4 ms·
HN may cite legitimate business interest and not oblige in deletion. A more extreme example can be that when you perform a deletion, do you also deep delete fr
by dyu 9y ago
HN may cite legitimate business interest and not oblige in deletion.
A more extreme example can be that when you perform a deletion, do you also deep delete from logs and backups of logs? What if you need to keep them for audit and forensic purposes?
Edit: citing legitimate business interest does not necessarily mean it will succeed. Courts will have the final say. EU likely will not enforce smaller entities so soon. We may need to see a few court decisions or better guidelines before we get a better idea how to navigate through GDPR.
- drinchev 9y agoAFAIK logs should not contain personal data at all and backups ... you need to figure out a way to delete the already deleted user data when you restore a backup. Interestingly enough. When I request to delete my data from HN, I would expect HN to send algolia (3rd party) a request to do so too. It should all propagate to even Google's search. That's all like too complicated to implement and here ( at least ) in Berlin companies are in huge trouble about the details.
- mankash666 9y agoGDPR rules do not apply to YC - a US company.
- dyu 9y agoI thought the legal side would work in a similar fashion as EU-US Privacy Shield?
- mankash666 9y ago"While joining the Privacy Shield is voluntary, once an eligible organization makes the public commitment to comply with the Framework’s requirements, the commitment will become enforceable under U.S. law" from [1]. I'm not a lawyer, but it's fairly obvious that web services built in accordance with the jurisdiction of incorporation take precedence, especially when the software/service makes no customization to appeal to the EU. Maybe one runs a blog with content critical of China, but since they're running said blog as a US corp on US soil, China cannot apply it's laws on the said blog. [1]: https://www.privacyshield.gov/Program-Overview https://www.privacyshield.gov/Program-Overview
- unicornporn 9y agoThat generalization is just plain wrong. > Article 3 of the GDPR says that if you collect personal data or behavioral information from someone in an EU country, your company is subject to the requirements of the GDPR. Two points of clarification. First, the law only applies if the data subjects, as the GDPR refers to consumers, are in the EU when the data is collected. This makes sense: EU laws apply in the EU. For EU citizens outside the EU when the data is collected, the GDPR would not apply. It's more complicated than that though. Just Google and you will find some valuable information. https://www.forbes.com/sites/forbestechcouncil/2017/12/04/yes-the-gdpr-will-affect-your-u-s-based-business/ https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...
- BjoernKW 9y agoIf that US company wants to do business with people or businesses located in the EU GDPR rules absolutely do apply. Yes, providing a free website can qualify as "doing business", too, for example if the company running the website uses it to attract potential customers, which arguably is one purpose of Hacker News.