Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

41–50 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#41
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

"offering" is not a critical word here, you almost certainly can't weasel out of the regulations by claiming you're not actively "offering" anything. If you put it online and EU users use it, you're offering it to them.

Re: Ask HN: Is HN GDPR compliant?

#42

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

This bothers me a lot as well. The EU shouldn't have domain over American companies. There's a reason that there isn't a ton of Tech companies in places like Germany.

Re: Ask HN: Is HN GDPR compliant?

#44
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Indeed, I noticed this in Google's GDPR terms and conditions I was required to agree to yesterday. Long story short, Google will charge you to delete your data, which I thought was against the spirit of the GDPR law:

"Google may charge a fee (based on Google’s reasonable costs) for any data deletion under Section 6.1.2(a). Google will provide Customer with further details of any applicable fee, and the basis of its calculation, in advance of any such data deletion."

Re: Ask HN: Is HN GDPR compliant?

#45
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

I think offering the service means being available. They would have to block EU users in order to not offer to them.

Re: Ask HN: Is HN GDPR compliant?

#46
post #24

Short answer: No, but it doesn’t matter. If you are a Non-EU business, that is a business with no legal presence or employees in the EU then you can comfortably skip GDPR compliance with minimal risk (some unknown obscure treaty provision?) #notalawyer

That's actually not true in terms of the GDPR. A company, simply, only needs to have an EU citizen as a customer for the company to be regulated by the GDPR. [1]

[1] https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...

Re: Ask HN: Is HN GDPR compliant?

#47
post #9

Why would it need to be compliant? Ycombinator is not a European company.

Because it has people from Europe accessing the site.

Okay, so now let's say your website is found non-compliant. You're a tiny operation in the US with absolutely no presence in the EU. The EU has absolutely no way to exert power over you.

Re: Ask HN: Is HN GDPR compliant?

#48

Earlier quoted context omitted.

But if they hold and manage data for users who reside in the EU (which they do), then I believe the rules apply too. From what I can gather, if a user in the EU approaches HN and asks for their profile data and posts to be removed, then that falls under the GDPR laws.

No, laws don't work that way. American first amendment rights, for instance, don't extend to websites based in Europe. You don't get to bring your laws and rights with you when you visit a website that's hosted and run in a foreign country. edit: clarified European based websites

This depends. Those laws could absolutely be enforced if, for example, Paul Graham tried to travel to Germany.

You may not agree with the ethics of that, but that's how it works in practice. Now whether or not the EU will attempt to enforce the GDPR that strongly is another question.

Re: Ask HN: Is HN GDPR compliant?

#49
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

A country can't tell foreign citizens how to behave, even if the country (or group of countries, in this case) writes a law saying they can.

In practice that's not true on many levels. Law enforcement happens across borders. (extradition (yes, in most cases it has to be a valid crime on both sides)) One country's law enforcement also can influence what other countries do without a good proof of anything. (Kim dot com?) That applies outside of LE as well. (points in the general direction of Middle East)

And then there's the soft influence of "we're big enough, we can dictate the rules, because who else will you trade with" which affected things like patent laws and trademarks around the world. It's interesting to see the US finding itself on the other side of that conversation sometimes.

Re: Ask HN: Is HN GDPR compliant?

#50

Why would it need to be compliant? Ycombinator is not a European company.

But if they hold and manage data for users who reside in the EU (which they do), then I believe the rules apply too. From what I can gather, if a user in the EU approaches HN and asks for their profile data and posts to be removed, then that falls under the GDPR laws.

Legal jurisdiction does not work that way.

Let's say Iran passed a law saying that it's illegal for anyone anywhere in the world to supply alcohol to a citizen of Iran, and that anyone selling alcohol must verify that their customers are citizens of not-Iran. When they attempt to enforce that against a German beer hall, they'll get laughed out of German court. Selling beer to adults is legal in Germany, no matter where they're from.

Likewise, the EU has no ability to enforce laws against American companies that don't have a physical presence in the EU.

Post reply on HN