be really rare. This really isn't a burden.
- unilynx 8y agoThen don't keep it ? We're talking about chat.. you shouldn't be logging the contents, at most a bit of metadata to prevent abuse (eg. a connection log to identify and block spammers). If you don't store that metadata longer than needed (a couple of weeks? storing it for years would be hard to defend) you have legitimate reasons to keep it, and don't need to worry about deletion requests
- GalacticDomin8r 8y ago> We're talking about chat.. The comment I replied to seemed to reference far more than chat.
- viraptor 8y agoThat's why I mentioned I'm ok with projects reacting strongly and removing themselves. Removing my info (and many other GDPR points) is in my interest. If they can't do this, I'm glad I won't be their immortal user.
- izacus 8y agoSmartest, most paid profession in the world and now bunch of those people are incapable of running DELETE SQL queries?
- iaml 8y agoGood luck running sql queries on your tape backup or event sourcing backend.
- treve 8y agoTwo questions come to mind: 1. Isn't this person allowed to be the Data Protection Officer themselves? 2. Is APNS inherently not compliant or if there something unique about this use-case? What's kind of great about this new regulation is that we get a clear view on businesses that can't adequately protect user's privacy. It's painful for businesses such as these, but ultimately it seems that consumers would come ahead of it. If the weak link in this case may not have been the developer themselves, but external factors but it's still a pretty interesting data point.
- DanBC 8y agoThis person doesn't need a DPO.
- elephant0xffff 8y agoI don't really get it. So what's the burden for the developer here - he argues that the IP is PII (personally identifiable information), which is true, but I don't think it means you can't log IPs in general anymore? So is now every standard apache2 installation a non-compliant (illegal?) service, as it logs GETs? I don't think that's the case. //edit: It seems to be the case that you are ok if you do log-rotation and delete old ones - which makes sense, so you can still use them for debugging.
- floatingatoll 8y agoThat makes a valid point: You should open a bug with Apache to remove IP address and User-Agent from the default log formats, as they should not be logged by default or else GDPR issues arise.
- Hamuko 8y agoYou can log IP addresses if there is a legitimate use for them. You just need to ensure that they are protected and that you do not keep them for any longer than is necessary (= use logrotate).
- GordonS 8y agoAs someone who both owns a small business and is a consumer, this seems completely reasonable to me. The GDPR has really made me think about minimising the collection of data that I don't need - absolutely a good thing.
- floatingatoll 8y agoLogging them by default is a silent opt-in to a scenario where you are legally obligated to protect data you may not even know exists. Anyone whose software logs IPs by default should stop, so that the admins who choose to log IPs must voluntarily choose to log protected information and handle it appropriately.
- slackoverflower 8y agoPretty sure that is exactly the case. GDPR went all out on user privacy that is simply a burden for small businesses to deal with EU citizens, it's financially more sensible to just block the entire EU from their services.
- floatingatoll 8y agoDoes GDPR have any non-monetary enforcement? For a site with no revenue, can they take any action other than a $0 fine?
- fasteddie 8y ago20m euro or 4% of revenue, whichever is higher, is the max fine. Up to the individual to say how truly likely it is a small revenueless project could possibly get fined, even with large amounts of malfeasance.
- brokencube 8y agoIt has a maximum, not a minimum: The higher of 4% turnover OR €20m. That means even with 0 revenue, your fine can be up to €20m (It won't, because if you're not making money your small fry to them, but still, the fine can be greater than 0)
- ucaetano 8y ago> Does GDPR have any non-monetary enforcement? Yes: https://gdpr-info.eu/art-84-gdpr/ https://gdpr-info.eu/art-84-gdpr/ > Member States shall lay down the rules on other penalties applicable to infringements of this Regulation So every country can create whatever penalties they want, as long as they are "effective, proportionate and dissuasive".
- slackoverflower 8y agoI'm convinced this is the start where EU citizens become second class Internet users. Many businesses just don't want to go through the troubles of GDPR regulatory hoops. For most businesses, there's enough customers to sustain their business in the US, Canada, rest of the world that they can ignore all EU customers.
- alex7o 8y agoThis might actually be a good thing, as it will open the opportunity for European companies to step up and fill the gaps.
- badsectoracula 8y agoIt doesn't have to be European companies, an American (or Japanese or any other place) company can go and fill the role as long as they follow GDPR.
- nickpp 8y agoAre you preparing to start such a company? I know zero funders excited about regulation. About technology and platforms, sure. But never about regulation. Only lawyers get excited about that.
- SahAssar 8y agoI'm guessing they would be interested in 550m unserved users in a single-market for a validated business idea, regardless of GDPR.
- nickpp 8y agoMaybe, but GDPR is not the only business-hostile regulation EU has. Together they make an environment in which even 550m users may not be worth it for the small startup. They will simply pivot to the more competitive, but freer, US market.
- 8y ago
- snogaraleal 8y agoYou do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
- drcode 8y agoReading the FAQ, the only way to really safely ignore the DPO provision would be to hire a law firm with GDPR expertise to parse the vague language in the law and to give written guidance as to whether the law applies to each specific web site, which you can then present to EU authorities in the future to show you performed due diligence to try to meet the requirements of the law.
- jimnotgym 8y agoI can only think you are not familiar with European principle based law vs US rule based law. Where you see 'vague', I see 'flexible' and 'able to move with the times'
- yesco 8y agoHave you considered that a law being "flexible" and "able to move with the times" is exactly why someone wouldn't like it being vague? A law that is "flexible" means that it's a law that can be arbitrarily applied. A law that can "move with the times" means that what might be fine now won't be fine later and just maybe you will be the first to find out. It doesn't matter if European law has a history of being "principle based", if it can fuck you then someday it just might. Europeans might be fine with this, but I think most Americans would not be. If I was in OP's position I would do the same thing, by simply blocking an IP range all possibility of being made an example of by some people from another continent is flushed down the drain. I'm absolutely baffled why people think this is absurd, if you're not even making any income off of it, why would you ever open yourself up to such expensive potential liability?
- jimnotgym 8y agoI think comments like that just open you up to rather obvious jibes about how long European law has been around vs the US. I will leave the reader to make their own jokes.
- jimnotgym 8y ago> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. A DPO is most certainly not required by all organisations[0], and I would be suprised if it applied to this project. I know lots of blogs are saying it is, but it is simply untrue. I'm not saying that this totally relieves the burden however. [0]:https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- tobltobs 8y ago> most certainly not ... but it is simply untrue. Most certainly simply untrue?
