Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

81–90 of 534 posts

Re: Shutting Down Forum (GDPR)

#82
post #73

Earlier quoted context omitted.

>now, because of this useless request No, it is because of an overreaction to a request. If they are acting in good faith then just reply

How many hours should this person put in to respond to the request?

And to all the others.

Re: Shutting Down Forum (GDPR)

#83
Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own.

You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored), odds of any corrective action against you seem very low.

In any case, the corrective demands of the EU give you time to comply after they declare that you've violated something? Could probably wait for that point even if you're in the EU.

Re: Shutting Down Forum (GDPR)

#84
post #42
post #27

Earlier quoted context omitted.

How does GDPR affect people in other countries with no interest in doing business in Europe? If I host a forum in the US and you ask me to remove your posts and I tell you where to stick it, what legal consequences might I face? Erm, asking for a friend.

As much as I dislike Donald Trump, I am willing to hold my nose here and suggest encouraging the Trump Administration to go full MAGA and direct Congress to pass laws explicitly stating that no foreign judgements or fines may be enforced on US citizens.

boom.

1000% increase in foreigners moving/ starting technology companies in the US.

seriously tho. great idea.

Re: Shutting Down Forum (GDPR)

#85
The GDPR seems to me to be just another example of nontechnical authorities trying to regulate what they don't understand.

Why don't more technical people become politicians, or at least form lobbying groups or think tanks?

Re: Shutting Down Forum (GDPR)

#86
post #73

Earlier quoted context omitted.

>now, because of this useless request No, it is because of an overreaction to a request. If they are acting in good faith then just reply

How many hours should this person put in to respond to the request?

About 3 minutes.

"Here's the privacy policy. Here's the data export page."

Re: Shutting Down Forum (GDPR)

#87
post #2

Overbearing legislation applied by unelected representatives is being abused. If only there were technical solutions provided with an assumption of goodwill instead of 88 pages of mandates without such an assumption.

How are the representatives "unelected"? The European Parliament is elected every five years by the citizens of all EU member states and voted on the GDPR in 2016 after long talks. Some even say that the GDPR is not hard enough.

Re: Shutting Down Forum (GDPR)

#88
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

From what I've seen of the policies in other forums: If they posted actual personal information, admins will edit it out on request, but in general they don't consider posts that don't contain anything identifying personal information and will keep them.

Re: Shutting Down Forum (GDPR)

#89
post #50

Earlier quoted context omitted.

> No lawyers required. Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.

>If there's a risk that someone could sue you over something That seems like a pretty broad policy... someone could all the time for any reason no matter how good a reason.

Sure, it's not black and white - it's a scale. We don't lawyer up for literally everything. But we do lawyer up for a lot of things.

It's sort of like the "never roll your own security" advice that gets brought out when people ask questions about crypto. To a certain extent, yeah, we do have to roll our own security. Of course developers need to roll their own stuff, at least at the integration level.

But as soon as it gets even slightly dangerous, I'm not going to be doing, say, my own XSS filtering. I need a vetted library at that point.

I've been taught to think of the law the same way - you don't roll your own legal advice.

Re: Shutting Down Forum (GDPR)

#90

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks.

If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

Post reply on HN