Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

51–60 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#51
As far as GDPR goes, according to Article 3 of GDPR it applies to processing if any of three conditions are met:

1. Processing that takes place in the context of processors and controllers that are in the Union, regardless of whether or not the processing itself takes place in the Union.

2. Processing the data of subjects who are in the Union by controllers or processors who are not in the Union if the processing is related to offering goods or services to such subjects in the Union or the processing is related to monitoring the behavior of such subjects that takes place in the Union.

3. Processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

If none of those cover an entity, that entity's processing is not covered by GDPR.

#2 would probably be the only relevant one for HN.

Is HN offering goods or services to subjects in the Union? Sure, people in the Union can access HN and even make accounts. But that might not be enough. One of the recitals for Article 3 elaborates:

> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.

Does HN envisage offering services in the Union, or is it simply a site that happens to work when accessed from the Union but was not envisaged to do so?

Another recital elaborates on the monitoring of behavior of subjects in the Union:

> In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.

HN seems to collect minimal data. It might not rise to the level of monitoring that would be needed to count as monitoring behaviour.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#52

HN is a respite from those awful cookie banners, that's something.

Why would HN need to follow rules from EU or China? This OP must be kidding. What about following Cameroon law? What makes EU more important? What if they conflict? Pass all the laws you want to in Bolivia for PII, HN should just ignore it. No they shouldn't hand all our data to Pakistan to abide by their laws either.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#53

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Discord was fined 800k euros just today for keeping deleted account's data for too long among other things, which is something at least. https://www.cnil.fr/en/discord-inc-fined-800-000-euros

  Failure to ensure the security of personal data (Article 32 of the GDPR)
  At the time of the online investigation, when creating an account on DISCORD, a password of six characters including letters and numbers was accepted.

  The restricted committee considered that DISCORD's password management policy was not sufficiently strong and restrictive to ensure the security of users' accounts.
Kind of surprising the GDPR is so prescriptive about password requirements!

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#54

Earlier quoted context omitted.

Seems like a risky gambit; AFAIK YC owns HN and would have a hard time arguing that that they're a small business incapable of following GDPR regs.

It's not a general "we can't do this" argument, it's got specific criteria, one being company size for certain regs to apply. But honestly YC probably doesn't even think about any of this, for good or bad. Most companies are super duper behind the ball on privacy regulations, despite the negative consequences.

Right. IDK how the size of YC gets calculated for the purposes of GDPR. It's a weird edge case.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#55

I'd guess HN isn't big enough for basically any privacy law to apply. Some parts of GDPR at least call out company size explicitly, other parts allow for "cost of implementation" to be considered, which for HN would probably be "prohibitively high" regardless of triviality, considering the team size.

Seems like a risky gambit; AFAIK YC owns HN and would have a hard time arguing that that they're a small business incapable of following GDPR regs.

The other way to look at it is that HN is too small to go after as in it would cost more in lawyers than they could recoup, possibly.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#58

Quoted post unavailable.

If the poser is freezing to death in California (CCPA) then we've all got to be worried...

California is big. Freezing/lack of heat/power in the winter IS a concern in the Eastern Sierras.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#60

CCPA states: The right to know the personal information that businesses have collected from an individual The right to opt-out of the sale of consumer data collection The right to delete personal information collected from them HackerNews doesn't collect personal data. Deleting anything someone wants deleted isn't covered

Pretty sure it requires deleting comments if requested, this at least how my employer treats GDPr.

Public comments really aren’t personal information.
Post reply on HN