Live data from Hacker News

Ask HN: Does GDPR and CCPA Apply to Hacker News?

news.ycombinator.com

91–99 of 99 posts

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#91

What part of the GDPR specifies that a company must remove your posts? Sure, it's a bit weird to force them to stay up, but the GDPR is mostly about PII. You can probably have your email address, username, and contact information removed from the database, but the comments themselves are different. I don't know much about the CCPA, but from what I've read, I don't think it covers this use case. As for if YC needs to…

This is a misconception. GDPR is about any data relating to a potentially identifiable person, not only data which actually identifies them. The thoughts you've posted on HN certainly relate to you!

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#92

Earlier quoted context omitted.

Right. IDK how the size of YC gets calculated for the purposes of GDPR. It's a weird edge case.

I actually operate in this space right now, and you wouldn't believe the number of companies who don't care about privacy, screw it up, get fined hugely, and then... just keep on not caring. It's unreal.

Interesting. Care to guess why? Cost of fines < cost of compliance? "not my job" syndrome? Incompetence? All 3?

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#93
post #12

HN is a respite from those awful cookie banners, that's something.

And those banners aren't even mandatory. Someone did it without learning the actual law and almost everybody does that.

Advertising agencies offer to install these banners to get higher bids from advertisers. Webmasters have a choice. Most choose money.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#94
post #17

There seems to be a legal theory that public discourse is not to be removed under the GDPR. Discord, for example, will also not delete your messages. Part of the problem is also that the government agencies tasked with regulating these things are hopelessly slow in pursing matters, especially when non-EU companies are concerned.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

This is actually incorrect. The US and many other countries have entered into trade agreements with each other. For example, if a company does business in Europe (sells goods or services to EU customers), they are subject to EU regulations in a whole host of areas. The GDPR is only one example of such law.

You, personally, are not subject to EU laws since you are, presumably, not running a business with EU customers or data subjects.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#95

I’ve always found it funny people think GDPR matters outside of the EU. You cannot regulate a steel manufacturer in China from the EU. Similarly, you cannot regulate how a company and server is setup in another country. It’s where the company is operating. In the case of hacker news the CCPA probably does have an impact. So i suspect they follow the appropriate law there. That’s because that’s where they are operatin…

HN is part of YCombinator which does business in Europe (see: https://www.ycombinator.com/companies?regions=Europe ). Companies doing business in Europe must follow European law, just like European companies doing business in the USA need to follow American law. The solution is quite obvious: don't do business with Europe and the GDPR doesn't apply. Don't do business with the USA (including companies like Amazon and…

The EU is desperate to get the sort of funding YC provides so they would never say "no".

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#96
post #5

Have you tried emailing them and asking for your comments and submissions removed under GDPR/CCPA?

Neither of those laws grants that right.

In general don't think they do unless they're directly or indirectly associated with someone's identity, but my question was more of one curious to the poster's outrage - they're upset about not possibly not having their comments removed, well... did they try to ask?

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#97

Earlier quoted context omitted.

I actually operate in this space right now, and you wouldn't believe the number of companies who don't care about privacy, screw it up, get fined hugely, and then... just keep on not caring. It's unreal.

Interesting. Care to guess why? Cost of fines < cost of compliance? "not my job" syndrome? Incompetence? All 3?

It’s this idea that if nobody is doing it, or if they handle it poorly, then nobody will care if you also handle it poorly.

CEOs are just writing it off as pesky lawyer shit, even though it’s 100% preventable…

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#98
post #17

Earlier quoted context omitted.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

US companies that act internationally are not immune from the laws of the states they act within.

True. Putting a website online available to anybody to visit does not mean I’m acting in Europe, though.

Re: Ask HN: Does GDPR and CCPA Apply to Hacker News?

#99
post #17

Earlier quoted context omitted.

Because, as has been pointed out ad nauseam THEY HAVE NO JURISDICTION to tell US companies what to do. Of course, every time I point this out, people get mad at me because they happen to like the law (ie, they like the idea of privacy, and privacy theatre is comforting to them). I'm personally of the opinion that one government telling me what to do is quite enough, thank you very much.

This is actually incorrect. The US and many other countries have entered into trade agreements with each other. For example, if a company does business in Europe (sells goods or services to EU customers), they are subject to EU regulations in a whole host of areas. The GDPR is only one example of such law. You, personally, are not subject to EU laws since you are, presumably, not running a business with EU customers…

The GDPR is explicitly not the same as those laws, claiming that it applies to anybody anywhere who puts a website online for any reason irregardless of any trade agreements.
Post reply on HN