benningm / mtpolicyd

a modular policy daemon for postfix
21 stars 3 forks source link

Web site mtpolicyd.org is not working #28

Closed kepi closed 6 years ago

kepi commented 6 years ago

403 when trying to access https://mtpolicyd.org/ for at least 10 days.

benningm commented 6 years ago

Regarding to the new data protection law in EU i had to check thru all my online presences.

Since the website content is mostly based on POD documentation which is also available from the source and browsable on CPAN/MetaCPAN i decided to save the time and turn it down.

The mailing list was also very low traffic. Please open issues here.

kepi commented 6 years ago

Oh, that's really a shame. I think website is really important for first contact with software and I wouldn't be probably using mtpolicyd without it.

As I'm EU citizen and have to deal with GDPR on everyday basis in work, maybe I can help you with questions? I'm not lawyer, but mtpolicyd website was super simple. If you just have documentation there, don't use cookies, dont have any signup/login you don't need to do anything. GDPR is only about collecting personal data.

I understand you with browsable on CPAN and I'm former Perl programmer so I should be familiar with it but mtpolicyd is software I use, not Perl module so it wouldn't cross my mind.

benningm commented 6 years ago

Yes, the page is just a custom static site generator script. And I also think it is not a problem to add a simple "data protection" page with "standard" content about log file storage etc.

But even if you do everything right, there is currently some legal uncertainty which may be abused.

kepi commented 6 years ago

It really is not needed. When you are not collecting data, you don't have any obligation to add information. GDPR looks scary but it is not. Logging is ok for GDPR purposes without any consent if you do not store it forever.

Also there is no intention from any official party to prosecute small websites, GDPR is primarily targeted at big players and abuse of personal data.

benningm commented 6 years ago

The officaly parties are not the problem. They are already overloaded and have no interesst to deal with personal websites and blogs. They are also instructed to be friendly to small organisations. So in case of a violation it is likley they just send you an frienldy reminder.

In germany it is not clear if you can send a "Abmahnung" (Cease and desist letter?) in case of violations. The local lawmakers missed to clarify such cases in german law. These letters have already been abused in the past.

benningm commented 6 years ago

The mtpolicyd.org website is back online!