Live data from Hacker News

Ask HN: Does HN respect the GDPR?

news.ycombinator.com

11–20 of 107 posts

Re: Ask HN: Does HN respect the GDPR?

#11
post #5

A particularly ugly thing happens if the HN mods for some good or bad reason decide to ban an account: their contributions will be there forever, with no ability to append explanations to previous posts. This will after May 25 be illegal for services offered in the EU, but I kind of think that the same courtesy should apply to non-europeans.

Not to devalue privacy (at all), but if the GDPR is so far reaching that anonymous posts are expected to comply with this, that destroys much discussion. Don't see why that's a reasonable expectation. That's no longer private but public data.

If you contribute to public knowledge/discussion, then taking your ball and going home leaves huge gaps in history, the same way you see [deleted] throughout many Reddit threads.

Is the GDPR that far reaching?

Re: Ask HN: Does HN respect the GDPR?

#12

Are they under any obligation to?

The regulation applies if the data controller, an organisation that collects data from EU residents, or processor, an organisation that processes data on behalf of data controller like cloud service providers or the data subject (person) is based in the EU. The regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. According to the…

So all web sites (most, anyway) are subject to the GDPR because they may record EU IP addresses in logs?

Re: Ask HN: Does HN respect the GDPR?

#13

Earlier quoted context omitted.

The regulation applies if the data controller, an organisation that collects data from EU residents, or processor, an organisation that processes data on behalf of data controller like cloud service providers or the data subject (person) is based in the EU. The regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. According to the…

So, no?

HN certainly processes IP and email addresses of individuals within the EU.

Re: Ask HN: Does HN respect the GDPR?

#14
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

There are cases out there, like LICRA vs Yahoo! [1] that could suggest otherwise.

[1]: https://en.wikipedia.org/wiki/LICRA_v._Yahoo!

Re: Ask HN: Does HN respect the GDPR?

#15
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

please read: https://blog.axeptio.eu/en/2018/03/20/gdpr-and-united-states...

Re: Ask HN: Does HN respect the GDPR?

#16
post #5

A particularly ugly thing happens if the HN mods for some good or bad reason decide to ban an account: their contributions will be there forever, with no ability to append explanations to previous posts. This will after May 25 be illegal for services offered in the EU, but I kind of think that the same courtesy should apply to non-europeans.

Not to devalue privacy (at all), but if the GDPR is so far reaching that anonymous posts are expected to comply with this, that destroys much discussion. Don't see why that's a reasonable expectation. That's no longer private but public data. If you contribute to public knowledge/discussion, then taking your ball and going home leaves huge gaps in history, the same way you see [deleted] throughout many Reddit threads…

The GDPR only cares about privacy, not quality of internet threads.

Re: Ask HN: Does HN respect the GDPR?

#19
post #8
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

my understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)

I haven't researched that particular point, but I'm not sure that your HN comments qualify as "personal data" under the GDPR (they'd need to personally identify you).

Re: Ask HN: Does HN respect the GDPR?

#20

For me the question that a lot of people will be asking after 25th May, is what happens if they don't? I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing.

> I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing. No. The danger is that Internet goliaths will use the GDPR to intimidate or even shut down smaller competitors. Think of patent trolls, just worse - because the GDPR has really huge fines attached and is damn easy to get wrong in implementations. While the GDPR was intended to be beneficial to EU co…

[deleted]
Post reply on HN