- eindiran 8y agoThere are two sentences there. A lot of people are claiming that a DPO is required. GP is saying that a DPO is most certainly not required and that the claim [that a DPO is required] is simply untrue.
- chernobogdan 8y agoThere are certainly allot large organisations that need a DPO, all these companies will compete on a small number of DPO candidates. How are they suppose to fill the positions by 25th of May?
- noobiemcfoob 8y agoAnother one bites the dust /Where dust == blocking EU
- coldacid 8y agoAnd won't be the last either, I bet.
- Hamuko 8y ago>I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. >1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10. I thought this guy was a single person who put something on Github. How is he required to appoint a DPO? What kind of large-scale processing of personal information is he doing?
- BinaryIdiot 8y agoEven if he was _required_ to appoint one (which I don't see how he is), he can appointment himself to do it. It's really not a huge deal...
- CobrastanJorji 8y agoI don't think he can. The DPO may not be assigned any tasks that would result in a conflict of interest between their role as a DPO and their other responsibilities. I suspect that means that the sole proprietor can't be the DPO. But, you know, not a lawyer, not even European, could be wrong. See article 38, paragraph 6, 2nd sentence.
- BinaryIdiot 8y agoYup, I read that and I don't see how it would be in the conflict of interest for probably the vast majority of cases. But, yeah, I'm not a lawyer too. Edit: DPO Network says this which I think is a pretty good summary (though it's not part of the explicit legal policy, it's someone's opinion) > CAN WE ASSIGN ONE OF OUR EMPLOYEES AS OUR DPO? > Yes. However, you must ensure that other professional duties of this employee must be compatible with his/her new duties as DPO and do not result in a conflict of interests. https://www.dponetwork.eu/faqs.html https://www.dponetwork.eu/faqs.html
- eterm 8y agoWhy not give the user control and have things such as crash reporting be opt-in? We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls and I think it's great that the EU GDPR is making people wake up to the scale of it. Suggesting that XMPP federation isn't compatible with GDPR seems like an over-reaction, isn't that like saying that SMTP isn't compatible?
- donohoe 8y agoYeah, they are over-reacting. For example, IP addresses are considered personal information but what that means is you just can't blindly collect them. If the service you use relies on IP addresses as a basic point of operation then its fine. CDNs aren't going out of business for example.
- islanderfun 8y ago> that means is you just can't blindly collect them Genuinely curious, what about all of the web servers that log every request which usually by default includes the client IP? Not doing anything special with the IP, they are just there in log files and archives.
- jtl999 8y ago`tail /var/log/nginx/access.log` Oops. Also the section of the GDPR that talks about pseudonymization using a token how should my user DB table be GDPR compliant? Contains ID (primary key), username, password hash, email, etc and the ID is also in other DB tables for obvious reasons (such as user posts/actions).
- jesdjkeujjuju 8y agoI think it can simply be GDPR compliant if you inform your users that you are saving that data in your database, and they give you the explicit OK to do to. Explicit consent meaning they tick a checkbox saying "I understand that page x is saving the data y in a database and I am OK with it". If you have a site where users can make posts, I'd say they pretty much give you consent by signing up. IANAL, though.
- mnkypete 8y agoThere is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-you-know-about-the-gdpr-and-why-you-may-be-wrong https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
- dmacedo 8y agoAnother good read on DPO role: http://www.ascentor.co.uk/2017/06/gdpr-data-protection-officer-dpo/ http://www.ascentor.co.uk/2017/06/gdpr-data-protection-offic...
- zerostar07 8y agoHaving an app that is non compliant out there induces anxiety. Having 10-20 old or fire-and-forget projects out there, it's anxiety multiplied. There is a non negligible chance that One disgruntled or trolling user or competitor will report you to their country's DPA . There are 28 DPAs and they are not all as good and fair as Germany's or the UK's , they may fine you even if there is no good reason. Example: in my country the DPA fined a company last week (3000 euros) because they searched a company's computer while the employee was not present, even though they found that the computer did not contain any personal information.
- hvidgaard 8y agoOnly the DPA of your country will handle complaints against you.
- zerostar07 8y agoBut for those outside the EU, any of the 28 DPAs can fine their company. Also, i think the DPAs can fine any company in the EU, not just the companies of the country the DPA is in.
- ucaetano 8y ago
- 5874-4b22-a4e0 8y agoHow would they even enforce GDPR? Can't companies just claim to clear your data?
- AnsisMalins 8y agoGuessing: even if you don't have assets in EU, you have a Google (or Facebook, or Amazon) account, and Google has assets in EU. EU could ask Google to ban you, or else.
- pluto9 8y agoThat seems like a bit of a stretch, unless you were actively using Google's services as a tool of your wrongdoing. The EU would be forcing an unrelated private company to act as an arm of law enforcement. It would be like the local police punishing you for speeding by leaning on Applebee's to refuse you service. Maybe there's a legal precedent for that sort of thing, but I'm not aware of it.
- yladiz 8y agoYou can be audited by the government to verify you're correctly deleting data.
- pavlov 8y ago>... I frequent Europe and do not want to get into legal trouble on vacation. Does the author seriously believe this could happen? Enforcement of GDPR is similar to antitrust law. A regular police officer isn't going to fine you for that. The author's anxiety makes as much sense as not traveling to the United States because you're worried that your one-person pottery business might be considered a monopoly under the Sherman Act.
- kybernetikos 8y agoBetOnSports, an AIM listed UK company took sports bets over the internet, including from US customers: > In July 2006, their then-CEO, David Carruthers, was arrested while changing planes in Texas on the way to Costa Rica from the U.K. In April 2009 he pleaded guilty to federal racketeering charges, and in January 2010 was sentenced to 33 months in prison.
- anonymouz 8y agoFrom Wikipedia: > BetonSports plc is a British online gambling company founded by Gary Kaplan in 1995. The company was one of the biggest players in the United States online gaming market, drawing in several billion US dollars in wagers in the early 2000s.[1] In June 2006 US authorities indicted the company and a number of its executives on RICO, mail fraud, and tax evasion charges arising from its supplying online betting to customers in the United States (the alleged crimes took place before the adoption of the Unlawful Internet Gambling Enforcement Act of 2006). This is about federal crimes committed by executives of a billion-dollar company. OP seems to be a solo open-source project, and violating the GDPR is not a criminal offense. This isn't even close to being comparable.
