Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

61–70 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#61
post #54
post #25

Earlier quoted context omitted.

This also bothers me a lot. I've always wondered how the EU intends to enforce its laws upon my little side projects here in the US.

>I've always wondered how the EU intends to enforce its laws upon my little side projects here in the US. It doesn't. It's made to force you to comply when you become bigger.

So it has clauses about project/service/product size/popularity?

Re: Ask HN: Is HN GDPR compliant?

#62
post #45
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

I think offering the service means being available. They would have to block EU users in order to not offer to them.

Read recital 23. The mere accessibility of a website to people in EU is not sufficient to determine if EU persons are targeted.

Re: Ask HN: Is HN GDPR compliant?

#63
post #56

Threads like this make me like GDPR more and more. Arrogant Americans coming in 'It doesn't have jurisdiction over American companies'. Wholly misinformed.

How do you expect the EU to enforce the GDPR extraterritorially? Like, do you expect the USA to comply with an EU request to impose a fine? Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks?

My personal guess is that everyone with shady business models will move offshore, and the EU will play a marginal game of whack-a-mole trying to coerce them through their vendors and customers, especially payment processors, similar to American enforcement of online gambling laws. I expect the GDPR to be effective on large companies that want to portray themselves as respectable, and ineffective on everyone else.

Re: Ask HN: Is HN GDPR compliant?

#64
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

That can't be the whole story though. In general, a regulation stipulating that a business provide a feature can't allow businesses to make it arbitrary difficult for a user to use that feature, since that would defeat the public policy behind the regulation. I suspect that the line here will be decided in some court.

> I suspect that the line here will be decided in some court.

Sure. At the end of the day though people shouldn't be using GDPR as an excuse to avoid making stuff or launching their projects. As long as you make a reasonable effort to do what people are asking for via email then you're probably not going to be the test case.

Re: Ask HN: Is HN GDPR compliant?

#65
post #61
post #54

Earlier quoted context omitted.

>I've always wondered how the EU intends to enforce its laws upon my little side projects here in the US. It doesn't. It's made to force you to comply when you become bigger.

So it has clauses about project/service/product size/popularity?

In fact, yes. For example, the record-keeping requirements don't apply to most businesses with less than 250 employees. The DPO requirements don't apply to most businesses with less than 250 employees. The entire regulation doesn't apply if you don't target people in the EU and don't offer goods or services to people in the EU. Some of the requirements only apply if you process data on large numbers of people regularly, rather than occasionally. And there's a recital calling on member states that enact and enforce the regulation to pay special attention to the unique needs of micro, small and medium sized businesses.

Re: Ask HN: Is HN GDPR compliant?

#66
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Can't that be a violation in the eyes of GDPR? If they don't give users a simple button, then can't that be argued to be not giving the user the ability to export data. The problem I have with GDPR is that there's so much open to interpretation.

Articles 15 and 17 (dealing with deletion and access) both contain a provision where if the request is unfounded or excessive, you may charge a reasonable fee. You cannot charge a fee for compliance with standard requests, and "reasonable" is something that would likely be argued in court.

Source: https://ico.org.uk/for-organisations/guide-to-the-general-da...

Edit: mis-referenced article 15 as export instead of access.

Re: Ask HN: Is HN GDPR compliant?

#67
post #24

Short answer: No, but it doesn’t matter. If you are a Non-EU business, that is a business with no legal presence or employees in the EU then you can comfortably skip GDPR compliance with minimal risk (some unknown obscure treaty provision?) #notalawyer

That's actually not true in terms of the GDPR. A company, simply, only needs to have an EU citizen as a customer for the company to be regulated by the GDPR. [1] [1] https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...

[deleted]

Re: Ask HN: Is HN GDPR compliant?

#68
post #20

American businesses should add a clause that all authorized access is predicated on a user knowingly acknowledging that they are not a resident of the EU. If GDPR becomes an issue they could abuse the CFAA to get the persons of interest extradited to the USA for prosecution of unauthorized access. It would be funny too because the data the lawyers would collect to proceed with a case would be from unauthorized access…

from* the USA?

I think "to". Like, anyone alleging the GDPR violation is admitting that they violated the CFAA. It's pretty stupid, though not clearly stupider than past successful uses of the CFAA.

Re: Ask HN: Is HN GDPR compliant?

#69

Earlier quoted context omitted.

It's not over stepping. Don't like the laws? Don't do business there. States in the US have different laws that affect operating businesses in them, too.

Funnily enough I operate a service to download copyright-expired content.. Only most of the content is still under copyright in the US. Early Elvis works seem to be very popular. I've banned all non-local IP addresses from the website with a splash page which tells them why they're unable to access content. This also doesn't stop my local ISP's and hosts eventually giving up on hosting my content as they're sick of r…

Isn't "webhosts that cheerfully ignore DMCA complaints" a large, well-established industry?

Re: Ask HN: Is HN GDPR compliant?

#70
post #56

Threads like this make me like GDPR more and more. Arrogant Americans coming in 'It doesn't have jurisdiction over American companies'. Wholly misinformed.

You will like it until the day those "Arrogant Americans" have effectively banned you from most of the internet, with the exception of the largest sites, and those based in Europe.

If you want the GDPR to have jurisdiction over American companies, American companies will simply refuse to do business with you.

Post reply on HN