Live data from Hacker News

Ask HN: Does HN respect the GDPR?

news.ycombinator.com

21–30 of 107 posts

Re: Ask HN: Does HN respect the GDPR?

#22
post #8
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

my understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)

How would EU law compel a non-EU entity to delete content based on the residency of the user?

As an example of the opposite state, where this does definitely apply: Tarsnap complies with Canadian law around collecting names/addresses for users who are located in Canada, because Tarsnap is operated as a Canadian business. But if Tarsnap were located in the US, it would not be responsible for collecting that information from Canadian users.

Re: Ask HN: Does HN respect the GDPR?

#24
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

There are cases out there, like LICRA vs Yahoo! [1] that could suggest otherwise. [1]: https://en.wikipedia.org/wiki/LICRA_v._Yahoo !

I'm not sure how this case suggests otherwise, but Yahoo is not HN/YCombinator, and Yahoo is most definitely impacted by the GDPR.

Re: Ask HN: Does HN respect the GDPR?

#25
post #8
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

my understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)

Yes, but you need to explicitly target the EU. What that exactly means will be determined will eventually be determined in court, but some examples:

- If you offer your products in Euros, which is the currency in most of the EU - If you offer payment methods which only exist in the EU or one of its members - Otherwise suggest you target EU citizens

Hacker News exists as a generic website on the internet, but it does not to target any country or region specifically. Therefore HN should be exempt from the legislation.

Re: Ask HN: Does HN respect the GDPR?

#26

Earlier quoted context omitted.

The regulation applies if the data controller, an organisation that collects data from EU residents, or processor, an organisation that processes data on behalf of data controller like cloud service providers or the data subject (person) is based in the EU. The regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. According to the…

So all web sites (most, anyway) are subject to the GDPR because they may record EU IP addresses in logs?

Yup, which is what makes GDPR so dangerous.

Re: Ask HN: Does HN respect the GDPR?

#28

For me the question that a lot of people will be asking after 25th May, is what happens if they don't? I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing.

> I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing. No. The danger is that Internet goliaths will use the GDPR to intimidate or even shut down smaller competitors. Think of patent trolls, just worse - because the GDPR has really huge fines attached and is damn easy to get wrong in implementations. While the GDPR was intended to be beneficial to EU co…

I'm interested in how you think this would work. As far as I can tell, the enforcing authority for the country where the individual affected resides would need to investigate. And frankly, where a smaller entity was playing fast and loose with data, I would want the authorities to investigate.

For instance, in the UK the plan appears to be for the ICO to work with companies and fine where there's a major breach and appropriate security wasn't implemented.

Now, perhaps some individuals will band together and complain, but they do not stand to gain from the enforcement in the same way that patent trolls do.

We're going from an era where companies can claim AES encrypted at rest and AES encrypted over the wire whilst running an ancient stack full of vulnerabilities and, above a certain scale, not even worry about it. I personally have high hopes that the GDPR will at least make people running companies like that worry a bit.

Post reply on HN