Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

91–100 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#91
post #88

Earlier quoted context omitted.

None of what I said is nonsense. The EU absolutely could enforce GDPR regulations on businesses which are not based in the EU, if persons involved in those businesses attempted to travel to the EU. That's not FUD, that's why Edward Snowden isn't going to hop on a plane back to the US anytime soon. Your argument about "pursue" falls under the umbrella of >Now whether or not the EU will attempt to enforce the GDPR that…

All of this is spelled out in the law. > Pursue isn't currently a fully defined term. This is pure FUD. This is fully defined that's what makes it a binding legislative act. Let's go to the actual law: Article 3: Territorial Scope [1] spells out the explicit territorial scope. > the monitoring of their behaviour as far as their behaviour takes place within the Union. Oh, sounds scary. The latter part is clarified [2]…

>Oh, sounds scary. The latter part is clarified [2]:

And according to that clarification, having paypal as a payment processor might make it apparent that the controller envisages offering goods or services to data subjects in the union. That's what I said. Or it might not. Its not fully defined. A cautious interpretation makes sense.

>There are no "EU cops" waiting at the airport. Please.

And to be clear, I never said there were. I was making the point that, contrary to g-g-great-grandparent, it is absolutely possible for a country to exert control over the actions of people outside its borders, assuming those people might have interest in international travel.

If you're going to keep yelling FUD about things, you should first confine yourself to calling out things people are actually saying, instead of creating ridiculous strawpeople. Its not productive to call people out for saying ridiculous things that they didn't actually say.

Re: Ask HN: Is HN GDPR compliant?

#92

Earlier quoted context omitted.

For curiosity, where are you? Are you unable to find a DMCA-proof server in a country where your content would also be legal, or is there a different problem?

It's a different problem - I'm part of the Commonwealth. I could host it in a country that would ignore requests, but the point of the website is to do everything correctly. If I hosted my content in a country that doesn't care about copyright or DMCA, I'm putting myself at risk if I was brought into court as I've purposefully skirted around laws. My country has proven we are held to US copyright law - see the Kim Do…

But does US law actually require you to respond to the DMCA notice? Like, the provider loses its safe harbor, but if there's no violation of US copyright law then why does that matter? That's perhaps a different test case from the one that you intend, of course...

Re: Ask HN: Is HN GDPR compliant?

#93
post #88

Earlier quoted context omitted.

All of this is spelled out in the law. > Pursue isn't currently a fully defined term. This is pure FUD. This is fully defined that's what makes it a binding legislative act. Let's go to the actual law: Article 3: Territorial Scope [1] spells out the explicit territorial scope. > the monitoring of their behaviour as far as their behaviour takes place within the Union. Oh, sounds scary. The latter part is clarified [2]…

>Oh, sounds scary. The latter part is clarified [2]: And according to that clarification, having paypal as a payment processor might make it apparent that the controller envisages offering goods or services to data subjects in the union. That's what I said. Or it might not. Its not fully defined. A cautious interpretation makes sense. >There are no "EU cops" waiting at the airport. Please. And to be clear, I never sa…

> And according to that clarification, having paypal as a payment processor might make it apparent that the controller envisages offering goods or services to data subjects in the union. That's what I said. Or it might not. Its not fully defined

This is not true. Using a payment processor or accepting credit cards in no way constitutes targeting of EU customers. In that scenario you are neither data controller nor processor, in fact. I think, like a lot of posters in this thread, you've spent virtually zero time understanding the law and are just echoing FUD.

Re: Ask HN: Is HN GDPR compliant?

#94
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

That can't be the whole story though. In general, a regulation stipulating that a business provide a feature can't allow businesses to make it arbitrary difficult for a user to use that feature, since that would defeat the public policy behind the regulation. I suspect that the line here will be decided in some court.

Yes, making things _arbitrarily_ difficult would probably go against the spirit of the law, even if it technically complied with it. But as Alex3917 pointed out, as long as a company responded to GDPR requests by email in a timeline in accordance with the law, they would be safe.

