All of our infrastucture has to change to honour that. If you cannot honour that change, maybe you shouldn't have been handling personal data.
I don't have any knowledge about monal.im (don't know what it is - some kind of im client?), but this person is making some claims:
- he needs a data-protection officer: no, only larger orgs handling lots of personal data need this. If he's making an im-client and not servers that store data he certainly doesn't, but I don't know what his setup is.
- crash analytics: This can be handled by telling the users clearly that you'll be gathering the data (and defaulting to not gathering if they don't actively approve). As long as you have a proper PURPOSE for gathering and storing the data and don't use it for anything else you're golden. You do have to document this, in case of a review (hyper-unlikely).
- Push: he's getting a message and storing the device/ip combination. This seems to be central to the service he's providing. Therefore he can and should put that in the description/terms of his service (as he cannot deliver the service without this). As long as it is clearly explained to the end-user this is fine, and he can keep doing it. If he stores it and does anything with this data other than the central purpose that he informed the end-user of he's in violation. I'd suggest putting it in clear text in front of the end-user and deleting the data as soon as it's no longer needed. Don't do any non-approved analysis on it. If you want to analyse - ask for permission.
XMPP federation may be a problem, I agree with that. The problemer here (as I see it) is that each service getting the personal data must only process it for the purposes explicitly agreed to by the end-user and honour any subsequent notifications of rectification and deletion. This is a hard nut to crack indeed.