- deleted 8y ago[deleted]
- kybernetikos 8y agoWhile I agree that violating the GDPR is much less likely to result in being pulled off a plane than running a company that allows people to gasp gamble on the internet, your characterisation of the problem as 'federal crimes' seems to suggest that there was something much more nefarious going on than simply allowing people in another jurisdiction to do something over the internet that is completely legal in the jurisdiction you are based in. I could be wrong, but according to my understanding, that's not the case. The 'federal crimes', were precisely enabling US customers to gamble over their phone lines. That was enough to get a publicly traded company in a friendly nation categorised as 'organised crime'. The other thing you mention about how it's not a criminal offense is something important a lot of people seem to be missing. If you're violating the GDPR and someone notices, the first thing that happens is that they work with you to try to correct the problem, not that they hit you with huge fines and laugh while twirling their mustaches.
- avar 8y ago> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. Is there any actual requirement within the GDPR that this needs to be a dedicated person, or does being a DPO just need to be someone's responsibility, e.g. in the case of a one-man open source project the guy who runs the project?
- jimnotgym 8y agoNo there is no requirement for most bodies at all. Please see my other comments on this discussion. A person at my company is called the DPO, but that is far from their main role in the business
- ucaetano 8y agohttps://gdpr-info.eu/art-38-gdpr/ https://gdpr-info.eu/art-38-gdpr/ > The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. I guess you could say that it is literally impossible for the DPO to not have conflicts of interest if the DPO is also the owner and manager of the company. More: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/ https://ico.org.uk/for-organisations/guide-to-the-general-da... > The DPO must be independent, an expert in data protection, adequately resourced, and report to the highest management level.
- unilynx 8y agoWell, if you're owner and manager, I think you've got the independence, adequately resourced and reporting about right. If you're a sole proprietor and managing data at volume and sensitivity levels that a DPO is required, I hope you're an expert at protecting that data..
- howard941 8y agoIf I continue to maintain mail and web server syslogd logs and Europeans access one of the swervers do I risk getting nailed under the GDPR?
- matchagaucho 8y agoMy understanding of GDPR, if the logs remain anonymized... i.e. the IP addresses are not correlated with user records, then the solution is compliant. The IP addresses are not considered PII.
- TomasEkeli 8y agoWhen I worked with GDPR compliance we tried and tried but still ended up with the opnion that IP adresses are considered personal information. Article 4 point 1 in the GDPR indicates this (unless you can somehow prove that the IP is not related to the person, which I think we all know it effectively is in most cases)
- kasey_junk 8y agoPII is not a GDPR concept. Most opinions (including the GDPR faq) will tell you IP is personal data.
- TomasEkeli 8y agoI keep telling people - the thing that changes with GDPR is that personal data you handle is now still owned by the person and only in your custody as long as they explicitly allow it. All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data. I don't have any knowledge about monal.im (don't know what it is - some kind of im client?), but this person is making some claims: - he needs a data-protection officer: no, only larger orgs handling lots of personal data need this. If he's making an im-client and not servers that store data he certainly doesn't, but I don't know what his setup is. - crash analytics: This can be handled by telling the users clearly that you'll be gathering the data (and defaulting to not gathering if they don't actively approve). As long as you have a proper PURPOSE for gathering and storing the data and don't use it for anything else you're golden. You do have to document this, in case of a review (hyper-unlikely). - Push: he's getting a message and storing the device/ip combination. This seems to be central to the service he's providing. Therefore he can and should put that in the description/terms of his service (as he cannot deliver the service without this). As long as it is clearly explained to the end-user this is fine, and he can keep doing it. If he stores it and does anything with this data other than the central purpose that he informed the end-user of he's in violation. I'd suggest putting it in clear text in front of the end-user and deleting the data as soon as it's no longer needed. Don't do any non-approved analysis on it. If you want to analyse - ask for permission. XMPP federation may be a problem, I agree with that. The problemer here (as I see it) is that each service getting the personal data must only process it for the purposes explicitly agreed to by the end-user and honour any subsequent notifications of rectification and deletion. This is a hard nut to crack indeed.
- benjaminl 8y agoSMTP is federated. Did GDPR outlaw email? I am assuming the answer is no, but would a startup be able to build a SMTP or NNPT like system today? It would be a shame for the GDPR to be yet another force moving the Internet from its historical decentralization reinforcing the current centralization trend.
- tobltobs 8y ago> no, only larger orgs handling lots of personal data need this. I can't find any exemption for small companies in Article 37 of the GDPR. Can you give me a hint what part do you interpret this way?
- BillinghamJ 8y agoThis project is completely out of scope for GDPR, not having any presence whatsoever in the EU. You aren't going to be arrested when going on holiday. You wouldn't be breaking the law at all, even if it was possible to enforce anything. Even if it was in the EU, it wouldn't require a DPO, and your use of IP addresses is very reasonable and within the standard allowances which don't require user consent. Maybe bother reading _anything_ from an official source before coming to this conclusion? This reads to me more as something you want to have a rant about because you don't like it - rather than as any kind of pragmatic decision.
- kasey_junk 8y agoDisclaimer: I work on GDPR stuff for a company it certainly applies to, this is my opinion not my companies We’ve spent tons of money & interacted with lots of official sources trying to get opinions about what GDPR means and it just isn’t available. Everything is a risk mitigation technique right now with no real answers in sight. If I had any personal projects serving traffic in the EU right now that weren’t profitable I’d likely shut them down. I think it’s likely that the regulatory agencies will act with restraint and this will all be hysteria without merit, but I’ve seen enough legal opinions to know that’s not the worst case scenario.
- ascorbic 8y agoWhat are you talking about? There's a ton of information about what GDPR means, both from the EU and the national regulators (particularly the ICO). The best sign that the regulators aren't going to go crazy with this, is that they already have quite significant powers and they're not throwing their weight around now.
- kasey_junk 8y agohttps://www.google.com/amp/s/www.xda-developers.com/facebook-privacy-lawsuit-belgium/amp/ https://www.google.com/amp/s/www.xda-developers.com/facebook... Mind you Belgium us 1/30 the size of the US
- maufl 8y agoPlease be nice to the developer. I didn't post it to shame him. I'm just very sad about the post because I was hoping to establish XMPP as the group chat in my family, of which half are iPhone users.
- kodablah 8y agoJust curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?
- tobltobs 8y agoIf the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?
- kodablah 8y agoI think everyone already knows that more regulations hurt businesses. We don't have to wait for the result to find that out. The question is whether the help done to consumers outweighs that. There are many ways to tackle the privacy issue beyond a large, sweeping law.
- bkor 8y ago> I think everyone already knows that more regulations hurt businesses. That's not a given. Further, it's more important to look at what's better for society as a whole. Further, less regulation within banking caused some big profits.. but also some hefty problems.
