Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

71–80 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#71

Earlier quoted context omitted.

Seems like a risky gambit; AFAIK YC owns HN and would have a hard time arguing that that they're a small business incapable of following GDPR regs.

The other way to look at it is that HN is too small to go after as in it would cost more in lawyers than they could recoup, possibly.

The GDPR doesn't allow people to start lawsuits. The law is upheld by government agencies, which usually give small companies a chance to fall in line before starting a lawsuit. They're also mostly focused on European businesses and most likely won't act until they receive enough complaints.

When it comes to lawyer fees, governments seem to have quite a pool of money when it comes to enforcing the law.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#72

HN is a respite from those awful cookie banners, that's something.

Why would HN need to follow rules from EU or China? This OP must be kidding. What about following Cameroon law? What makes EU more important? What if they conflict? Pass all the laws you want to in Bolivia for PII, HN should just ignore it. No they shouldn't hand all our data to Pakistan to abide by their laws either.

CCPA is not from China https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#73

Earlier quoted context omitted.

The other way to look at it is that HN is too small to go after as in it would cost more in lawyers than they could recoup, possibly.

The GDPR doesn't allow people to start lawsuits. The law is upheld by government agencies, which usually give small companies a chance to fall in line before starting a lawsuit. They're also mostly focused on European businesses and most likely won't act until they receive enough complaints. When it comes to lawyer fees, governments seem to have quite a pool of money when it comes to enforcing the law.

> The GDPR doesn't allow people to start lawsuits.

it most certainly does

the national authorities should be the first avenue, but if they don't agree with you you can go after the company directly

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#74
What part of the GDPR specifies that a company must remove your posts?

Sure, it's a bit weird to force them to stay up, but the GDPR is mostly about PII. You can probably have your email address, username, and contact information removed from the database, but the comments themselves are different.

I don't know much about the CCPA, but from what I've read, I don't think it covers this use case.

As for if YC needs to follow the GDPR: YC does business in the EU so they'd be foolish to ignore it. If you believe your rights are being infringed, contact your local DPA and file a complaint.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#75

Earlier quoted context omitted.

Pretty sure it requires deleting comments if requested, this at least how my employer treats GDPr.

GDPR and CCPA are different laws from different countries.

That's fair, at least at my employer we have simply rolled out GDPR compliance globally so we do not have to do deal with different jurisdictional compliance headaches as much.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#76
post #53

Earlier quoted context omitted.

Failure to ensure the security of personal data (Article 32 of the GDPR) At the time of the online investigation, when creating an account on DISCORD, a password of six characters including letters and numbers was accepted. The restricted committee considered that DISCORD's password management policy was not sufficiently strong and restrictive to ensure the security of users' accounts. Kind of surprising the GDPR is…

Is it actually prescriptive, or does it say (in more legalese form) "use industry best practices to protect user data". Six characters is laughably bad and would fail pretty much any password requirements I've seen in the last decade (except for my credit union who only updated like 5 years ago after finally migrating to a better back end).

The GDPR is actually surprisingly understandable and 'plain English' (obviously, lawyers have their own interpretations of everything).

Key section is probably this one: https://gdpr-info.eu/art-32-gdpr/

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#77

Earlier quoted context omitted.

Why would HN need to follow rules from EU or China? This OP must be kidding. What about following Cameroon law? What makes EU more important? What if they conflict? Pass all the laws you want to in Bolivia for PII, HN should just ignore it. No they shouldn't hand all our data to Pakistan to abide by their laws either.

CCPA is not from China https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...

Sorry I was referring to GDPR

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#78

CCPA states: The right to know the personal information that businesses have collected from an individual The right to opt-out of the sale of consumer data collection The right to delete personal information collected from them HackerNews doesn't collect personal data. Deleting anything someone wants deleted isn't covered

> HackerNews doesn't collect personal data. There's an email field in the settings.

Optional and used for recovery purposes and it is self serve for removal and immediately removed

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#79

CCPA states: The right to know the personal information that businesses have collected from an individual The right to opt-out of the sale of consumer data collection The right to delete personal information collected from them HackerNews doesn't collect personal data. Deleting anything someone wants deleted isn't covered

Pretty sure it requires deleting comments if requested, this at least how my employer treats GDPr.

I think that depends on if comments contain any of your "personal information" (as defined by the GDPR). Certainly it's much easier (and safer) to just delete all of a user's comments than to audit each one and decide which comments have personal information and which don't, so I suspect that's why your employer (and many others, probably) take that route.

But, for example, consider your post here that I'm replying to: I don't think anyone could credibly claim that it contains personal information. I believe HN will anonymize the username on past comments during account deletion (maybe only if requested, though?), so at least the comment wouldn't be attributed to anyone identifiable. But, of course, if someone posted their real name in a comment, or even just information that could identify them, that would be personal information in the comment body itself.

Frankly I'm not a fan of the idea that comments on a public forum need to be deleted as a result of GDPR deletion requests. It would really suck if clicking on an old HN comment thread meant that you'd see a bunch of "[deleted due to GDPR request]" peppered all over the comment threads. Or think of a site like Stack Overflow: it would be a shame if a GDPR deletion request means that SO has to delete all a user's questions (which others may have spent time and effort answering!) and answers (that others would continue to benefit from reading).

I think in this case the GDPR goes too far in making the site owner responsible. Sure, a site owner should absolutely be responsible for personal information it asks for and intentionally collects, but it seems a bit unfair to extend that to information a user may voluntarily submit, in a context where the submission is free-form and unstructured.

Then again, I'm -- perhaps hypocritically -- of the opinion that sites like Facebook should be required to delete all posts and content when someone wants to delete their account. Back when I used it, I'd definitely run into some old post comments where some comments have been deleted (due to account closures), which really confuses the conversation going on in the comments. For some reason my heart is trying to tell me that FB and HN are somehow different here, even though I can't logically support that. I think my feeling is that stuff I post on HN belongs to the community, whereas stuff I (used to) post on FB still belongs to me. Not sure why there should be that difference, though.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#80

Earlier quoted context omitted.

> HackerNews doesn't collect personal data. There's an email field in the settings.

Optional and used for recovery purposes and it is self serve for removal and immediately removed

None of that makes it non-PII.
Post reply on HN