10 ms·
Ask HN: Does HN respect the GDPR?
Specifically, does HN/Y Combinator plan to allow contributors from the EU to request their contributed content to be deleted after May 25?
Note that they currently do not allow bulk deletes of one contributor's messages, "as that would wreck havoc in the discussion threads".
Basically you can ask nicely to delete some few posts, but if you want to delete all of your contributions you will get a no. This is at odds with the GDPR.
- emodendroket 9y agoAre they under any obligation to?
- hprotagonist 9y agoThe regulation applies if the data controller, an organisation that collects data from EU residents, or processor, an organisation that processes data on behalf of data controller like cloud service providers or the data subject (person) is based in the EU. The regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. According to the European Commission, "personal data is any information relating to an individual, whether it relates to his or her private, professional or public life. It can be anything from a name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer’s IP address." https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Scope https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- JungleGymSam 9y agoSo, no?
- teraflop 9y agoHN certainly processes IP and email addresses of individuals within the EU.
- jakeogh 9y agoSo what? Countries don't get to make laws for other countries. That's the point in having markets of ideas.
- madez 9y agoBut countries decide who to punish for what. One thing might not be unlawful in your country, but in another, and that other country can try to go after you. That fact is rather boring and well-established. What matters is how the other country enforces the punishment.
- zenhack 9y agoThe thing is, the EU doesn't have sovereignty outside of Europe. If I actually have presence in the EU, or do business with the EU, that's one thing. But they can't tell some rando with a blog living in Boston to delete comments any more than North Korea can pass a law banning making fun of Kim Jong Un in Berlin. They can huff and puff, but at the end of the day they just don't have the authority.
- madez 9y agoAny jurisdiction can "tell you things" and judge you, even if it's not your own. Admittingly, without cooperation with your jurisdiction, the EU jurisdiction cannot enforce a meassure if you don't have any presence under EU jurisdiction. However, if your jurisdiction cooperates with the EU jurisdiction, or if you eventually have some kind of presence in the EU, like traveling, they can go after you.
- zie 9y agoIANAL but I agree. If an entirely US based company was found guilty in a court of law in the EU, but has no business interests in EU, and has no assets of any kind, then the most the EU could do is ask the US politely to do something about the company FOR THEM. the US would have no requirement (unless there is some treaty around this I'm unaware of) to do anything about it. If they had assets of some kind in the EU country, they could capture those assets presumably. But from what I understand with the GDPR at least at the beginning of this, is the EU govt will first try to work with the company to help them comply, before going to such drastic measures as courts and seizing assets. I imagine the large giants like Facebook, etc will just negotiate through their army of lawyers to minimize the effects of GDPR as much as possible, and delay as long as possible. Before ultimately implementing ~ 1/2 of the best intentions behind the GDPR in about a decade or so.
- icedchai 9y agoSo all web sites (most, anyway) are subject to the GDPR because they may record EU IP addresses in logs?
- mschuster91 9y agoYup, which is what makes GDPR so dangerous.
- ryanlol 9y agos/dangerous/good/
- mindslight 9y agoMassachusetts is attempting to promulgate sales taxes on out of state Internet purchases using similar logic applied to cookies [0]. It seems that all it takes is nouns being put on these things, for that parasitic ambient authority to attempt to jam itself in. Having said that, as a USian, it seems like it's at least possible for EU regulation to have its intended effects (/me glances at uUSB connectors on everything). So, especially because I bear no responsibility for its existence, I'm cautiously optimistic that the GPDR will do some good pushing back against the surveillance industry, rather than simply being yet another tool to strip individuals' freedoms away. [0] Hey, maybe if it holds up in court, it will spur development and adoption of browser-based nym management!
- emodendroket 9y agoIt seems a little different if we're talking about selling and shipping goods to a territory.
- mindslight 9y agoPer US federal law, retailers are only responsible for collecting a given state's sales tax if they have a physical presence in that state. The legal theory specifically relies on considering the cookie on the user's computer as a physical presence in the state.
- emodendroket 9y agoRight, so the data controller in this case is HN... which is based in the United States. What am I missing?
- DanBC 9y ago> The regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU.
- deleted 9y ago[deleted]
- davidjgraph 9y agoFor me the question that a lot of people will be asking after 25th May, is what happens if they don't? I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing.
- mschuster91 9y ago> I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing. No. The danger is that Internet goliaths will use the GDPR to intimidate or even shut down smaller competitors. Think of patent trolls, just worse - because the GDPR has really huge fines attached and is damn easy to get wrong in implementations. While the GDPR was intended to be beneficial to EU consumers, I fear it will end up being most beneficial to lawyers.
- deleted 9y ago[deleted]
- dpwm 9y agoI'm interested in how you think this would work. As far as I can tell, the enforcing authority for the country where the individual affected resides would need to investigate. And frankly, where a smaller entity was playing fast and loose with data, I would want the authorities to investigate. For instance, in the UK the plan appears to be for the ICO to work with companies and fine where there's a major breach and appropriate security wasn't implemented. Now, perhaps some individuals will band together and complain, but they do not stand to gain from the enforcement in the same way that patent trolls do. We're going from an era where companies can claim AES encrypted at rest and AES encrypted over the wire whilst running an ancient stack full of vulnerabilities and, above a certain scale, not even worry about it. I personally have high hopes that the GDPR will at least make people running companies like that worry a bit.
