Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

21–30 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#21
If HN stores IP addresses or does any sort of de-anonymization on their end, then probably yes. They cover this in their privacy policy, at least for California [1], but their terms of use (right to refuse deletion) seem inconsistent with CCPA.

Also, if they don't store IP or actively deident, then I'm not sure either reg applies. HN isn't collecting PII. Just because you chose to type some info into a free form text box doesn't mean that the are liable for treating that data as PII, unless they're doing the tagging and extraction themselves or you inform them you're in CA/EU and the post contains PII. ianal.

[1] https://www.ycombinator.com/legal/#calprivacy

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#22

Maybe the lack of any kind of business relationship matters? I.e. HN isn't making money from the people posting here.

the company solicits business from EU/UK citizens

unless they want to stop funding/accepting applications from them: it applies to them

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#23
I'd guess HN isn't big enough for basically any privacy law to apply.

Some parts of GDPR at least call out company size explicitly, other parts allow for "cost of implementation" to be considered, which for HN would probably be "prohibitively high" regardless of triviality, considering the team size.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#24

I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…

That's a very poor analogy, as you can put tariffs on Chinese steel and disallow imports unless they adhere to EU standards.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#25
post #11

HN is a respite from those awful cookie banners, that's something.

Dark pattern banners I call them. One day I clicked the 'more options' button on a foreign website and it was a list of over 1000 different third parties listed each with their own toggle.

broken as designed.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#26
post #6

I can’t wait for the day the EU actually tries to enforce their laws on individuals and companies with no presence there. Will be a fun extradition battle to watch

No EU country would ever try to extradite anyone over a GDPR violation...

International companies that choose to process data from EU citizens but blatantly ignore the regulation will be subject to enforcement action from the country's supervisory authority. The supervisory authority has the power to "order the suspension of data flows to a recipient in a third country or to an international organisation" or "to impose a temporary or definitive limitation including a ban on processing".

In practice, this means you can say goodbye to doing business with your EU customers if you don't want to play by the rules. I doubt it'll be much of a loss for them to lose access to services provided by a company that doesn't care about their customers' privacy.

As ever, a significant minority of Americans on Hacker News really Just Do Not Grasp the benefit of the EU or its regulations such as GDPR. "All regulation must be bad!!" It's quite tiresome, really.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#29
post #16
post #12

Earlier quoted context omitted.

And those banners aren't even mandatory. Someone did it without learning the actual law and almost everybody does that.

They are mandatory if by browsing a website your data ends up in a 3rd party, which means almost all websites.

It's only 'mandatory' (see comment below) if they (whether the primary operator or the subcontractor) is doing things that aren't strictly for functionality.

The problem is that while the EU hopes that disclosures are designed to introduce friction to make the site more privacy-friendly... let's say that money is still a strong motivator for a lot of websites. I even spotted cookie prompts that were essentially that "close door" button on lifts.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#30
post #11

HN is a respite from those awful cookie banners, that's something.

Dark pattern banners I call them. One day I clicked the 'more options' button on a foreign website and it was a list of over 1000 different third parties listed each with their own toggle.

Use Firefox's built in privacy blocking tools as a bare minimum.

Personally, I use uBlock, the built in privacy list, and most crucially: Cookie AutoDelete.

I have it set such that if I unload a domain for 30 minutes, all of its cookies are deleted. The end result is that I have something that works decently, while preserving history and passwords.

Post reply on HN