Live data from Hacker News

Ask HN: Does HN respect the GDPR?

news.ycombinator.com

71–80 of 107 posts

Re: Ask HN: Does HN respect the GDPR?

#71

Earlier quoted context omitted.

I'm not a lawyer either, but have been going through the GDPR process at my job. It doesn't matter if you operate or are established in the EU. If you have EU visitors/users they gain the protections of the GDPR and you have to comply. GDPR affects any org/site that collects personal or sensitive data. Amongst many others IP address and email address are considered PII under GDPR. We use IP address for some high leve…

I'm very interested to see how such requests would actually work...mainly because I'm curious to see what actual authority the EU has to enforce its laws outside of its borders. I understand it applying to companies that are doing business in Europe but beyond that...?

There's a plenty of measures the EU could take within it's jurisdiction to enforce it's laws around the world.

It might suck if the EU started blocking payments to you.

Re: Ask HN: Does HN respect the GDPR?

#72
post #67
post #49

Earlier quoted context omitted.

> How would EU law compel a non-EU entity Because US and EU have singed agreements to that effect. It's the price US must pay for EU to allow American internet companies to serve EU customers. It obviously applies to any company with direct business operations in any one of the 28 member states of the EU. But financial transaction is not nessesary for the extended scope of the law to kick in. Collecting personal data…

Which agreement between the US and EU mandates this?

EU-U.S. and Swiss-U.S. Privacy Shield Framework.

It came to effect 2016 and replaced the Safe Harbor agreement.

Re: Ask HN: Does HN respect the GDPR?

#73
post #72
post #67

Earlier quoted context omitted.

Which agreement between the US and EU mandates this?

EU-U.S. and Swiss-U.S. Privacy Shield Framework. It came to effect 2016 and replaced the Safe Harbor agreement.

"While joining the Privacy Shield is voluntary, once an eligible organization makes the public commitment to comply with the Framework’s requirements, the commitment will become enforceable under U.S. law."

From https://www.privacyshield.gov/Program-Overview

Re: Ask HN: Does HN respect the GDPR?

#74
post #70
post #69

Earlier quoted context omitted.

I'm not sure where you derived your comment about gut-feelings from. Do you have an example of precedent for one country's laws being enforced on a company with no business presence in that country, without there being a law or treaty in a country the business does operate in that mandates compliance with the foreign law? I don't think anyone would dispute that if the US were to make a law requiring US companies to c…

> My point is that absent some measure by the US government, EU laws are not applicable to companies without business presence in the EU They are applicable if they say they are applicable. Effective enforceability is optional to applicability. The case is pretty simple in my eyes. We have separate, sovereign jurisdictions and governments. They can do about anything they want, if they have the means to do so and aren…

I'll admit to what feels like a pedantic point: Yes, the EU can make a law saying it'll be very very angry if a non-EU entity does not do what it wants. But since this post is asking about HN's compliance with the GDPR, it seems practical to scope the conversation to "Can the EU make and enforce a law that affects non-EU entities".

Otherwise, it's fair to say that I can personally draft a document saying HN must give me $3.50, and sign it into law for the House Of Akerl. But my law is quite uninteresting to HN, given the low odds of any of the YC folks sending me $3.50.

Re: Ask HN: Does HN respect the GDPR?

#75

Earlier quoted context omitted.

Yup, which is what makes GDPR so dangerous.

Massachusetts is attempting to promulgate sales taxes on out of state Internet purchases using similar logic applied to cookies [0]. It seems that all it takes is nouns being put on these things, for that parasitic ambient authority to attempt to jam itself in. Having said that, as a USian, it seems like it's at least possible for EU regulation to have its intended effects (/me glances at uUSB connectors on everythin…

It seems a little different if we're talking about selling and shipping goods to a territory.

Re: Ask HN: Does HN respect the GDPR?

#76
post #6

I'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.

I'm not a lawyer either, but have been going through the GDPR process at my job. It doesn't matter if you operate or are established in the EU. If you have EU visitors/users they gain the protections of the GDPR and you have to comply. GDPR affects any org/site that collects personal or sensitive data. Amongst many others IP address and email address are considered PII under GDPR. We use IP address for some high leve…

In the case of hackernews it seems like email address, ip, profiles, and comments could contain personally identifiable data.

You aren't required to put anything in the profile. If you choose to put information in the profile, you can remove it yourself at any time you so choose.

Re: Ask HN: Does HN respect the GDPR?

#77
post #74
post #70

Earlier quoted context omitted.

> My point is that absent some measure by the US government, EU laws are not applicable to companies without business presence in the EU They are applicable if they say they are applicable. Effective enforceability is optional to applicability. The case is pretty simple in my eyes. We have separate, sovereign jurisdictions and governments. They can do about anything they want, if they have the means to do so and aren…

I'll admit to what feels like a pedantic point: Yes, the EU can make a law saying it'll be very very angry if a non-EU entity does not do what it wants. But since this post is asking about HN's compliance with the GDPR, it seems practical to scope the conversation to "Can the EU make and enforce a law that affects non-EU entities". Otherwise, it's fair to say that I can personally draft a document saying HN must give…

Well, it seems we agree that the EU can make a law theoretically-legally affecting non-EU entities.

Can that law be enforced? That depends on whether YC has a representation in the EU, or people from YC plan to visit the EU in the future, or many other things. Maybe the EU gets creative to find other ways of enforceability. I don't intend to give a full assessment of the ways of enforcement.

Either way, it is not a nice thing to have a big jurisdiction going after you.

One can avoid the GDPR by not handling data from or about European citizens or people in the EU, and having no presence there, and actively filtering out affected people.

Or one can implement the GDPR.

Re: Ask HN: Does HN respect the GDPR?

#78
post #65
post #27

Earlier quoted context omitted.

So what? Countries don't get to make laws for other countries. That's the point in having markets of ideas.

Nice idea, but not 100% consistent with reality. Several countries apply their laws to their citizens, even if they aren’t in their own country. For example ”Your worldwide income is subject to U.S. income tax, regardless of where you reside.” ( https://www.irs.gov/individuals/international-taxpayers/us-c... ) Other example: the “Hague invasion act” which authorizes the US president to invade Europe in order to liber…

If I am in my country, I am only bound by the laws in my country. Sure I can piss off another country (violate their blasphemy laws for example) and then I better remember to not go there.

Re: Ask HN: Does HN respect the GDPR?

#79
post #73
post #72

Earlier quoted context omitted.

EU-U.S. and Swiss-U.S. Privacy Shield Framework. It came to effect 2016 and replaced the Safe Harbor agreement.

"While joining the Privacy Shield is voluntary, once an eligible organization makes the public commitment to comply with the Framework’s requirements, the commitment will become enforceable under U.S. law." From https://www.privacyshield.gov/Program-Overview

U.S companies have option to either do legally binding self-certifications or outside compliance reviews.

If they don't do that, they have no authority to collect data from EU Citizens (no user accounts or customers from EU).

Re: Ask HN: Does HN respect the GDPR?

#80
post #25
post #8

Earlier quoted context omitted.

my understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)

Yes, but you need to explicitly target the EU. What that exactly means will be determined will eventually be determined in court, but some examples: - If you offer your products in Euros, which is the currency in most of the EU - If you offer payment methods which only exist in the EU or one of its members - Otherwise suggest you target EU citizens Hacker News exists as a generic website on the internet, but it does…

That is incorrect. You don't need to specifically target the EU. If you handle data from European citizens, the GDPR applies to you.
Post reply on HN