And what happens if someone quotes my comment?
How does the allowance of comment/submission deletion affect HN being perceived as a "permanent record"? I've always found this aspect of HN to be important to me.
If comments can be deleted selectively, what effect does that have on the permanent record? How many users would be tempted to write something they don't want recorded permanently simply to judge responses before they delete the comment later? (As opposed to requiring that all comments for a user be deleted together, which would likely discourage deletion to remove specific comments.)
Would this give rise to third-party "comment recovery" services that scrape something like archive.org (assuming it is less affected by the GDPR) or maintain their own records to piece together comment threads with deleted comments? Similar to services that archive tweets that might get deleted.
Has Hacker News ever presented itself as a service that maintains permanent records for archival sake, or merely one that chooses not to delete comments? I don't think they have an obligation to serve a purpose they never intended to serve.
>How many users would be tempted to write something they don't want recorded permanently simply to judge responses before they delete the comment later?
Users do that now - there is an edit and delete window for comments, it just has a limit.
>Would this give rise to third-party "comment recovery" services that scrape something like archive.org (assuming it is less affected by the GDPR) or maintain their own records to piece together comment threads with deleted comments?
Probably, such services exist for imageboards.
Alas, I'm not a EU citizen so even sites that do afford GDPR protection probably won't respond to requests from me. Like Facebook [1].
[1] https://techcrunch.com/2018/04/04/facebook-gdpr-wont-be-univ...
In the list of "When does the right to erasure apply?", I'm not sure which one you would argue if you wanted to have your HN comments deleted.
1. The data is still necessary for the original purpose
2. HN doesn't rely on consent for this data (I don't think?)
3. I think HN are using legitimate interests, so you could try to object to the processing. I think HN could argue that their legitimate interests override the objection?
4+ Don't apply
So the only one that might work would be point 3. IANAL but it is in HN legitimate interests to keep the comment.
I'm not certain, it seems a bit woolly now I've written it down. It might depend on the seriousness of your objection.
Overall though I think it's important to remember that the right isn't absolute, you can't just have all your data deleted whenever you like. That's not the point of the law.
However, US companies with no legal/corporate presence in the EU are ONLY bound by US law.
Take the case of EFF vs Australian patent troll [1]. Though EFF was sued in Australian court under Australian law, it didn't matter because EFF was an American company.
This holds true, otherwise China could sue US media under Chinese law on the pretext of said media being available within China via the Internet.
Similarly, for the EU to go after non EU corporate/legal entities, it'll need to implement a GDPR firewall, much like China's great firewall. It simply cannot push the onus of GDPR compliance on non EU entities with laws that it can't apply on them
[1]: https://www.eff.org/deeplinks/2017/11/court-rules-effs-stupi...
If US companies (without a EU legal/corporate presence) are beholden to EU law, then US companies are beholden the Chinese censorship laws
Makes no sense at all and the analogy with the Chinese censorship laws is really bad (not sure why I'm reading this analogy again and again on HN). GDPR holds on US businesses only for the EU users. If they don't have EU users they don't have to care about the GDPR. US businesses can have different set of rules for the US and EU market (that's what Facebook plans to do about the GDPR). The GDPR doesn't apply for the US market and the US users. Also US companies can limit their service to the US market if they don't agree with the GDPR.
Again - your opinions are just as valid as mine because there isn't a precedent in US (federal) courts. Stop pretending like your 'opinion' is fact
It's an EU law governing companies holding data about EU citizens. It means that EU courts can rule over the activity of such companies, whether the companies come from the USA or elsewhere. Do you anticipate the EU wanting to test the GDPR in a US court? That would be as strange as the US choosing to test a US law in an EU court.
Take the case of EFF vs Australian patent troll [1]. Though EFF was sued in Australian court under Australian law, it didn't matter because EFF was an American company.
[1]: https://www.eff.org/deeplinks/2017/11/court-rules-effs-stupi...
We all agree that GDPR applies to companies that operate in the EU.
Beyond that, there‘s a big uncertainty. Time will tell how the GDPR will be enforced with regard to companies that don‘t have a presence in the EU.
My guess is that smaller ventures (like HN) are going to fly under the Radar, while bigger companies are going to comply.
A more extreme example can be that when you perform a deletion, do you also deep delete from logs and backups of logs? What if you need to keep them for audit and forensic purposes?
Edit: citing legitimate business interest does not necessarily mean it will succeed. Courts will have the final say. EU likely will not enforce smaller entities so soon. We may need to see a few court decisions or better guidelines before we get a better idea how to navigate through GDPR.
Interestingly enough. When I request to delete my data from HN, I would expect HN to send algolia (3rd party) a request to do so too. It should all propagate to even Google's search.
That's all like too complicated to implement and here ( at least ) in Berlin companies are in huge trouble about the details.
> Article 3 of the GDPR says that if you collect personal data or behavioral information from someone in an EU country, your company is subject to the requirements of the GDPR. Two points of clarification. First, the law only applies if the data subjects, as the GDPR refers to consumers, are in the EU when the data is collected. This makes sense: EU laws apply in the EU. For EU citizens outside the EU when the data is collected, the GDPR would not apply.
It's more complicated than that though. Just Google and you will find some valuable information. https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...
Yes, providing a free website can qualify as "doing business", too, for example if the company running the website uses it to attract potential customers, which arguably is one purpose of Hacker News.
I'm not a lawyer, but it's fairly obvious that web services built in accordance with the jurisdiction of incorporation take precedence, especially when the software/service makes no customization to appeal to the EU. Maybe one runs a blog with content critical of China, but since they're running said blog as a US corp on US soil, China cannot apply it's laws on the said blog.
But when it is, being able to delete comments by emailing the admins and asking for them to be deleted sounds like it would be in compliance with the law.
I don't know any specifics, but I expect they would probably do that for you anyway, before the law, too.
Sort of, kind of.
If you offer no services that will be used by citizens of the EU, you can just carry on.
If the law applies that means a corporation could get into hot water if customers or vendors in the EU don't want or can't trade with them anymore.
The law applies to them in the sense that if they don't follow it, they face negative repercussions. It is not enforceable by the EU directly since they aren't in their jurisdiction.
Application and Enforcement of Law are, atleast IMO, separate things. It's an implication relationship of Enforcement->Application. Application alone does not mean it is enforced but enforcement means it's applied.
Difference being that if the law applies then the EU might want to enforce but lacks the teeth to. They would if they could.
If a company I do business with is subverting my rights (in this case the ability to even remember something), I'll gleefully stop using them.
Astroturf corps are salivating at the possibilities.
In this case choosing another vendor may not be easy (find a GPU that isn't AMD/NVidia/Matrox and that works with most games or find a social network that allows the same reach as facebook or find a video sharing site with the same ad revenue and reach as youtube)
Well, the USA has been doing this to other countries for decades. Your failure to self regulate the protection of the huge volumes of personal data you like to collect plus your governments love to hoover this up has led to this. