4 ms·
I'm curious: why is hacker news non-GDPR-compliant?
by klez 5mo ago
I'm curious: why is hacker news non-GDPR-compliant?
- deleted 5mo ago[deleted]
- walthamstow 5mo agoYou can't delete your account by self-service, you have to email dang, which is probably non-compliance because it adds friction. It's a grey area, it'd have to be tested in court. I highly doubt anyone will bring a case though. That's like calling the police on your own drug dealer. (IANAL)
- dgellow 5mo agoI don’t see how that has anything to do with GDPR. An email is a perfectly fine way to initiate the process. It’s not a gray area
- deleted 5mo ago[deleted]
- KaiserPro 5mo ago> which is probably non-compliance because it adds friction. You're gonna have to point to part of the regulation where thats not allowed. there is a mechanism for deletion. so long as its done within 30 days its still within spec
- deleted 5mo ago[deleted]
- walthamstow 5mo agoI don't know it inside out but I'm following the basic standard "it should be as easy to withdraw consent as give it" The overall point being that if you want to use a product/service, you'll look past minor violations of local regulations on account deletion or charger bundling.
- gcr 5mo agoGiving consent required you to receive an email to verify your account. Revoking consent requires you to send an email. It’s symmetric, like poetry.
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- bityard 5mo agoYou're admitting to not actually knowing the law, yet accusing someone of being in violation of it...
- deleted 5mo ago[deleted]
- stronglikedan 5mo agoreddit in a nutsh... oh wait...
- jve 5mo ago> You can't delete your account by self-service, you have to email dang, which is probably non-compliance because it adds friction GDPR has nothing to do with friction I beleve. Our lawyer told me that GDPR also applies to paper records, so there is some real-world friction right there. The important part that there is a right - in whatever good/broken process it is enveloped is irrelevant. Moreover does HN host PII data? Not if you don't give it to them.
- rcxdude 5mo agoSome of GDPR's language around consent for data processing (which, I will note, you only need if you don't have a legitimate and expected purpose for storing and processing it!) has implications for friction: many 'cookie popups' are not compliant because they make not giving consent harder than giving consent. But deletion requests are not so strong: if you make people really jump through hoops then you might get in some trouble, but the expencted standard is basically at 'sending an email and getting a result within 30 days'.
- jve 5mo agoDepending on the data "sending an email and getting a result within 30 days" may not be basis for approving deletion request. You have no way to identify whether the data is associated with the person (if the data is not associated with the email). So additional validation would surely be subject to friction.