Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

61–70 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#61

Earlier quoted context omitted.

It's not a general "we can't do this" argument, it's got specific criteria, one being company size for certain regs to apply. But honestly YC probably doesn't even think about any of this, for good or bad. Most companies are super duper behind the ball on privacy regulations, despite the negative consequences.

Right. IDK how the size of YC gets calculated for the purposes of GDPR. It's a weird edge case.

I actually operate in this space right now, and you wouldn't believe the number of companies who don't care about privacy, screw it up, get fined hugely, and then... just keep on not caring.

It's unreal.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#62
post #35
post #16

Earlier quoted context omitted.

They are mandatory if by browsing a website your data ends up in a 3rd party, which means almost all websites.

No, banner isn't mandatory. Information is mandatory. I don't remember exact page now but it was some govt page here in Poland that had info about cookies in page footer, and it was also ok

[deleted]

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#63
post #45
post #11

Earlier quoted context omitted.

Dark pattern banners I call them. One day I clicked the 'more options' button on a foreign website and it was a list of over 1000 different third parties listed each with their own toggle.

That's actually how it's supposed to work. Only the most recent ruling, and it was Google specific, forced them to add "Reject all" button.

afaik the law says rejecting all should be as easy as accepting all, which is google got the ruling they did, even having to click "more options" before "reject all" is against the letter of the law, though I don't know that that one will ever actually be enforced.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#64

to put it bluntly, nobody outside the EU has to give a damn about the EU law.

If you conduct business (even if only over the internet) in the EU, the EU considers you subject to their laws. Same as with the United States (and probably every other jurisdiction).

Do you have to comply with EU law if you conduct business there? It depends on whether the EU can enforce judgements against you. If you live in the EU, then the EU can certainly enforce judgements against you. If you live in a cooperating jurisdiction, like the US, then I'm pretty sure that EU judgements can be enforced against you. That would take more effort on the EU's part, but if they really want to, I believe they can ask and get the US courts to enforce judgements.

If you live somewhere where the courts will not enforce EU judgements, then yeah, you don't need to care about EU laws. At least, until you travel someplace that does...

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#65
Short answer: they probably have to delete your personal data.

Long answer: it depends on the regulation. To the best of my understanding yes under the GDPR. If you are interested in what constitutes personal data and when an organisation needs to or does not need to comply with a request under the GDPR and the CCPA take a look here: https://yourdigitalrights.org/#faq

(I am one of the founders of YourDigitalRights.org. We help people send data deletion and access requests. I am not a lawyer and this is not a legal advice.)

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#67

I’ve had all my submissions deleted when requested so not sure what the issue is

And I've had that request denied. That you have to make a case to a single person who can choose what to do about it is the issue as I see it.

But that's not a legal issue, as long as they agree to deletion if you're CA/EU and your data is PII.

I agree on principle that all communication mediums should allow users to delete and edit their own posts. Retraction is speech.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#68
post #45

Earlier quoted context omitted.

That's actually how it's supposed to work. Only the most recent ruling, and it was Google specific, forced them to add "Reject all" button.

afaik the law says rejecting all should be as easy as accepting all, which is google got the ruling they did, even having to click "more options" before "reject all" is against the letter of the law, though I don't know that that one will ever actually be enforced.

afaik technicalities like this can be adjusted by member states and it's country specific. EU court overruled Google case for whole EU.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#69
post #53

Earlier quoted context omitted.

Discord was fined 800k euros just today for keeping deleted account's data for too long among other things, which is something at least. https://www.cnil.fr/en/discord-inc-fined-800-000-euros

Failure to ensure the security of personal data (Article 32 of the GDPR) At the time of the online investigation, when creating an account on DISCORD, a password of six characters including letters and numbers was accepted. The restricted committee considered that DISCORD's password management policy was not sufficiently strong and restrictive to ensure the security of users' accounts. Kind of surprising the GDPR is…

Is it actually prescriptive, or does it say (in more legalese form) "use industry best practices to protect user data". Six characters is laughably bad and would fail pretty much any password requirements I've seen in the last decade (except for my credit union who only updated like 5 years ago after finally migrating to a better back end).

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#70

I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…

HN is part of YCombinator which does business in Europe (see: https://www.ycombinator.com/companies?regions=Europe).

Companies doing business in Europe must follow European law, just like European companies doing business in the USA need to follow American law.

The solution is quite obvious: don't do business with Europe and the GDPR doesn't apply. Don't do business with the USA (including companies like Amazon and Google) and American law doesn't apply. The EU won't try to fine Walmart and Target, the USA probably won't try to fine Système U.

(Unless it's about oil, government influence, or copyright infringement, of course, then the USA will force the issue; probably not relevant for most companies)

Post reply on HN