Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

31–40 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#31
I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says:

  (2) This Regulation applies to the processing of personal data
  of data subjects who are in the Union by a controller or processor
  not established in the Union, where the processing activities
  are related to:

    (a) the offering of goods or services, irrespective of whether
    a payment of the data subject is required, to such data subjects
    in the Union; or

    (b) the monitoring of their behaviour as far as their behaviour
    takes place within the Union.
So, I would ask: Has HN made an "offering of goods or services . . . to such data subjects in the Union"? (https://gdpr-info.eu/art-3-gdpr/)

The critical issue is that word: "offering."

The language here seems to be about intentions. Has HN "offered" anything to data subjects in the Union? Maybe not. To be sure, people in the EU may have chosen to look at HN, but has HN sought to "offer" to them?

(The presence of a domain such as news.ycombinator.eu would tip to "yes.")

Re: Ask HN: Is HN GDPR compliant?

#32
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

That can't be the whole story though. In general, a regulation stipulating that a business provide a feature can't allow businesses to make it arbitrary difficult for a user to use that feature, since that would defeat the public policy behind the regulation.

I suspect that the line here will be decided in some court.

Re: Ask HN: Is HN GDPR compliant?

#33
post #13

Earlier quoted context omitted.

Unfortunately GPDR effects any site/company that has EU visitors which is nearly all sites.

Fortunately GPDR effects any site/company that has EU visitors which is nearly all sites.

No, it simply doesn't. If you've been told this you've been informed incorrectly.

Re: Ask HN: Is HN GDPR compliant?

#35
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Can't that be a violation in the eyes of GDPR? If they don't give users a simple button, then can't that be argued to be not giving the user the ability to export data. The problem I have with GDPR is that there's so much open to interpretation.

Re: Ask HN: Is HN GDPR compliant?

#36
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

They do provide an API and public data set, so the export could be self serve.

Re: Ask HN: Is HN GDPR compliant?

#38

Upon cursory inspection, the single fact that user don't seem to be able to delete their account data from here would make it not compliant. Similarly the inability to delete posts after a certain time may also conflict with the data removal stipulation of GDPR. But as a corollary to that, GDPR laws seem to only apply where there is data that can personally identify a user. The usage of nicknames and throwaway accoun…

You don't have to follow any of the rules in the GDPR if you have a good reason for doing so, which doesn't overstep the basic rights of the person. Being able to operate the business in the way that it's intended is a fine reason. So, user comments don't have to be deleted because that would change the way HN operates and creates value. However, it's harder to explain why the comments can't be anonymized by unlinking it from the user table and changing the username to 'deleted'.

Re: Ask HN: Is HN GDPR compliant?

#39
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

A country can't tell foreign citizens how to behave, even if the country (or group of countries, in this case) writes a law saying they can.
Post reply on HN