- badsectoracula 8y ago
- merinowool 8y agoComments here only show how terrible this law is, as nobody has a clue how to interpret the requirements. EU direction is simple - cripple the internet so that only handful of companies could afford to navigate regulational hurdles and that way it will be easier for bureaucrats to control it. Any small initiative kill with fines. In few years internet will be under full control of socialist regime and people are sleep walking into new reality with the help of do-gooders.
- deleted 8y ago[deleted]
- rwcarlsen 8y agoMany of the comments here are rebutting - saying that a DPO isn't needed or that this guy gave up unnecessarily. But the fact that he had to spend who knows how much of his time to even discover whether he needs to do anything (or what sort of trouble he could get into) is too much of a barrier for many people and their hobby side projects. This is unfortunate and not surprising collateral damage of the GDPR.
- GordonS 8y agoI'm a small businesses owner. When I first found out about the GDPR, this was exactly my view, and I even posted on HN to that effect. Then I actually spent a little time to find out more and, as someone who cares about privacy, quickly realised the positive intent behind it, and how simple it is to comply with in principle: let users know what data you collect and what you do with it, and give them the possibility to request it or request it's deleted. TBH, if someone requested any of this, I'd do it without the GDPR.
- jwdunne 8y agoYou don't need a DPO. I work with healthcare businesses and some of them don't even need a DPO. You only need a DPO if you are a public authority, if you do large scale processing or large scale processing of sensitive data (ambiguous in the GDPR). If you collect some data, all you need is a privacy policy outlining such, stating what you collect in general and that your legal basis for doing so is to provide the user a service and to monitor for app crashes / bugs - both within your legitimate interests. Many people have interpreted GDPR to be stricter than it is. In fact, those who have to do the most work are those that cause incredible damage to individuals when they lose data - especially those that have had recent, massive data breaches e.g Equifax.
- sparrish 8y agoI'd feel better if there were a definition of 'large scale' somewhere but the official documents are just too ambiguous. Are 1 million IPs in my logs 'large scale'?
- djsumdog 8y agoIt really should be defined by company size or revenue. If I my site goes viral and a small web app suddenly has 2M lines of logs, but my revenue is small/non-existent, then there's no reason to comply. If that pushes my revenue over 1M euros a year, you now get pushed into a zone where you should be compliant, and you have enough revenue to afford it as well.
- gervase 8y agoAnother comment in this thread indicated that "large scale" was any business in which 5 employees or more had access to the data in the course of normal business operations. Not exactly an ironclad source, but better than nothing, hopefully.
- theclaw 8y agoPossibly but they are not "sensitive data" (aka "special categories of personal data"). Article 9 of the GDPR outlines what these special categories are: "personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, [...] genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation"
- djhworld 8y agoIt seems to me like he's overreacting a bit I get that the GDPR regulations seem quite complex and daunting but his usecase seems pretty simple to me.
- belorn 8y ago> registering for a push does make an HTTP call which logs a user’s IP and this requires GDPR compliance. APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server. Obviously, this is needed for a notification to be delivered to the right person. Article 6, Paragraph 1, seems to cover those two parts of data collection. Logging a user's IP for security is acceptable, as is logging for a legitimate interests of the user (or operator) as long as it do not conflict with the interest of the data subject in regard to their need for data protection. APNS push tokens seems to fit that description quite well.
- GordonS 8y agoAgreed, I don't see how this possibly cannot be a legitimate interest - the user knows they need to be contacted for a push request to work, even if they don't understand or care about the underlying vagaries of IP addresses.
- hackersword 8y agoit covers it ... except when it doesn't. Which is open to 'interpretation' Where is the scale balanced on this ... will it be the same in each of the different countries implemeting it? >as long as it do not conflict with the interest of the data subject in regard to their need for data protection Article 6.1.f >processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. So ... I can retain IP records in my logs , as long as they aren't a child?
- belorn 8y agoIn regard to children I view it as part of two different interpretations. One is that data in regard to children need to be considered with extra care and in those cases that the process is written down or is more formal then that consideration need to addressed. The other way to see it is a bridge to the US regulation COPPA, where operators in the US and EU now have to follow the same rules in regard to children. In this case Monal would have to move out of both EU and US in order to avoid the regulations in regard to children.
- zerostar07 8y agoWhile this developer may be overreacting (he probably doesn't need a DPO), i understand why it might just be easier to block it , at least until there are precedents about how to comply and more info on how the regulation will be enforced. GDPR can be scary for developers, because nobody actually knows how a website or app is supposed to work (I have yet to see a single example), and it requires a series of steps that are not trivial on the administrative side. The Right to be forgotten is the easy part. Having to document everything you do and introduce data-dumping mechanisms that are both anonymous and secure is administrative burden. Having to do that for every little project that you release, even if it has 10 users, is a bit too much. Many developers cast a wide net, releasing products often, and this is practically unnecessary work unless you have a significant amount of users. Introducing opt-in forms everywhere is also not great. It didn't work for Windows Vista so why do we expect this to work on the web? Opt-ins for things like cookies should be implemented on the browser. What's the point of warning a person before sharing their email? What's the point of warning them even you 'll install a cookie? IP addresses and cookies etc are integral parts of the HTTP protocol and the browser so why not introduce anti-tracking regulation that targets browser vendors and telcos instead of introducing regulation that targets every developer on the planet? It doesn't seem like an optimal plan imho. The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one. It's easy for US developers to be positive of GDPR because they can avoid the overreaching parts, but for us in the EU its something we have to abide by 100% of the time. I 'd like to hear what other people think about those, because otherwise i hear a lot of emotional praise for GDPR which is blind to how problematic it is at day 0.
- slrz 8y ago> The example of the cookie law (for which it's hard to argue that it has not utterly failed) should act as a bad precedent, not a good one. It is an utter failure but mostly because services try hard to turn it into a travesty and simultaneously manage to deceive their users by attributing blame for the annoying cookie warnings to regulators. "We are required by law to show you this stupid warning because our site uses advanced features that need cookies to work. Without them, you couldn't even login! (OK)" Which, of course, is utter bullshit. If you can stop this deception, things might actually work out as intended. Sites may rethink their need for personal data gathering if cookie warnings would have to look more like the following. "We'd like to analyze your site usage for ad targeting and other things that make us some more money. Do you agree we use cookies for that? (yes/no) NOTE: Even if you disagree, standard site functionality like logins will continue to work unharmed."
