Also, if they don't store IP or actively deident, then I'm not sure either reg applies. HN isn't collecting PII. Just because you chose to type some info into a free form text box doesn't mean that the are liable for treating that data as PII, unless they're doing the tagging and extraction themselves or you inform them you're in CA/EU and the post contains PII. ianal.
Ask HN: Does GDPR and CCPA Apply to Hacker News?
21–30 of 99 posts
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#22Maybe the lack of any kind of business relationship matters? I.e. HN isn't making money from the people posting here.
unless they want to stop funding/accepting applications from them: it applies to them
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#23Some parts of GDPR at least call out company size explicitly, other parts allow for "cost of implementation" to be considered, which for HN would probably be "prohibitively high" regardless of triviality, considering the team size.
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#24I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#25Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#26I can’t wait for the day the EU actually tries to enforce their laws on individuals and companies with no presence there. Will be a fun extradition battle to watch
International companies that choose to process data from EU citizens but blatantly ignore the regulation will be subject to enforcement action from the country's supervisory authority. The supervisory authority has the power to "order the suspension of data flows to a recipient in a third country or to an international organisation" or "to impose a temporary or definitive limitation including a ban on processing".
In practice, this means you can say goodbye to doing business with your EU customers if you don't want to play by the rules. I doubt it'll be much of a loss for them to lose access to services provided by a company that doesn't care about their customers' privacy.
As ever, a significant minority of Americans on Hacker News really Just Do Not Grasp the benefit of the EU or its regulations such as GDPR. "All regulation must be bad!!" It's quite tiresome, really.
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#27Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#28Quoted post unavailable.
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#29Earlier quoted context omitted.
And those banners aren't even mandatory. Someone did it without learning the actual law and almost everybody does that.
They are mandatory if by browsing a website your data ends up in a 3rd party, which means almost all websites.
The problem is that while the EU hopes that disclosures are designed to introduce friction to make the site more privacy-friendly... let's say that money is still a strong motivator for a lot of websites. I even spotted cookie prompts that were essentially that "close door" button on lifts.
Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?
#30HN is a respite from those awful cookie banners, that's something.
Dark pattern banners I call them. One day I clicked the 'more options' button on a foreign website and it was a list of over 1000 different third parties listed each with their own toggle.
Personally, I use uBlock, the built in privacy list, and most crucially: Cookie AutoDelete.
I have it set such that if I unload a domain for 30 minutes, all of its cookies are deleted. The end result is that I have something that works decently, while preserving history and passwords.