Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

51–60 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#51

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

This bothers me a lot as well. The EU shouldn't have domain over American companies. There's a reason that there isn't a ton of Tech companies in places like Germany.

They don't have domain over American companies.

Just don't accept European customer's data and you're fine.

Re: Ask HN: Is HN GDPR compliant?

#53

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

This bothers me a lot as well. The EU shouldn't have domain over American companies. There's a reason that there isn't a ton of Tech companies in places like Germany.

They don't have domain over American companies if they're not doing business in the EU.

Re: Ask HN: Is HN GDPR compliant?

#54
post #25

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

This also bothers me a lot. I've always wondered how the EU intends to enforce its laws upon my little side projects here in the US.

>I've always wondered how the EU intends to enforce its laws upon my little side projects here in the US.

It doesn't.

It's made to force you to comply when you become bigger.

Re: Ask HN: Is HN GDPR compliant?

#55

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

Demanding privacy is not overstepping it is consumer protection. The consumer need to rely that you treat their data responsibly and the GDPR is a rule book what you need to do. And yes, this rule book knows sanctions.

Re: Ask HN: Is HN GDPR compliant?

#57

Earlier quoted context omitted.

But if they hold and manage data for users who reside in the EU (which they do), then I believe the rules apply too. From what I can gather, if a user in the EU approaches HN and asks for their profile data and posts to be removed, then that falls under the GDPR laws.

Is there any reason why HN would be bound by EU laws, if it's not a European organization? What other countries laws should it be bound by, other than the ones it operates in?

Currently it may not be bound by them. But it could find itself in a situation where it matters - for example when working with / providing service to / getting service from another company in the EU which asks "so, are you GDPR compliant?" Given what HN does, that's not very likely though.

Re: Ask HN: Is HN GDPR compliant?

#58

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

It's not over stepping. Don't like the laws? Don't do business there. States in the US have different laws that affect operating businesses in them, too.

Funnily enough I operate a service to download copyright-expired content.. Only most of the content is still under copyright in the US. Early Elvis works seem to be very popular.

I've banned all non-local IP addresses from the website with a splash page which tells them why they're unable to access content.

This also doesn't stop my local ISP's and hosts eventually giving up on hosting my content as they're sick of reviewing DMCA's from US-based copyright-holders. Many of the smaller ones simply give me 24 hours notice or no notice at all, nobody wants to risk a lawsuit from the big-bad US media companies.

I get several hundred letters and emails a year with copyright holders threatening lawsuits and legal action. I suspect similar issues will arise for non-GDPR compliant services in the form of user support tickets.

Re: Ask HN: Is HN GDPR compliant?

#59
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Indeed, I noticed this in Google's GDPR terms and conditions I was required to agree to yesterday. Long story short, Google will charge you to delete your data, which I thought was against the spirit of the GDPR law: "Google may charge a fee (based on Google’s reasonable costs) for any data deletion under Section 6.1.2(a). Google will provide Customer with further details of any applicable fee, and the basis of its c…

The GDPR explicitly says you may charge a reasonable fee to cover your administrative costs.

Re: Ask HN: Is HN GDPR compliant?

#60

Upon cursory inspection, the single fact that user don't seem to be able to delete their account data from here would make it not compliant. Similarly the inability to delete posts after a certain time may also conflict with the data removal stipulation of GDPR. But as a corollary to that, GDPR laws seem to only apply where there is data that can personally identify a user. The usage of nicknames and throwaway accoun…

Nothing in the GDPR says you must be able to delete your own data. It says that you may request a business delete your personal data, and they may have to comply if they don't have a legitimate business reason not to. There's a balancing test, not a blanket requirement that every web app be littered with delete buttons.
Post reply on HN