- kybernetikos 8y ago> Obviously, this is needed for a notification to be delivered to the right person. This seems pretty clearly a case of 'Legitimate Interest'. Filling in a couple of page word document (a LIA) and keeping it somewhere on the off-chance that someone queries you, is likely sufficient from my understanding. (This is not legal advice).
- Tomte 8y agoNever heard of Monal. We won‘t miss it.
- tobltobs 8y agoPluralis Majestatis?
- draw_down 8y agoI don't think you can have it both ways- some things will close down/leave EU over this because they can't afford to comply, or rather they can't afford the risk of being found noncompliant. I think the law is at the very least a good start, but like they say, you have to break some eggs to make an omelet. It's easy to claim over-reaction when it's not your hide at risk.
- fcbrooklyn 8y agoEvery time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enforcement? I suspect not, but perhaps there's a business opportunity in giving them the opportunity to do so. Sort of a GoFundMe for peer-to-peer insurance. 2) The GDPR is all about not being a jerk with your users' data. As long as you don't do that, and do relatively minor things X, Y and Z, you're totally fine. This flavor of argument might actually be true, but if I'm assuming the risk I'm probably going to want to hear it from someone with skin in the game, like a lawyer, who I can point to if it turns out to be false. Even if I had the desire to read through the law (I don't) and understand the specific implications for my project (I wouldn't), the very act of doing this represents a cost that I could more simply avoid by excluding EU residents from my service. I'd choose the latter path every time, and put "support EU residents, check into the legal implications of GDPR" on the roadmap, for "someday". 3) You're exposed to millions of risks anytime you do anything. This is just one more and you're making a big deal of it. Often this accusation comes with a subtext that you're trying to prove some political point, suggesting that you're making a decision in bad faith to "punish" the EU. Well, I personally think something like the GDPR is needed, and have no particular axe to grind, but I also have no idea if the legal exposure is serious, and no particular desire to put in the work to find out. Yes, business, or really any activity, involves legal risk. In this case though, the risk is pretty serious, first of all because the penalties (20M Euros max) are serious, and secondly because it will be very difficult to claim that you've never heard of the GDPR. If Tonga creates some law impacting side hustles on the internet, at a minimum I can credibly claim to be unaware of that law. The GDPR on the other hand has been all over the news for weeks. I've clearly heard of it (especially now that I've commented on a discussion of it on HN). My feeling is there's a real risk that this law will lead to a general practice of non-EU individuals, and non-EU startups launching MVPs to at least temporarily block the EU to avoid unnecessary risk. That's not the intended purpose of the law, but laws have unintended consequences all the time. If the EU wants to avoid this unintended consequence they should provide a clear, objective, and cheap (in terms of both time and money), set of instructions that will allow projects like monal to continue operating there. If such a set of instructions exists, I haven't seen it.
- disinterestpart 8y agoAs a mostly disinterested party here, I can't help but to be happy about GDPR. I know that the large internet companies in my country like Google, Facebook, Amazon, Twitter, Oracle, IBM, etc. will have no trouble complying with this law but it will help to deter smaller competitors and upstarts from other countries and from within the EU. That's more money for us and a nice fat moat to keep everyone else out. This just made Silicon Valley impregnable. All that's very well though. The fact this was posted on a large traffic like Hacker News means the author of monal.im will be subject to spiteful abuse from EU citizens whom believe their nation^H^H^H^H "union" can do no wrong.
- ultim8k 8y agoI'm pretty sure lawyers and "consultants" are the only ones super happy about GDPR. Companies will still harvest user data with updated T&Cs and more buttons for the user to click, because all services will be useless without accepting. Governments will also continue gathering users' data for "the common good".
- TomVDB 8y agoI'm pretty sure that many ordinary European (and US!) citizen are pretty happy about the GDPR as well. If clicking an extra button is really all it takes. But despite the assurances of many here that it's not hard to comply, I'd probably have shut down the servers of my own hobby non-profitable location data gathering website as well, simply because even reading the GDPR document would be too much effort.
- DanBC 8y agoPersonal projects are exempt. https://gdpr-info.eu/recitals/no-18/ https://gdpr-info.eu/recitals/no-18/ > This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities.
- josecastillo 8y agoThis is going to sound crazy, but I spun up an instance of a simple open-source comments system[1] for a blog that I write, and I chickened out of deploying it because I wasn't sure if it complied with GDPR. I distrust Disqus over their ad-driven model and deep tracking of users, so for now I’m just doing without comments. Is it possible to self-host something that handles user data (name, comment, IP address) and comply with this regulation? What if there's more data, federated data? Can one just spin up an instance of Friendica, for example, or are there additional steps required for compliance? I'm honestly not sure anymore. [1]: https://posativ.org/isso/ https://posativ.org/isso/
- ozim 8y agoIf you do it for hobby it is not a problem. For IP address if you don't store it indefinitely, like you can anonymise IP after a month. I think you store IP for spam protection, solving user issues, which is lawful basis so you can protect your good interest. Most important you are not passing it to some third party. Second you can always make consent checkbox. DPO is required only if you really store race, religion, credit card data, health records. If you keep name and IP you do not need a DPO. There is so much FUD about GDPR, it will pass after a year. Now compliance vendors are having part, a lot of champagne will be opened on May 25th. In the end if you know, what data you have, why do you have it and who you share it with, it should be good enough.
- DanBC 8y agoIt doesn't apply to personal projects, unless they're commercial. https://gdpr-info.eu/recitals/no-18/ https://gdpr-info.eu/recitals/no-18/ > This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
- KajMagnus 8y ago> Is it possible to self-host something that handles user data (name, comment, IP address) and comply with this regulation? Yes. There's something called GDPR legitimate interest (a subcategory in the "Lawful basis" someone else mentioned here), which lets you store e.g. IP addresses for security reasons, without asking for permission. See: http://www.privacy-regulation.eu/en/recital-49-GDPR.htm http://www.privacy-regulation.eu/en/recital-49-GDPR.htm I think Talkyard ( = open source comments, no ads, no tracking) is GDPR compliant. For example, people can download their personal data and delete their accounts. (I'm developing it). https://www.talkyard.io/blog-comments https://www.talkyard.io/blog-comments
- danbruc 8y agoWhile Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide free meals for homeless people in my spare time. I just built this car from scratch for myself and now they tell me I can not drive it on public roads just because I don't have the time and money to meet the required standards?
- noobiemcfoob 8y agoYour point is clear, but this is internet software all having to comply with the same regulations regardless of actual industry. I'm having to close my small construction company because the FDA passed harsher food safety requirements.
