Live data from Hacker News

Woman allegedly impersonated prosecutor, dropped charges against herself

unionleader.com

291–300 of 336 posts

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#291

Earlier quoted context omitted.

This is already the case. Yes, you have to comply with CCP laws for _China residents_ if you want to have your website available in China. It doesn't say you have to apply the laws to all people around the world. But GDPR vs. China isn't a perfect comparison, because GDPR isn't blocking any content. It is not even _about_ the content. It's about following the privacy rights that I as an EU resident have and you as an…

China has the jurisdiction over the Chinese resident, their ISP and other local infrastructure. It doesn't have jurisdiction over foreign companies and foreign companies don't have to comply with anything. (Unless they want to do business with Chinese residents or operate in China) Same applies to the EU situation. You may want to be nice to the foreign visitors otherwise and comply with the foreign laws, but that's…

> Unless they (...) operate in China

Exactly. If you're operating in the EU, you are bound by the EU laws. But "operating" doesn't mean you have to sell something:

> The GDPR applies to US businesses, regardless of their size in terms of revenue or staff, if at least one of the following two conditions are met:

> 1. The company offers good or services (even in the absence of commercial transactions) to EU/EEA residents.

> 2. The company monitors the behavior of users inside the EU/EEA.

So yes, if the news website in this thread tracks me without my consent, they are violating my rights and the EU laws. I am not sure how realistic enforcing this law actually is, though, unless they have a EU branch (what you described as jurisdiction).

Source: https://termly.io/resources/articles/gdpr-in-the-us/

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#294

Earlier quoted context omitted.

China has the jurisdiction over the Chinese resident, their ISP and other local infrastructure. It doesn't have jurisdiction over foreign companies and foreign companies don't have to comply with anything. (Unless they want to do business with Chinese residents or operate in China) Same applies to the EU situation. You may want to be nice to the foreign visitors otherwise and comply with the foreign laws, but that's…

> Unless they (...) operate in China Exactly. If you're operating in the EU, you are bound by the EU laws. But "operating" doesn't mean you have to sell something: > The GDPR applies to US businesses, regardless of their size in terms of revenue or staff, if at least one of the following two conditions are met: > 1. The company offers good or services (even in the absence of commercial transactions) to EU/EEA residen…

The website you linked brings up 2 out of 4 examples where the EU data is collected, the business is not aimed at the EU residents, and says (verbatim) "GDPR does not apply". Same reasons seem to apply to the context discussed here (news site aimed at the US region). Specifically:

> Although such a website would likely track the user behavior of EU/EEA citizens, as the website would attract native speakers of several European languages, the GDPR does not apply here because:

> the service does not target EU/EEA residents, and

> the tracked user behavior is not occurring within the EU/EEA.

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#295

Earlier quoted context omitted.

> Unless they (...) operate in China Exactly. If you're operating in the EU, you are bound by the EU laws. But "operating" doesn't mean you have to sell something: > The GDPR applies to US businesses, regardless of their size in terms of revenue or staff, if at least one of the following two conditions are met: > 1. The company offers good or services (even in the absence of commercial transactions) to EU/EEA residen…

The website you linked brings up 2 out of 4 examples where the EU data is collected, the business is not aimed at the EU residents, and says (verbatim) "GDPR does not apply". Same reasons seem to apply to the context discussed here (news site aimed at the US region). Specifically: > Although such a website would likely track the user behavior of EU/EEA citizens, as the website would attract native speakers of several…

Nice catch - I didn't expect the examples to somehow contradict the general statement from the same section. TIL.

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#296
post #260

Earlier quoted context omitted.

This is Portuguese for Thanks? Off topic, but reading it I just noticed it sounds an awful lot like ありがとう (“arigatou” as in “domo arigatou Mr. Roboto”). I think there’s an etymology lesson in this, although I’m not sure which way it goes, probably Portuguese -> Japanese via Nagasaki.

It's a well known theory but it's most likely false[1], though there are several words imported to Japan via Portuguese that have long remained, such as the word for England, イギリス, which comes from the Portuguese for English (people), Ingles , which drives me a bit potty as it's used now to refer to the whole of the UK and I have trouble trying to distinguish England from Scotland et al when speaking with Japanese pe…

In Sweden we often use "England" for the UK. But I always feel a little guilty when doing it.

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#297
post #114

Earlier quoted context omitted.

Maybe it’s not a big deal, unless you value honesty above all else. I am not always honest, especially when it’s obvious to me that the other party will only use my goodwill to their advantage. In the case of the parent, I can imagine many scenarios where it is difficult or untimely to get supervisor approval, but failure or delay in doing so results in the employee catching all the heat for it.

> unless you value honesty above all else. . > I am not always honest, I work with regulated professionals. Honesty is a big deal. Dishonesty is seen as a fundamental personal flaw. Healthcare professionals who've been dishonest struggle to show remediation. It's really weird to me that I need to explain that forging someone else's name on documents is a bad idea .

Now imagine that the name field is only relevant to your employer (so it's not like forging a signature on a real document), and that the same employer punishes you for working too slowly if you don't write someone else's name.

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#298
post #260

Earlier quoted context omitted.

Obrigado!

This is Portuguese for Thanks? Off topic, but reading it I just noticed it sounds an awful lot like ありがとう (“arigatou” as in “domo arigatou Mr. Roboto”). I think there’s an etymology lesson in this, although I’m not sure which way it goes, probably Portuguese -> Japanese via Nagasaki.

It's actually related to the English phrase "much obliged!" -- from the Latin obligare, participle obligatus, meaning to indebt (both morally and fiscally).

https://en.wiktionary.org/wiki/obligo#Descendants

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#299
post #121

Earlier quoted context omitted.

Yep, so far "We can't serve you for legal reasons AKA we won't comply with the reasonable provisions of data protection" has been met with a broad shrug .

What's anyone supposed to do about it? GDPR didn't exactly provide funding to help anyone get compliant and it's hard to argue that GDPR compliance is a priority for a struggling local media site. It's a bummer, but I think it was inevitable in the way the law is structured.

Does the site also give that error if you are in California? To meet the requirements for CCPA, a news site (that isn't doing anything untoward) is most likely also going to be GDPR compliant.

Re: Woman allegedly impersonated prosecutor, dropped charges against herself

#300
post #267

Earlier quoted context omitted.

Is there evidence that they aren't besides not being confident about GDPR compliance? There's a lot more to GDPR than not selling data.

If you just aim to provide static content, i.e. public web pages and articles I think you’d really have to “go out of your way” to break GDPR (which in this case is likely tons of ad network code among other shady things).

Does your web server create logs that contain IP addresses (as most do by default)? Now you’re processing PII according to GDPR. Do you include any assets at all that are hosted by a third party who therefore have access to IP addresses? Do you have the necessary DPA with them plus your web host?

Do you have a compliant privacy policy, data retention policy, breach notification policy? Have you named a data privacy officer? Do you have a written process for erasure requests?

You’re probably right that the ads are a problem but ain’t nobody getting GDPR compliance for free.

Post reply on HN