Re: Ask HN: Is HN GDPR compliant?

#95
post #93

Earlier quoted context omitted.

>Oh, sounds scary. The latter part is clarified [2]: And according to that clarification, having paypal as a payment processor might make it apparent that the controller envisages offering goods or services to data subjects in the union. That's what I said. Or it might not. Its not fully defined. A cautious interpretation makes sense. >There are no "EU cops" waiting at the airport. Please. And to be clear, I never sa…

> And according to that clarification, having paypal as a payment processor might make it apparent that the controller envisages offering goods or services to data subjects in the union. That's what I said. Or it might not. Its not fully defined This is not true. Using a payment processor or accepting credit cards in no way constitutes targeting of EU customers. In that scenario you are neither data controller nor pr…

And it's very courageous of you that you're willing to risk other people's money to that effect :)

It's quite odd that you're calling a statement that amounts to "in the presence of untested law, caution is warranted" FUD.

That's like not even controversial. You're entire argument is predicated on you understanding the law better than everyone else. And well, I'm not particularly confident in a person whose most used word is "FUD" and who began a conversation by misunderstanding what I was saying. What reason do I have believe you?

Re: Ask HN: Is HN GDPR compliant?

#96
post #77
post #76

Earlier quoted context omitted.

If you want to do business in Pakistan you do.

I'm not doing business in Pakistan or in the EU. The mere fact that a Pakistani or European uses my site doesn't subject me to the laws of Pakistan or the European Union.

The fact that they are using your site means you are doing business with them.

Re: Ask HN: Is HN GDPR compliant?

#97
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

At my job we do it semi-automatic; i.e. there are automatic export tools, but emails are sent forth and back first.

This is because we've received only a handful of requests and because there isn't an automatic system for the extra layer of authentication comparable to answering an email with a token in it.

Come to think of it, this places an even bigger value on email: You can probably get all of someone's private data from external sites once you have their email. As if it wasn't a big enough part of stealing someone's identity already; now you can properly steal people's pasts!

Re: Ask HN: Is HN GDPR compliant?

#98
post #70
post #56

Threads like this make me like GDPR more and more. Arrogant Americans coming in 'It doesn't have jurisdiction over American companies'. Wholly misinformed.

You will like it until the day those "Arrogant Americans" have effectively banned you from most of the internet, with the exception of the largest sites, and those based in Europe. If you want the GDPR to have jurisdiction over American companies, American companies will simply refuse to do business with you.

Even if this was the case - if companies treating their customers' data like shit vanish from the European market, I'd be really happy. Not a big loss at all. :)

Additionally, leaving the European market opens up a big opportunity for EU-companies. Basically, that's the way to go if you want to wreck American dominance over the Internet (and the companies which matter know that very well, which is exactly why they are NOT dropping the EU).

For European citizens it's a win either way. That's why nobody is impressed by your threats - they just look like people pissed off because the EU is now doing what the USA had been doing for decades - meddling in other countries sovereignity. (If you want to interpret it that way, which imho is wrong.)

Re: Ask HN: Is HN GDPR compliant?

#99

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

This bothers me a lot as well. The EU shouldn't have domain over American companies. There's a reason that there isn't a ton of Tech companies in places like Germany.

Well internet is a connected place. Same things happen when US changes their policy. Foe example new net neutrality laws will probably somehow affect the whole world.

Also i think there are lot of tech companies in Germany they just target german audience.

Re: Ask HN: Is HN GDPR compliant?

#100

Probably not. I really have mixed emotions about GDPR being a SaaS founder. It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies. The EU can do what it wants, but generally I am against regulation as it promotes bureaucracy, stifles innovation, and creates fluff and burden's especially on small companies such Chief Data Protection Officer and Chief Data Offic…

> It seems overstepping and heavy handed that the EU can enact laws that affect American's and American companies.

Unlike eg Kinder Eggs? https://www.cbp.gov/newsroom/national-media-release/dont-be-...

Post reply on HN