Live data from Hacker News

Ask HN: Does HN respect the GDPR?

news.ycombinator.com

51–60 of 107 posts

Re: Ask HN: Does HN respect the GDPR?

#51
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

I'm not a lawyer either, but have been going through the GDPR process at my job. It doesn't matter if you operate or are established in the EU. If you have EU visitors/users they gain the protections of the GDPR and you have to comply. GDPR affects any org/site that collects personal or sensitive data. Amongst many others IP address and email address are considered PII under GDPR. We use IP address for some high leve…

I'm very interested to see how such requests would actually work...mainly because I'm curious to see what actual authority the EU has to enforce its laws outside of its borders.

I understand it applying to companies that are doing business in Europe but beyond that...?

Re: Ask HN: Does HN respect the GDPR?

#52
post #47
post #34

Earlier quoted context omitted.

But countries decide who to punish for what. One thing might not be unlawful in your country, but in another, and that other country can try to go after you. That fact is rather boring and well-established. What matters is how the other country enforces the punishment.

The thing is, the EU doesn't have sovereignty outside of Europe. If I actually have presence in the EU, or do business with the EU, that's one thing. But they can't tell some rando with a blog living in Boston to delete comments any more than North Korea can pass a law banning making fun of Kim Jong Un in Berlin. They can huff and puff, but at the end of the day they just don't have the authority.

Any jurisdiction can "tell you things" and judge you, even if it's not your own.

Admittingly, without cooperation with your jurisdiction, the EU jurisdiction cannot enforce a meassure if you don't have any presence under EU jurisdiction. However, if your jurisdiction cooperates with the EU jurisdiction, or if you eventually have some kind of presence in the EU, like traveling, they can go after you.

Re: Ask HN: Does HN respect the GDPR?

#53
post #46

What happens when I ask Google to go through everyone's gmail inbox and remove my information and all emails I've sent?

Interesting question. Google might argue you should direct your request to those individuals you emailed to. Google storing the emails doesn't necessarily mean that they're responsible for processing your deletion request under the GDPR (or maybe it does, I'm just speculating).

Google still makes available to its Gmail users the previous emails I've sent to them.

Re: Ask HN: Does HN respect the GDPR?

#54
post #5

A particularly ugly thing happens if the HN mods for some good or bad reason decide to ban an account: their contributions will be there forever, with no ability to append explanations to previous posts. This will after May 25 be illegal for services offered in the EU, but I kind of think that the same courtesy should apply to non-europeans.

> no ability to append explanations to previous posts

Nobody can reply to posts that are more than a month old anyway. And the edit window is only a few hours.

Re: Ask HN: Does HN respect the GDPR?

#55
post #23
post #21

Earlier quoted context omitted.

They "do not support that". Agree that it would be a nice workaround. Should also be technically trivial.

We're working on it.

I guess I just want to provoke you by now,

but when you say "you're working on it"

..what you actually worked on was

a) rate-limiting my user (vgf)

b) artificially moving my post to the second page using some kind of penalty?

That is insanely weak sauce. How do you even look yourself in the mirror every morning?

Anyway, all of this is useful stuff for May 25. I have been doing lots of screenshots the past hour.

Re: Ask HN: Does HN respect the GDPR?

#56

Earlier quoted context omitted.

Granted I've only sat in on a few GDPR meetings, but I don't think it works like that. In your example you were the one that sent your information to some other 3rd party, so you would be the one responsible for that data transfer and its consequences.

Is that not exactly what OP is asking for, but for HackerNews instead of Gmail? Gmail is hosting the data I sent. Not to mention that I sent the emails to their servers, not some third-party.

While laws like this allow for large grey areas where all of this is up for debate, the focus of the GDPR is largely on two things.

(1) Companies that collect data and "process" it. If you're hosting it with reason, it's no big deal. If you're actively doing something with it, then you can run afoul of the law.

(2) Companies that share their information with third parties. It puts a much larger onus on companies that have your data to use it appropriately and only for intended purposes.

If you read through the wording of the law, it's perfectly possible to have an e-mail service that complies with everything.

I think the crux of this particular argument though is whether or not you "own" the emails you sent. I think at the most if you pushed this issue to the max you could get a company to scramble your email address so that it doesn't identify you anymore... but all of this is more a thought exercise about minute details. The true intent of the law is the major points above.

Re: Ask HN: Does HN respect the GDPR?

#57

Earlier quoted context omitted.

So all web sites (most, anyway) are subject to the GDPR because they may record EU IP addresses in logs?

Yup, which is what makes GDPR so dangerous.

So how is this going to be enforceable on organizations outside of the EU?

Re: Ask HN: Does HN respect the GDPR?

#59
post #46

Earlier quoted context omitted.

Interesting question. Google might argue you should direct your request to those individuals you emailed to. Google storing the emails doesn't necessarily mean that they're responsible for processing your deletion request under the GDPR (or maybe it does, I'm just speculating).

Google still makes available to its Gmail users the previous emails I've sent to them.

Yes, but the GDPR makes a distinction between data controllers and data processors. The data controller is obligated to process your request, but Google could argue they're just the data processor, and redirect you to the users (again still speculating... not a lawyer)

Re: Ask HN: Does HN respect the GDPR?

#60
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

please read: https://blog.axeptio.eu/en/2018/03/20/gdpr-and-united-states...

I wonder how this applies to SESTA/FOSTA, as many escort listing sites are apparently already operating from overseas.
Post reply on HN