- jacquesm 8y agoNo, you don't have to close at all. You just need to comply with the law, just like everybody else. You also need to file your taxes, keep the books in order, ensure that you do not pollute the environment, in some cases you need to be licensed in order to be able to practice your trade and so on. Why would this particular regulation suddenly cause you to close your business unless you were doing something really shady?
- tathougies 8y agoPerhaps it costs money to do so, and the company does not have enough working capital + lines of credit to make the payments necessary? I feel like your statement here is basically "you are a business, therefore it is impossible for you to run out of money", which -- superficially -- seems very naive.
- jacquesm 8y agoAt that level it doesn't have to cost anything other than your time. And if it's not a business it is a hobby and those cost time (and usually also money). The GDPR is not going to cause any but the weakest businesses to close shop, in fact if the GDPR causes a business to close (which I highly doubt other than people voluntarily throwing in the towel because they can't be bothered) then I am not sure if I'm going to shed tears over that because it likely means that that business was so weak already that other things besides GDPR compliance were suffering as well (such as security).
- matthewmacleod 8y agoThe overreaction to GDPR from US tech startups in particular surprised me at first. But my partner is a lawyer working on GDPR compliance for a variety of tech firms, and he explained that there's almost a historical cultural difference in terms of attitudes to ownership of personal data. European regulation typically treats personal data as being the property of the person being identified; US tradition considers data generated by a company to the be the property of that company, not of the person. This made the whole massive unnecessary panic by primarily US-based small companies much more understandable to me.
- jcims 8y agoIt's not really 'unnecessary' if you didn't account for the objectives of the GDPR in your initial design. Assign any moral attributes you like to it, if GDPR requires substantial tinkering with your product then it's reasonable to be concerned.
- jacquesm 8y agoThis is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope that just ignoring European customers is going to make the bogeyman go away. Legal compliance is a requirement for any business, and privacy law is just one more thing to take into account and for a small business that does not process super sensitive data (such as medical information or financial information) the costs of compliance are negligible. They're not '0', but then again it is a business and costs of doing business are the norm.
- dageshi 8y agoPerhaps, when it comes down to it, he doesn't want to be subject to a law that he had no ability to influence given that he's not an EU citizen. In blocking EU users he is fully compliant with the GDPR as he has zero of their personal data to begin with?
- kuschku 8y agoIf that was the case, no one outside the US could use VISA/MasterCard either (they enforce US laws on all international customers), or could make any business with any US company (even HN has to enforce the Iran embargo on all its international users). If you want to criticize local laws applied internationally, abolish the US.
- zerostar07 8y agoi believe they enforce them legally, via international law. there is no such thing about privacy
- s73v3r_ 8y agoSure, he's entitled to take his ball and go home if he really wants to. That doesn't put him in the right, and it doesn't make his move anything more than whining.
- consto 8y agoGoodbye to bad rubbish.
- abritinthebay 8y agoLong story short: Monal developer doesn't understand GDPR, makes a bunch of incorrect claims about it, doesn't want to understand it, and so removes his software from the EU. That's his right, go him. He didn't have to write a ton of incorrect nonsense about the GDPR though. He could have just skipped to the last step. GDPR compliance is not actually that hard - I'm in the middle of doing it for a very large company - as long as you're not storing information about users it's almost trivial tbh, but there are a lot of unfortunate vague terms in the law (the intent is rather clear however). The reaction to this law in the US is rather funny because the rest of the world has been dealing with strange US laws for decades on the web... finally something bites the other direction and people freak out.
- abiox 8y ago> The reaction to this law in the US is rather funny because the rest of the world has been dealing with strange US laws for decades on the web... finally something bites the other direction and people freak out. i'm quite positive that i've seen people call for europeans to not do business with american businesses on account of said us laws (in other HN threads).
- abritinthebay 8y agoUsually over data privacy/hosting & law enforcement AFAIK. That’s more due to lack of laws there
- ahje 8y ago> as long as you're not storing information about users it's almost trivial tbh This is the part that most people seem to miss.
- abritinthebay 8y agoTrue! Even if you are it’s not too bad (the hardest part is tracking consent & that’s not exactly hard) People just don’t want to.
- 8y ago
- megous 8y agoI think the part about rather big enforcement penalties made it easy for various consultants to scare companies and sadly also some individual developers. I already had to fend off implementing some ridiculous features. I've pushed against misconceptions and use of non-existent terminology that's not even in the law. People are taking info from all kinds of sources, some of them sketchier than others, despite the existence of official EU guides, and the law itself. But I bet it will be easy to comply for most non-adtech/tracking businesses. And as an internet user, I'm looking forward to better data exports, data removal and more transparency.
- fiatjaf 8y agoIf you find yourself in this same situation, maybe you'll want to take a look at https://euroshield.xyz/ https://euroshield.xyz/ (direct EU IP blocks coming soon).
- tobyhinloopen 8y agoCool, the new cookie wall. "Are you european-wall?"
- deleted 8y ago[deleted]
- kerng 8y agoProbably a good reason to not use this product, even outside the EU.
- hackersword 8y agoA "society" is all about building up information about the people around you and knowing about them. Complete anonymity often leads to the breaking down of people filters and behaviours, they think they can do whatever they want without consequences. Many countries outlaw face coverings as they imply correlation with lawlessness. The direct linking of IP address as PII flies in the face of that. If I am logging IP addresses for security and to monitor against abuse, and I in fact determine that an IP address is abusive, it behooves me to have any/all data that ip address used in my system to try to identify them. The right to be forgotten .. why just online? Why just digital? What if a shop owner or waiter in small town notes which customer like what, or what client tips well. Which local has annoying kids that she lets wander an vandalize the store. If that owner/waiter writes that down in a log, and shares with co-worker on next shift ... is that in violation. What if they don't write it down and just have a really good memory ... what if they just 'organically' get a reputation and word gets around. Is old wives gossip illegal under GDPR , or the "sterotypical" Italians mothers who keep an eye out on all the kids in street and report to each other who is doing what. Plenty of stores and bars will have a list "don't take personal checks from these people" ... are those types of lists not allowed anymore? If the GDPR was JUST limited to "customers" or people who have explicitly created accounts that might be one thing, but over reaching to say ANY apache webserver that automatically logs IP addresses had to be GDPR compliant is absurd. If I post a tech blog with how-tos , personal ramblings, or even example code projects I release as open source that you are completely free to use or not use ... why do I have now have some obligation to you? You chose to walk up to my storefront and look inside ... I'm free to remember whatever I want about you while you looked around. The US passed pretty broad overreaching Computer Fraud and Abuse Act [https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act] that many have argued is so broad that a violation of TOS could be considered abuse/hacking. If you view my site without agreeing to my TOS, should I be able to have you prosecuted?
