Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

31–40 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#31

CCPA states: The right to know the personal information that businesses have collected from an individual The right to opt-out of the sale of consumer data collection The right to delete personal information collected from them HackerNews doesn't collect personal data. Deleting anything someone wants deleted isn't covered

Pretty sure it requires deleting comments if requested, this at least how my employer treats GDPr.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#33

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Interesting Definitely not how my employer interprets GDPR.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#34

I'd guess HN isn't big enough for basically any privacy law to apply. Some parts of GDPR at least call out company size explicitly, other parts allow for "cost of implementation" to be considered, which for HN would probably be "prohibitively high" regardless of triviality, considering the team size.

Seems like a risky gambit; AFAIK YC owns HN and would have a hard time arguing that that they're a small business incapable of following GDPR regs.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#35
post #16
post #12

Earlier quoted context omitted.

And those banners aren't even mandatory. Someone did it without learning the actual law and almost everybody does that.

They are mandatory if by browsing a website your data ends up in a 3rd party, which means almost all websites.

No, banner isn't mandatory. Information is mandatory. I don't remember exact page now but it was some govt page here in Poland that had info about cookies in page footer, and it was also ok

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#36

If HN stores IP addresses or does any sort of de-anonymization on their end, then probably yes. They cover this in their privacy policy, at least for California [1], but their terms of use (right to refuse deletion) seem inconsistent with CCPA. Also, if they don't store IP or actively deident, then I'm not sure either reg applies. HN isn't collecting PII. Just because you chose to type some info into a free form text…

.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#37
post #17

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

> Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do.

Actually in practice many important US companies do have market activity or assets in the EU, arguably including Y Combinator. Also, the EU (or its governments) wouldn't bother a random plumber in Iowa or honestly even in Prague (unless in the latter case someone have bothered to complain).

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#38
post #17

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

US companies that act internationally are not immune from the laws of the states they act within.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#39
post #17

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

GDPR is intentionally written to be extraterritorial in scope. If you're collecting data on EU citizens while being located anywhere in the universe, it applies to you.

If you never have any plans to step foot in the EU, then they can't do anything to you.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#40
post #6

I can’t wait for the day the EU actually tries to enforce their laws on individuals and companies with no presence there. Will be a fun extradition battle to watch

It wouldn't be extradition, it would be sanctioning. Same mechanisms and difficulties apply as trying to sanction Russian oligarchs.
Post reply on HN