Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

81–90 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#81
Short answer: no.

https://gdpr-info.eu/art-17-gdpr/

In particular, there are sections about archiving and freedom of expression/information which I believe would apply to an online discussion forum where all comments are made public by virtue of them being posted in the first place.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#82
post #58

Earlier quoted context omitted.

If the poser is freezing to death in California (CCPA) then we've all got to be worried...

California is big. Freezing/lack of heat/power in the winter IS a concern in the Eastern Sierras.

My comment wasn't meant ot be about California's weather, although ofc I see why you read that meaning.

The US is producing a hug excess of natural gas, which it'd almost certainly keep onshore if Americans were at risk of freezing to death. If someone in the Eastern Sierras is freezing to death this winter due to lack of gas, then no one comes out of that scenario unscathed.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#83

Earlier quoted context omitted.

Pretty sure it requires deleting comments if requested, this at least how my employer treats GDPr.

Public comments really aren’t personal information.

If they include personal information, then they absolutely are (a quick search for "GDPR user generated content" is enlightening). If I posted my full name and address in this comment, I believe a GDPR deletion request would indeed legally require HN to delete it (if I lived in the EU, that is, which I don't).

And that's the problem: the vast majority of HN posts probably don't include personal information. But if someone were to submit a GDPR deletion request to HN, does HN really want to spend the time auditing perhaps hundreds or thousands of comments in order to determine what has personal information in it and what doesn't? And then also making a judgment as to whether the entire comment would need to be deleted, or if only part of it needed to be redacted? So I'd completely understand if HN would comply by deleting all comments.

(I'm intentionally ignoring the fact that it's unclear if the EU could even enforce the GDPR against HN/YC, as I'm not sure if they have any business entities in the EU. Certainly the GDPR as written tries to be extraterritorial in its demands, but enforcement is another matter. HN/YC are of course subject to the CCPA, though.)

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#84

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Discord was fined 800k euros just today for keeping deleted account's data for too long among other things, which is something at least. https://www.cnil.fr/en/discord-inc-fined-800-000-euros

Reading the summary you linked, it isn't clear if Discord is being fined solely over retaining account information alone, or if that includes comments/messages.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#87
Does HN needs to cancel user comments under GDPR?

Ina short anwer : YES, but not because what you think.

Under GDPR you have the right to ask your PII to be erased from production (it still goes under archive for a some time depending on legal constraints)

So it is valid demand for HN to ask your comments to be erased from be “live” in production

Are your comments PII? Yes, as they are linked to a user, username that is linked to an email and bio, and they may contains also PII inside.

So you could ask it to be removed.

Can HN avoid that deletion? Yes only if they prove they have a more valid reason with a legitimate interest to keep it, or that there is any relevant legal obligation to keep it

Do they have ? Not really in that case, however they could also rely on the existence of a particular legitimate interest to inform (if they prove that they are a media), or that there is a legitimate interest relying on the impossibility to understand conversations if you cut off some parts of the discussions and the related feeds.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#88
post #73

Earlier quoted context omitted.

The GDPR doesn't allow people to start lawsuits. The law is upheld by government agencies, which usually give small companies a chance to fall in line before starting a lawsuit. They're also mostly focused on European businesses and most likely won't act until they receive enough complaints. When it comes to lawyer fees, governments seem to have quite a pool of money when it comes to enforcing the law.

> The GDPR doesn't allow people to start lawsuits. it most certainly does the national authorities should be the first avenue, but if they don't agree with you you can go after the company directly

I suppose, but it'll take months before you can even start taking action by yourself, and you'll have to find a good reason to disagree with the DPA's lawyers. The DPA declaring your case unenforceable certainly doesn't help your chances; maybe if the DPA doesn't have time for your complaint do you have a chance.

Even then the recouped damage is minimal if you win. The GDPR is not like many other laws that give way to massive civil suits.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#89

I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…

HN is part of YCombinator which does business in Europe (see: https://www.ycombinator.com/companies?regions=Europe ). Companies doing business in Europe must follow European law, just like European companies doing business in the USA need to follow American law. The solution is quite obvious: don't do business with Europe and the GDPR doesn't apply. Don't do business with the USA (including companies like Amazon and…

lol ycombinator investing in companies is not the same as "doing business".

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#90
post #24

I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…

That's a very poor analogy, as you can put tariffs on Chinese steel and disallow imports unless they adhere to EU standards.

That's not regulating the production of steel, but adding a tariff on an industry. You could obviously block someone from selling in your country, but that doesn't mean you have the right to regulate them.

Just like you could block a website within your country. That said, you can't force them to adhere to anything.

Put a different way, if I run a news paper in Russia, sure you can block the distribution in the EU. The EU cannot tell the news paper what to publish.

Post reply on HN