- adambrenecki 8y ago> I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. Lots of people are responding to the DPO side of this sentence, saying that it's not as onerous as the author of this article is making it sound, but as someone who's also not based in the EU it's the "EU Representative" part that I'm more worried about myself. Article 27 says: > (1) Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union. Article 3(2) is the bit that says the GDPR applies to processing outside the EU of EU citizens' data etc. > (2) The obligation laid down in paragraph 1 of this Article shall not apply to: > a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or > b) a public authority or body. It's clear here that not everyone outside the EU needs to have an EU representative, but 2a is wordy and confusing enough that it's real hard for a non-EU non-lawyer to figure out with certainty whether or not they need one. The ambiguous combination of 'and's and 'or's don't help, but 'unlikely to result in a risk to the rights and freedoms of natural persons' sounds like something that's ambiguous enough on its own that you might need an EU lawyer to actually interpret it.
- pheleven 8y agoIf this is the sort of enforcement we can expect, this could suck: https://ico.org.uk/action-weve-taken/enforcement/sse-energy-supply-ltd/ https://ico.org.uk/action-weve-taken/enforcement/sse-energy-... (there are several others, this one is just interesting because it's a very simple mistake with very minimal PII) Also, my understanding is Germany allows for whistle-blowers to take a cut of fines. Language in the GDPR calls for over-estimating damages for loss of PII when compensating individuals as well. Generally, I appreciate the GDPR. That said, it's a huge burden trying to go through many dozens of workflows, technical or otherwise, where (typically minimal) PII is recorded, catalog them, limit (and purge) intake of data to bare minimums, create documentation supporting said workflows to be able to provide the SA's, create a plan for being able to search ALL those workflows/databases/spreadsheets/apps that have PII to supply that data upon request, and then be able to delete all cases of such data upon request. Turns out that's actually a mountain of work. It will probably force us to significantly improve workflows and combine data repositories moving forward but it's a large burden up front. Likely many hundreds, if not thousands, of hours for our fairly small enterprise.
- DanBC 8y agoIt's a fixed penalty, so ICO didn't have much choice over the amount.
- jacquesm 8y agoI read that enforcement report. I think it was fully warranted that the 1,000 pound fine was levied against that company. (1) they did not immediately report the fact that they disclosed that customers private information and (2) they did not have appropriate technical measures in place to avoid such problems, specifically: they were tasking their cs reps to cut-and-paste information between screens that could display the information of two unrelated customers, a super stupid and error-prone set up. The fine, 1000 pounds is proportionate given the size of the entity it is levied against, the resources at their disposal and the turnover of the company, if the company had been much smaller one would hope for leniency but the fine would have not been levied at all or it would have been 1000 pounds, no middle ground there. You'd hope they learned their lesson.
- hackersword 8y agoThe GDPR is by most accounts and interpretations aimed at "the big players" ... but it is not SPECIFICALLY written to be limited to them. Two view points to this: 1) If make to specific, big players will find a way to slip through the exceptions and game/lawyer the system 2) So vague , that only the "big players" will have the infrastructure/legal approval to actually guarantee 100% compliance. Smaller fish that the reward just doesn't justify the risk/uncertainty will certainly pull out of the market. If the law is about "supercookies" and targeting an individual throughout the entire internet ... it should say that. If its about the transfer/monetization of the aggregation of data ... PII being sold for money or some other in-kind transaction ... say that. If a single entity uses a cookie and retains data for one single domain and that is ok ... say that. If retaining logs that contain an IP Address and the logged in credentials are ok to keep for security auditing. .... say that ... if its only ok to store them for a year(??), 6 months(??) , 1 month(??) ... say fucking that! If a company/site is aggregating PII of over a million unique users is troubling and should be specifically bound by these restrictions and need a DPO ... say that. If a site only has a few 1,000 - 10,000 Unique PII records/users of note , and is not the focus of these regulations .... say that. Give concrete examples, lawyer the shit out of it ... leave open for amendments so when abused can be modified. It's just a shitty law trying to fix an already shitty situation.
- brandonjm 8y agoIf a similar law to GDPR was introduced in other countries such as the US, complying now would probably cost considerably less than dumping business in every country that does it and complying with all the laws only once you can't operate sustainably as a business anymore.
- chx 8y agoHonestly, most small USA businesses take one look at "Up to €20 million, or 4% annual global turnover – whichever is higher." and just run. There's no point in even trying to salvage the situation. > For the 3.7 million small businesses with 1 to 4 employees, the Census Bureau figures show average annual sales in 2007 were $387,200. Given that, who wants to risk a 20M fine? All this advice in this thread to do this, run it through a lawyer (lawyers are expensive especially international ones), makes no sense to the majority of the businesses in the USA: there are less than 8M employers in the USA and a very small percentage has a yearly turnover of even a mil not to mention the ~600M USD where the fine changes from a constant to a percentage. To give you another idea of how much money this is, about a quarter of public companies have less than 25M USD market cap. As a dual Canadian-EU citizen I am stupefied by this law.
- blackbrokkoli 8y agoPlease actually read the law before you try to argue with “as a...“. The fine scales with the violation and it does -surprise- not mean that arbitrary Github projects will have to pay 20m€...
- fenwick67 8y agoThe sentiment of a law doesn't always translate to the enforcement of it in practice
- dbbk 8y agoSimilar laws already exist and have existed for a long time. There’s no evidence of disproportionately and illogically large fines having been handed out in the past, and nothing to suggest regulators will start now.
- chx 8y agoShow me a law where you need to make half a billion euros before the potential fine becomes proportional of your turnover. It only takes one opportunistic apparatchik to make your life hell and this GDPR thing is now law in such places like Hungary where I haul from and if they can get away with it, trust me, they will go overboard. Maybe not 20M overboard but still.
- peterburkimsher 8y ago> Do you know a good GDPR consultant? >> Yes. > Can you tell me their email address? >> No.
- solotronics 8y agothis is the natural reaction to a business model such as Facebook. they are making billions from everyones private data and the result is an overreaction that hurts mostly small companies
- zenovision 8y agoJust block all EU users. EU only makes 15% of the world population and after Brexit even much less than 15%, so they are not that important.
- m-arnold 8y agoHugo (static blog generator) is spending non-insignificant efforts to comply: https://github.com/gohugoio/hugo/issues/4616 https://github.com/gohugoio/hugo/issues/4616. It looks like a simple thing like embedding a Youtube video in your blog post is no longer so simple. As well as loading any external JS dependencies.
