Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

81–90 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#81
post #78

Earlier quoted context omitted.

This depends. Those laws could absolutely be enforced if, for example, Paul Graham tried to travel to Germany. You may not agree with the ethics of that, but that's how it works in practice. Now whether or not the EU will attempt to enforce the GDPR that strongly is another question.

This is pure nonsense. You might learn that the GDPR only applies to businesses located in the EU or who pursue EU citizens. It does not mean that if you Google Analytics and an EU citizen stumbles upon your site you are suddenly in violation. It is not some sort of magical global law that applies to every business in the world. The amount of FUD and ignorance and nonsense about the GDPR is getting out of control. Wh…

None of what I said is nonsense. The EU absolutely could enforce GDPR regulations on businesses which are not based in the EU, if persons involved in those businesses attempted to travel to the EU. That's not FUD, that's why Edward Snowden isn't going to hop on a plane back to the US anytime soon.

Your argument about "pursue" falls under the umbrella of

>Now whether or not the EU will attempt to enforce the GDPR that strongly is another question.

Pursue isn't currently a fully defined term. Is pursuing specifically advertising and marketing towards? Or is it simply allowing to register? If I use paypal as a payment service, that allows EU citizens to pay, am I pursuing them since they can now purchase my service?

Fwiw, I agree that its unlikely that HN is violating the GDPR, and its even more unlikely that HN will be chased for any violations it did commit. But calling others' more cautious interpretation of the law "nonsense" isn't particularly productive, especially when I wasn't even commenting on the GDPR in the first place, but instead on broader ways that international law works.

Re: Ask HN: Is HN GDPR compliant?

#82
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Here's your export:

https://news.ycombinator.com/user?id=lamlam https://news.ycombinator.com/threads?id=lamlam https://news.ycombinator.com/submitted?id=lamlam https://news.ycombinator.com/favorites?id=lamlam

If I was a linux nerd I'd turn that into a cat / curl combo.

Re: Ask HN: Is HN GDPR compliant?

#83

Earlier quoted context omitted.

Not in my country, and I have no intention of hosting this outside these borders which could get me in legal hot water.

For curiosity, where are you? Are you unable to find a DMCA-proof server in a country where your content would also be legal, or is there a different problem?

It's a different problem - I'm part of the Commonwealth.

I could host it in a country that would ignore requests, but the point of the website is to do everything correctly. If I hosted my content in a country that doesn't care about copyright or DMCA, I'm putting myself at risk if I was brought into court as I've purposefully skirted around laws.

My country has proven we are held to US copyright law - see the Kim DotCom case. What would usually be considered a matter for civil court was brought into criminal court because it crossed borders and unfounded claims were made against the accused (namely money laundering) who's now being extradited.

I simply want to provide a free, legal media service to those in my country. There's no money in it - I don't even run AdSense, I simply pay for hosting. So far, so good.

If I do get dragged into court, I expect a precedence to be set for future cases. This will also open up a lot of free historical media for government-run TV and streaming services, and local media producers.

It's kind of like a weird tech protest against goofy copyright laws.

Re: Ask HN: Is HN GDPR compliant?

#85

Earlier quoted context omitted.

But if they hold and manage data for users who reside in the EU (which they do), then I believe the rules apply too. From what I can gather, if a user in the EU approaches HN and asks for their profile data and posts to be removed, then that falls under the GDPR laws.

No, laws don't work that way. American first amendment rights, for instance, don't extend to websites based in Europe. You don't get to bring your laws and rights with you when you visit a website that's hosted and run in a foreign country. edit: clarified European based websites

Ya, but good luck traveling to europe ever again.

Re: Ask HN: Is HN GDPR compliant?

#88
post #78

Earlier quoted context omitted.

This is pure nonsense. You might learn that the GDPR only applies to businesses located in the EU or who pursue EU citizens. It does not mean that if you Google Analytics and an EU citizen stumbles upon your site you are suddenly in violation. It is not some sort of magical global law that applies to every business in the world. The amount of FUD and ignorance and nonsense about the GDPR is getting out of control. Wh…

None of what I said is nonsense. The EU absolutely could enforce GDPR regulations on businesses which are not based in the EU, if persons involved in those businesses attempted to travel to the EU. That's not FUD, that's why Edward Snowden isn't going to hop on a plane back to the US anytime soon. Your argument about "pursue" falls under the umbrella of >Now whether or not the EU will attempt to enforce the GDPR that…

All of this is spelled out in the law.

> Pursue isn't currently a fully defined term.

This is pure FUD. This is fully defined that's what makes it a binding legislative act.

Let's go to the actual law:

Article 3: Territorial Scope [1] spells out the explicit territorial scope.

> the monitoring of their behaviour as far as their behaviour takes place within the Union.

Oh, sounds scary. The latter part is clarified [2]:

> Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.

There's a ton of nonsense about this on HN right now but anybody who's actually read the law should understand that the intention of the law is to prevent non-consensual surveillance of EU citizens. The idea that if somebody who stumbles upon your website and you log their IP address makes you subject is pure FUD. The idea that the EU will pursue American sites who don't target the EU is pure FUD. But the biggest FUD of all is this notion that the EU even has some sort of legal enforcement mechanisms independent of a Member State. As they say, that's not how any of this works. There are no "EU cops" waiting at the airport. Please.

[1] https://gdpr-info.eu/art-3-gdpr/

[2] https://www.gdpreu.org/the-regulation/who-must-comply/

Re: Ask HN: Is HN GDPR compliant?

#89

Earlier quoted context omitted.

Indeed, I noticed this in Google's GDPR terms and conditions I was required to agree to yesterday. Long story short, Google will charge you to delete your data, which I thought was against the spirit of the GDPR law: "Google may charge a fee (based on Google’s reasonable costs) for any data deletion under Section 6.1.2(a). Google will provide Customer with further details of any applicable fee, and the basis of its c…

The GDPR explicitly says you may charge a reasonable fee to cover your administrative costs.

Oh! I totally missed that. Thank you for the correction.

Not meaning to be argumentative, but is there a reference for that beyond Article 12 Section 5? (I probably missed that too.) But that section seems to suggest you can only charge a fee (or even decline to act) if the requests are unfounded or repeatedly excessive:

https://gdpr-info.eu/art-12-gdpr/

"Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either:

charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or

refuse to act on the request.

(Google's clause was opting to charge for any deletion request that is not yet automated.)

Re: Ask HN: Is HN GDPR compliant?

#90
post #31

I would strongly advise that we read carefully the language for Art. 3, "Territorial scope," which says: (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, t…

A country can't tell foreign citizens how to behave, even if the country (or group of countries, in this case) writes a law saying they can.

According to the Geneva Convention, war crimes have international jurisdiction.

This means that a court in, eg, Spain can "tell foreign citizens how to behave"

Post reply on HN