Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

71–80 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#71
post #56

Threads like this make me like GDPR more and more. Arrogant Americans coming in 'It doesn't have jurisdiction over American companies'. Wholly misinformed.

How do you expect the EU to enforce the GDPR extraterritorially? Like, do you expect the USA to comply with an EU request to impose a fine? Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks? My personal guess is that everyone with shady business models will move offshore, and the EU wil…

EU can sue American companies without getting US government approval/ involvement as long as they have operations here.

>Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks?

At least somewhat of a deterrence. As if American KYC & AML laws are completely ineffective.

>My personal guess is that everyone with shady business models will move offshore, and the EU will play a marginal game of whack-a-mole trying to coerce them through their vendors and customers, especially payment processors, similar to American enforcement of online gambling laws. I expect the GDPR to be effective on large companies that want to portray themselves as respectable, and ineffective on everyone else.

Implying the big companies aren't the ones with the 'shady business models'? My view is that this is specifically made for the big companies.

Re: Ask HN: Is HN GDPR compliant?

#72
post #51

Earlier quoted context omitted.

This bothers me a lot as well. The EU shouldn't have domain over American companies. There's a reason that there isn't a ton of Tech companies in places like Germany.

They don't have domain over American companies. Just don't accept European customer's data and you're fine.

I'm not a citizen of Pakistan.

I don't live in Pakistan.

My servers aren't in Pakistan.

Pakistan can't force me to comply with their laws just because a Pakistani national uses my site.

Same thing with EU laws.

Re: Ask HN: Is HN GDPR compliant?

#73

Earlier quoted context omitted.

Funnily enough I operate a service to download copyright-expired content.. Only most of the content is still under copyright in the US. Early Elvis works seem to be very popular. I've banned all non-local IP addresses from the website with a splash page which tells them why they're unable to access content. This also doesn't stop my local ISP's and hosts eventually giving up on hosting my content as they're sick of r…

Isn't "webhosts that cheerfully ignore DMCA complaints" a large, well-established industry?

Not in my country, and I have no intention of hosting this outside these borders which could get me in legal hot water.

Re: Ask HN: Is HN GDPR compliant?

#74
post #71

Earlier quoted context omitted.

How do you expect the EU to enforce the GDPR extraterritorially? Like, do you expect the USA to comply with an EU request to impose a fine? Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks? My personal guess is that everyone with shady business models will move offshore, and the EU wil…

EU can sue American companies without getting US government approval/ involvement as long as they have operations here. >Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks? At least somewhat of a deterrence. As if American KYC & AML laws are completely ineffective. >My personal guess is…

By "shady business model", I mean something like "business model dependent on breaking the GDPR". Facebook seems almost surely still profitable while complying, just not quite so spectacularly so. Many e.g. data brokers probably aren't. Their choice then becomes to disappear or go offshore. I think many will choose the latter. American extraterritorial enforcement of its financial laws is the most successful example of such enforcement that I know, and it's still easy to fund an online poker account.

I'd agree that the GDPR is designed for large companies, and will genuinely improve their behavior. I think its effects will be similar e.g. to American cities with very strong and complex tenant protections--we create a class of large, politically-connected operators with the resources to comply, and a class of shady operators one step ahead of the law. There's little in between--if you lack the resources to be absolutely certain you comply, and the punishments for large and small noncompliance are both catastrophic, then you might as well go all the way. (Yes, I expect the regulators to mostly exercise reasonable discretion. No, I don't want the discretion of a mid-level bureaucrat to be the only thing between me and financial ruin.) That part doesn't seem positive to me.

Aside: I wonder how many people promoting heavy-handed enforcement of data protection laws without regard for the second-order consequences have argued against heavy-handed enforcement of drug laws without regard for the second-order consequences...

Re: Ask HN: Is HN GDPR compliant?

#75

Earlier quoted context omitted.

Isn't "webhosts that cheerfully ignore DMCA complaints" a large, well-established industry?

Not in my country, and I have no intention of hosting this outside these borders which could get me in legal hot water.

For curiosity, where are you? Are you unable to find a DMCA-proof server in a country where your content would also be legal, or is there a different problem?

Re: Ask HN: Is HN GDPR compliant?

#76
post #72
post #51

Earlier quoted context omitted.

They don't have domain over American companies. Just don't accept European customer's data and you're fine.

I'm not a citizen of Pakistan. I don't live in Pakistan. My servers aren't in Pakistan. Pakistan can't force me to comply with their laws just because a Pakistani national uses my site. Same thing with EU laws.

If you want to do business in Pakistan you do.

Re: Ask HN: Is HN GDPR compliant?

#77
post #76
post #72

Earlier quoted context omitted.

I'm not a citizen of Pakistan. I don't live in Pakistan. My servers aren't in Pakistan. Pakistan can't force me to comply with their laws just because a Pakistani national uses my site. Same thing with EU laws.

If you want to do business in Pakistan you do.

I'm not doing business in Pakistan or in the EU.

The mere fact that a Pakistani or European uses my site doesn't subject me to the laws of Pakistan or the European Union.

Re: Ask HN: Is HN GDPR compliant?

#78

Earlier quoted context omitted.

No, laws don't work that way. American first amendment rights, for instance, don't extend to websites based in Europe. You don't get to bring your laws and rights with you when you visit a website that's hosted and run in a foreign country. edit: clarified European based websites

This depends. Those laws could absolutely be enforced if, for example, Paul Graham tried to travel to Germany. You may not agree with the ethics of that, but that's how it works in practice. Now whether or not the EU will attempt to enforce the GDPR that strongly is another question.

This is pure nonsense.

You might learn that the GDPR only applies to businesses located in the EU or who pursue EU citizens. It does not mean that if you Google Analytics and an EU citizen stumbles upon your site you are suddenly in violation. It is not some sort of magical global law that applies to every business in the world.

The amount of FUD and ignorance and nonsense about the GDPR is getting out of control. Why not do some research? Or actually read the regulation?

Anyways I see it's a lost cause but I find it remarkable how much BS about this topic exists from a community that prides itself on its technology acumen.

Re: Ask HN: Is HN GDPR compliant?

#79

Earlier quoted context omitted.

Indeed, I noticed this in Google's GDPR terms and conditions I was required to agree to yesterday. Long story short, Google will charge you to delete your data, which I thought was against the spirit of the GDPR law: "Google may charge a fee (based on Google’s reasonable costs) for any data deletion under Section 6.1.2(a). Google will provide Customer with further details of any applicable fee, and the basis of its c…

The GDPR explicitly says you may charge a reasonable fee to cover your administrative costs.

Five euros I was told in the knowledge session at my work.

Re: Ask HN: Is HN GDPR compliant?

#80
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

HackerNews is a content marketing platform for YC. They likely have European LPs and they certainly have European startups. I can’t see how they would avoid this and similarly, you just need a couple disgruntled founders who didn’t get accepted to cause a stir and report them.
Post reply on HN