- vgf 9y agoA particularly ugly thing happens if the HN mods for some good or bad reason decide to ban an account: their contributions will be there forever, with no ability to append explanations to previous posts. This will after May 25 be illegal for services offered in the EU, but I kind of think that the same courtesy should apply to non-europeans.
- aaron-lebo 9y agoNot to devalue privacy (at all), but if the GDPR is so far reaching that anonymous posts are expected to comply with this, that destroys much discussion. Don't see why that's a reasonable expectation. That's no longer private but public data. If you contribute to public knowledge/discussion, then taking your ball and going home leaves huge gaps in history, the same way you see [deleted] throughout many Reddit threads. Is the GDPR that far reaching?
- Dylan16807 9y ago> no ability to append explanations to previous posts Nobody can reply to posts that are more than a month old anyway. And the edit window is only a few hours.
- krapp 9y agoI feel like Hacker News should auto-delete threads that old, anyway. Chances are there's nothing there people will care about, and if they do, they can make their own archive.
- cedsav 9y agoI'm not a lawyer, but HN is not established (AFAIK) in the EU, and while it has EU users, it likely does not meet the threshold of actively offering goods or services to EU residents. Being accessible from the EU in itself isn't sufficient to trigger the GDPR.
- huac 9y agomy understanding is that these conditions apply to people in the EU, i.e. that EU residents must be able to delete their content from HN (but HN has no obligation to non-EU residents)
- cedsav 9y agoI haven't researched that particular point, but I'm not sure that your HN comments qualify as "personal data" under the GDPR (they'd need to personally identify you).
- mziel 9y agoIP addresses are identified as personal data in GDPR. They're not exposed in the frontend, but HN might use them e.g. for logging. Also things like deletion, takeout and consent/opt-out need to be supported (provided that HN falls under GDPR).
- M2Ys4U 9y ago"Personal data" is defined quite broadly in the GDPR: Article 4 states ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
- bostik 9y agoI just read a pretty interesting white paper (written by a compliance law firm) about data anonymisation and pseudonymisation with regards to GDPR. It provided a really neat ballpark of data that constitutes "user information" on two separate levels. Direct identifiers include such material as: name, address, phone number, all kinds of national identifiers, biometrics, device identifiers and clinical trial record numbers. Indirect (or "quasi-direct", a new word for me) include: gender, date of birth, postal codes or other geographic grouping identifiers, first language at home, marital status, ethnicity, .... --- If you look at the two groups, there's a pretty clear distinction. Anything that would allow to send a highly personalised communication to a person is direct. Anything that allows to target marketing cohorts is indirect. The indirect ones may not sound important on the surface, but once you start doing group intersections, their combinations can become extremely narrow pointers.
- peterkelly 9y agoI agree it would cause problems with the discussion threads, but a solution to this would be for HN to substitute the username & message with "Removed due to GDPR request" or similar.
- NicoJuicy 9y agoOr decouple the content from the username/email, GDPR approved, content is still alive
- vgf 9y agoThey "do not support that". Agree that it would be a nice workaround. Should also be technically trivial.
- sctb 9y agoWe're working on it.
- vgf 9y agoFor months now. That is not credible. Seems like you actually need legislation as a deadline.
- mziel 9y agoThis is the case with most organisations. You have a finite amount of resources and attention, therefore you need to prioritise. Most GDPR chatter started picking up only in the last few months (of course big orgs have been preparing for the May deadline for a while already).
- vgf3 9y agoThis is still vgf. The first vgf was rate-limited ("you are posting too fast"). I created another user, vgf2. That user was also affected by the same rate-limit, based on cookies or IP. I'm now on a VPN in incognito mode, so no old cookies. I also note that this thread suddenly jumped from moving quickly onto the top of the front page to somewhere in the middle of page 2. Oh my. I dunno what to say except: shame on you, HN/YC.
- NicoJuicy 9y agoDownvoted, deadline hasn't passed. No reason to stress about it
- idbehold 9y agoWhat happens when I ask Google to go through everyone's gmail inbox and remove my information and all emails I've sent?
- deleted 9y ago[deleted]
- rando444 9y agoGranted I've only sat in on a few GDPR meetings, but I don't think it works like that. In your example you were the one that sent your information to some other 3rd party, so you would be the one responsible for that data transfer and its consequences.
- idbehold 9y agoIs that not exactly what OP is asking for, but for HackerNews instead of Gmail? Gmail is hosting the data I sent. Not to mention that I sent the emails to their servers, not some third-party.
- rando444 9y agoWhile laws like this allow for large grey areas where all of this is up for debate, the focus of the GDPR is largely on two things. (1) Companies that collect data and "process" it. If you're hosting it with reason, it's no big deal. If you're actively doing something with it, then you can run afoul of the law. (2) Companies that share their information with third parties. It puts a much larger onus on companies that have your data to use it appropriately and only for intended purposes. If you read through the wording of the law, it's perfectly possible to have an e-mail service that complies with everything. I think the crux of this particular argument though is whether or not you "own" the emails you sent. I think at the most if you pushed this issue to the max you could get a company to scramble your email address so that it doesn't identify you anymore... but all of this is more a thought exercise about minute details. The true intent of the law is the major points above.
- cedsav 9y ago
- RcouF1uZ4gsC 9y agoMaybe the easiest thing to do is for websites to place a banner that if you are a EU citizen, you are not welcome or allowed to view the website and are violating the terms of service.
- jakeogh 9y agoForced labor? Forced speech? Demanding others time without compensation? What is Europe becoming?
- JulienRbrt 9y agoI have never understood why HN does not do like Reddit – replacing the username by [deleted] or ghost.