Live data from Hacker News

Ask HN: Does HN respect the GDPR?

news.ycombinator.com

41–50 of 107 posts

Re: Ask HN: Does HN respect the GDPR?

#41

Earlier quoted context omitted.

So all web sites (most, anyway) are subject to the GDPR because they may record EU IP addresses in logs?

Yup, which is what makes GDPR so dangerous.

Massachusetts is attempting to promulgate sales taxes on out of state Internet purchases using similar logic applied to cookies [0]. It seems that all it takes is nouns being put on these things, for that parasitic ambient authority to attempt to jam itself in.

Having said that, as a USian, it seems like it's at least possible for EU regulation to have its intended effects (/me glances at uUSB connectors on everything). So, especially because I bear no responsibility for its existence, I'm cautiously optimistic that the GPDR will do some good pushing back against the surveillance industry, rather than simply being yet another tool to strip individuals' freedoms away.

[0] Hey, maybe if it holds up in court, it will spur development and adoption of browser-based nym management!

Re: Ask HN: Does HN respect the GDPR?

#42
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

I'm not a lawyer either, but have been going through the GDPR process at my job. It doesn't matter if you operate or are established in the EU. If you have EU visitors/users they gain the protections of the GDPR and you have to comply.

GDPR affects any org/site that collects personal or sensitive data. Amongst many others IP address and email address are considered PII under GDPR. We use IP address for some high level geolocation data and decided to drop the last octet so it's not tied directly to an individual visitor. The specialists we spoke with had concerns about free form input fields because anyone can write anything they want in them.

In the case of hackernews it seems like email address, ip, profiles, and comments could contain personally identifiable data. I'm also curious how HN similar sites are supposed to comply with GDPR removal requests when it can destroy the usability and functionality of the site.

Re: Ask HN: Does HN respect the GDPR?

#44
post #30
post #23

Earlier quoted context omitted.

We're working on it.

For months now. That is not credible. Seems like you actually need legislation as a deadline.

This is still vgf. The first vgf was rate-limited ("you are posting too fast").

I created another user, vgf2. That user was also affected by the same rate-limit, based on cookies or IP.

I'm now on a VPN in incognito mode, so no old cookies.

I also note that this thread suddenly jumped from moving quickly onto the top of the front page to somewhere in the middle of page 2. Oh my.

I dunno what to say except: shame on you, HN/YC.

Re: Ask HN: Does HN respect the GDPR?

#45

What happens when I ask Google to go through everyone's gmail inbox and remove my information and all emails I've sent?

Granted I've only sat in on a few GDPR meetings, but I don't think it works like that.

In your example you were the one that sent your information to some other 3rd party, so you would be the one responsible for that data transfer and its consequences.

Re: Ask HN: Does HN respect the GDPR?

#46

What happens when I ask Google to go through everyone's gmail inbox and remove my information and all emails I've sent?

Interesting question. Google might argue you should direct your request to those individuals you emailed to. Google storing the emails doesn't necessarily mean that they're responsible for processing your deletion request under the GDPR (or maybe it does, I'm just speculating).

Re: Ask HN: Does HN respect the GDPR?

#47
post #34
post #27

Earlier quoted context omitted.

So what? Countries don't get to make laws for other countries. That's the point in having markets of ideas.

But countries decide who to punish for what. One thing might not be unlawful in your country, but in another, and that other country can try to go after you. That fact is rather boring and well-established. What matters is how the other country enforces the punishment.

The thing is, the EU doesn't have sovereignty outside of Europe. If I actually have presence in the EU, or do business with the EU, that's one thing. But they can't tell some rando with a blog living in Boston to delete comments any more than North Korea can pass a law banning making fun of Kim Jong Un in Berlin. They can huff and puff, but at the end of the day they just don't have the authority.

Re: Ask HN: Does HN respect the GDPR?

#48

What happens when I ask Google to go through everyone's gmail inbox and remove my information and all emails I've sent?

Granted I've only sat in on a few GDPR meetings, but I don't think it works like that. In your example you were the one that sent your information to some other 3rd party, so you would be the one responsible for that data transfer and its consequences.

Is that not exactly what OP is asking for, but for HackerNews instead of Gmail? Gmail is hosting the data I sent. Not to mention that I sent the emails to their servers, not some third-party.

Re: Ask HN: Does HN respect the GDPR?

#49
post #22
post #8

Earlier quoted context omitted.

my understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)

How would EU law compel a non-EU entity to delete content based on the residency of the user? As an example of the opposite state, where this does definitely apply: Tarsnap complies with Canadian law around collecting names/addresses for users who are located in Canada, because Tarsnap is operated as a Canadian business. But if Tarsnap were located in the US, it would not be responsible for collecting that informatio…

> How would EU law compel a non-EU entity

Because US and EU have singed agreements to that effect. It's the price US must pay for EU to allow American internet companies to serve EU customers.

It obviously applies to any company with direct business operations in any one of the 28 member states of the EU. But financial transaction is not nessesary for the extended scope of the law to kick in. Collecting personal data from EU citizen is enough.

Post reply on HN