Live data from Hacker News

Ask HN: Is HN GDPR compliant?

news.ycombinator.com

101–110 of 113 posts

Re: Ask HN: Is HN GDPR compliant?

#101

Earlier quoted context omitted.

For curiosity, where are you? Are you unable to find a DMCA-proof server in a country where your content would also be legal, or is there a different problem?

It's a different problem - I'm part of the Commonwealth. I could host it in a country that would ignore requests, but the point of the website is to do everything correctly. If I hosted my content in a country that doesn't care about copyright or DMCA, I'm putting myself at risk if I was brought into court as I've purposefully skirted around laws. My country has proven we are held to US copyright law - see the Kim Do…

> What would usually be considered a matter for civil court was brought into criminal court because it crossed borders

Wasn't it criminal because he was doing it as a business and earning money from it?

Re: Ask HN: Is HN GDPR compliant?

#102
post #61

Earlier quoted context omitted.

So it has clauses about project/service/product size/popularity?

In fact, yes. For example, the record-keeping requirements don't apply to most businesses with less than 250 employees. The DPO requirements don't apply to most businesses with less than 250 employees. The entire regulation doesn't apply if you don't target people in the EU and don't offer goods or services to people in the EU. Some of the requirements only apply if you process data on large numbers of people regular…

DPO?

Re: Ask HN: Is HN GDPR compliant?

#103
post #24

Short answer: No, but it doesn’t matter. If you are a Non-EU business, that is a business with no legal presence or employees in the EU then you can comfortably skip GDPR compliance with minimal risk (some unknown obscure treaty provision?) #notalawyer

That's actually not true in terms of the GDPR. A company, simply, only needs to have an EU citizen as a customer for the company to be regulated by the GDPR. [1] [1] https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...

Yes. It SAYS that. However it’s about enforcement.

Dumb example: Blasphemy is illegal in Ireland but Irish Gov can’t enforce that law in France.

Re: Ask HN: Is HN GDPR compliant?

#104
post #88

Earlier quoted context omitted.

None of what I said is nonsense. The EU absolutely could enforce GDPR regulations on businesses which are not based in the EU, if persons involved in those businesses attempted to travel to the EU. That's not FUD, that's why Edward Snowden isn't going to hop on a plane back to the US anytime soon. Your argument about "pursue" falls under the umbrella of >Now whether or not the EU will attempt to enforce the GDPR that…

All of this is spelled out in the law. > Pursue isn't currently a fully defined term. This is pure FUD. This is fully defined that's what makes it a binding legislative act. Let's go to the actual law: Article 3: Territorial Scope [1] spells out the explicit territorial scope. > the monitoring of their behaviour as far as their behaviour takes place within the Union. Oh, sounds scary. The latter part is clarified [2]…

> ... the biggest FUD of all is this notion that the EU even has some sort of legal enforcement mechanisms independent of a Member State.

In that case, I'm not sure how to interpret Microsoft v. Commission (triggered by EC, ruled by ECJ), or how to make sense of the fact that the EU, IIRC, has its own (non-state) representative at the WTO, which in turn has its own (state-independent) dispute resolution system, with capacity to inflict trade sanctions.

The 'cops' analogy might be very misleading here, right?

Re: Ask HN: Is HN GDPR compliant?

#105
post #77

Earlier quoted context omitted.

I'm not doing business in Pakistan or in the EU. The mere fact that a Pakistani or European uses my site doesn't subject me to the laws of Pakistan or the European Union.

The fact that they are using your site means you are doing business with them.

You know, same could be said for the US, but look how that turned out for Kim Dotcom. Extradition and humongous expenses for him - all because people in a country that was unrelated to the site decided to break their copyright rules and use it :).

Re: Ask HN: Is HN GDPR compliant?

#106
post #90

Earlier quoted context omitted.

A country can't tell foreign citizens how to behave, even if the country (or group of countries, in this case) writes a law saying they can.

According to the Geneva Convention, war crimes have international jurisdiction. This means that a court in, eg, Spain can "tell foreign citizens how to behave"

Downvoted? Why? By people who defend the sovereign right to carry out war crimes?

Re: Ask HN: Is HN GDPR compliant?

#107
post #6

One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant. Of cours…

Can't that be a violation in the eyes of GDPR? If they don't give users a simple button, then can't that be argued to be not giving the user the ability to export data. The problem I have with GDPR is that there's so much open to interpretation.

If you have an email address you can give users for privacy requests and a promised turnaround time (we will respond to all privacy messages in 7 days) you're OK.

Re: Ask HN: Is HN GDPR compliant?

#108

Earlier quoted context omitted.

In fact, yes. For example, the record-keeping requirements don't apply to most businesses with less than 250 employees. The DPO requirements don't apply to most businesses with less than 250 employees. The entire regulation doesn't apply if you don't target people in the EU and don't offer goods or services to people in the EU. Some of the requirements only apply if you process data on large numbers of people regular…

DPO?

Data Protection Officer. There are a few situations where you MUST assign a DPO (large company, or systemic monitoring or processing of data, or processing of protected data). If you're talking about a tiny side project with basic data protection and you're not doing social scraping, GDPR will likely ignore you.

Re: Ask HN: Is HN GDPR compliant?

#109
post #101

Earlier quoted context omitted.

It's a different problem - I'm part of the Commonwealth. I could host it in a country that would ignore requests, but the point of the website is to do everything correctly. If I hosted my content in a country that doesn't care about copyright or DMCA, I'm putting myself at risk if I was brought into court as I've purposefully skirted around laws. My country has proven we are held to US copyright law - see the Kim Do…

> What would usually be considered a matter for civil court was brought into criminal court because it crossed borders Wasn't it criminal because he was doing it as a business and earning money from it?

That's still a civil case in New Zealand. It's copyright infringement, you don't go to jail - you get sued and bankrupted. The fact he was making money from it doesn't change the court, he just gets sued for more (in this case, it would have been everything he owned).

Re: Ask HN: Is HN GDPR compliant?

#110

Earlier quoted context omitted.

It's a different problem - I'm part of the Commonwealth. I could host it in a country that would ignore requests, but the point of the website is to do everything correctly. If I hosted my content in a country that doesn't care about copyright or DMCA, I'm putting myself at risk if I was brought into court as I've purposefully skirted around laws. My country has proven we are held to US copyright law - see the Kim Do…

But does US law actually require you to respond to the DMCA notice? Like, the provider loses its safe harbor, but if there's no violation of US copyright law then why does that matter? That's perhaps a different test case from the one that you intend, of course...

US law shouldn't matter to us at all. We shouldn't need to know what a DMCA notice is. A copyright claim should be made in the host country's format applicable to their laws, that doesn't seem to be a reality to any of the claims I've received.

Where I am, you should receive an IP rights notice and an interim injunction to remove the works. I've never received anything like that.

Post reply on HN