5 ms·
If you’re in the EU you can refer to the GDPR and request all the data they have on you.
by beokop 8y ago
If you’re in the EU you can refer to the GDPR and request all the data they have on you.
- yorwba 8y agoSure you can, but HN is not GDPR-compliant, so you'll just get pointed at the public API.
- twtw 8y agoHow can HN just choose to be noncompliant? Aren't there penalties? I don't understand the jurisdiction of GDPR very well, but I thought it applied to all EU users.
- beokop 8y agoIt does apply to all EU users and they risk fines if they don’t comply.
- ydnaclementine 8y agoA law is only as good as it is enforced
- mattr47 8y agoIt does not apply as HN is not in the EU. If an EU citizen does not want their data collected then they can choose not to participate, as the EU has no jurisdiction over HN.
- mdekkers 8y agoThat isn't how the GDPR works. There are many GDPR primers on the web, here is a random one. https://www.recode.net/2018/5/16/17360944/gdpr-us-business-eu-european-union-data-protection-privacy https://www.recode.net/2018/5/16/17360944/gdpr-us-business-e...
- zenexer 8y agoThe EU claims that's not how it works. Everyone else claims that is how it works. It's highly unlikely that the EU will actually be able to enforce it globally.
- mdekkers 8y agoIt's highly unlikely that the EU will actually be able to enforce it globally If you want to do business in some way with the EU, or have your business officers visit the EU, then that is how it works. The EU took a leaf out of the USA "global jurisdiction" book.
- freehunter 8y agoYeah if Y Combinator chooses to never do business in the EU (considering one of their companies is Afrostream who does business in the EU, this may be up for debate), they may be able to get away with it. My company only targets US citizens and EU citizens would never get any value of any kind in any way at all from my business, so GDPR is not on my radar. But YC might have a harder time making that claim.
- james_s_tayler 8y agoOnly if they get hit with a notice to comply and then they have a grace period in which to comply, so that's how.
- zenexer 8y agoAnd if they don't comply, what then? None of the penalties can actually be enforced if they have no presence in Europe, unless the US decides to cooperate, which seems unlikely.
- james_s_tayler 8y agoWell this is why I always say "there are no rules, only realities".
- M2Ys4U 8y agoThere's a process by which US courts can enforce foreign judgments. I wouldn't be surprised if supervisory authorities apply to do this for intransigent US companies.
- merb 8y agoyou can be noncompliant if you have no jurisdication inside the eu, i.e. if hn has nothing inside the eu where the eu can actually send a fine. also I doubt that the eu would penal hn, because you can delete your username which will impersonate yourself and also hn does not really save that much personal data.
- kingnothing 8y agoGDPR requests provide 30 days to respond. It's quite possible they have a manual script they can run to grab your data / delete your account, but it isn't exposed via the web.