- blub 8y agoYoutube, disqus, twitter are designed to collect as much info about persons as possible, so yes, it might be difficult to prevent them from doing that. The fault lies entirely with those companies, which did the wrong thing with impunity until it was literally outlawed.
- intrasight 8y agoOne thing I see missing from these discussions is budget - specifically the budgets for the regulatory agencies responsible for enforcing GDPR. Lack of enforcement budget will, I think, make GDPR a non-issue for the vast majority of organizations. And as the EU ramps up its infighting over the new budget, there will be LESS budget allocated for something like this that has no vested constituents who will be helped or harmed by such allocation.
- eksemplar 8y agoYou don’t need a DPO if you’re a one man company, or your revenue is under a certain amount of which I can’t remember, because it hasn’t been relevant at our 10.000 employee municipality. You’re allowed to track ips in your log, if there is a reason for it and you only keep them for a reasonable amount of time. You do need to gather consent for push messages. But you can do so by simply asking your users, and frankly, you should always ask your users before you spam them, but it’s obviously going to be a little work to implement. This is an overreaction, especially because no one knows how the GDPR plays out until it’s been tested in the courts.
- Proven 8y agoThabk god there is the government to protect me!
- oneplane 8y agoThis makes little sense. There is nothing in the GDPR that you shouldn't already have done. Besides, even if you don't operate in the EU, it makes sense to have a basic privacy setup anyway, and GDPR compliance is just that... https://gdprchecklist.io https://gdprchecklist.io (was on HN a few days ago IIRC) On top of that, this isn't american lawyering. If you make a mistake or are simply trying but not having a good time at it, you're not automatically destroyed, put in jail, fined for billions of euros etc. The GDPR is beneficial to everyone, except people with bad intentions or bad practises (like having big budgets for PR, Ads and the CEO but not for tech). The GDPR for basic FOSS and other single-person software boils down to: - Don't capture data and not ask first - Don't capture data and not tell - Don't capture data and now show - Don't capture data and not say where it is - Don't capture data and not say who can access it - Generally, users should be able to CRUD their data - Delete data on request - Export data on request Most of that is common sense and in most non-commercial services this is available anyway. You can make it even simpler: - Only CRUD when a user CRUDS and tell them that is what they are doing while they are doing it - Make sure the delete/opt-out/close account button actually works - Have a line somewhere saying "i'm hosting this on platform XYZ in country ABC" Since you are likely going to build CRUD + delete account anyway, that's a solved problem. Unsubscribe/Delete account usually already exists, no problems there either. That leaves writing a few lines telling users where you are storing stuff and how to contact for issues. Don't forget: laws comparable to the GDPR were already in effect long before the EU came up with a EU-wide version. In the UK for example, you could ask a business to send an export of all the data they have on you via mail, and they were bound by law to comply. In the netherlands, if you store PII of people who are not your clients and send them mail/spam/offers, you get fined. Hell, they even had a more universal version where you aren't allowed to put mail in someone's mailbox unless it was addressed specifically to them, and there was one where you weren't allowed to put any ads in if the mailbox was marked for that. And you have a system where cold-calling was not allowed, same for fax-ads.
- amurgul 8y agoYou CANNOT, by any means, consider an IP address to be "personal data". You cannot say "I don't want my IP to lay around in a database somewhere" because ... IT IS NOT YOUR IP. An IP address is used to uniquely identify a device on a network, not a person. This device can be (and usually is) a router, a proxy, a server of some kind, a corporate computer, a public computer and so on. Not to mention the fact that a device can also have multiple IP addresses at the same time. So, an IP address CANNOT be used to uniquely identify a person and it really shouldn't be considered in the context of GDPR. Ah, an IP address + some other identification data, that's another discussion. Depending on the combination, it might be considered personal data.
- lewiseason 8y agoWhat GDPR says about this is: > [A]n identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. I think the principle is that since an IP address could be used to identify you, it is considered personal data.
- teget 8y agoEven under current rules the common household IP-Address appears to be (in combination with any other relevant data (a timestamp for example)) personal data. > Article 2(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data must be interpreted as meaning that a dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data within the meaning of that provision, in relation to that provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person. [ECLI:EU:C:2016:779]
- hashmal 8y ago> I get the impression that it is an end of an era for the internet. This is an era many of us won't regret.
- akshatpradhan 8y agoI started ComplianceChaos.com to sell my Policy Writing Services. I specialize in ISO 27001, HIPAA, and PCI-DSS. I’d love the opportunity to add GDPR to my current list of specialities.
- youwishboye 8y agogood riddance
- fapjacks 8y agoSee ya!
- lagadu 8y ago> I do not have the resources to meet the letter of the law for compliance especially with respect to retention and processing these tokens. Harsh words but I feel they're warranted: If you don't want to treat my private data with the due diligence you should, then we're better off not using your service.
- zerostar07 8y ago> my private data > we're better off not using Just pointing out that some people may want to choose how they want their data treated case-by-case, instead of having no option to use the website because its blocked
- Stenzel 8y agoIf you sell hardware, you have to deal with CE/FCC/RoHS and -worst of all- WEEE compliance, to name just a few. In comparison, GPDR is a piece of cake. Just sayin.
- StreamBright 8y ago"Data Protection Officer I do not have the resources to hire a Data Protection Officer (DPO) or EU Representative as required by GDPR. I do not have designated EU contacts." What? Where does it say in the law that: a, you need one b, it cannot be you I mean come on, this is just a very ignorant post from the author.
- vbezhenar 8y agoHow can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?
- borlum 8y agoSuper over reaction. "End of an era"
- tobyhinloopen 8y agoI like the GDPR panic. People should think twice before handling our data. If they don't think they can handle it, I'm fine with them gone.
- interdrift 8y agoAgain, an absolutely uninformed opinion on GDPR. Shame that you can't be bothered to care about your users.
- deleted 8y ago[deleted]
- wlll 8y ago> Data Protection Officer He doesn't need one > Crashes So don't send the users IP with the crash report? > Push I don't know enough about this, but: "APNS push tokens are associated with devices which can be traced back to a user if combined with info on the originating XMPP server." I didn't think monal ran their own XMPP servers? If they don't then is there really a danger of someone combining the data from the two services? > Honestly, I do not know if XMPP federation is legal anymore in the EU with GDPR. I have no idea, but if the monal developer isn't running any XMPP servers then is this even an issue? This all seems like someone who doesn't like GDPR having a bit of a tantrum and interpreting the laws in a way that makes it seem like they are in a worse position than they actually are.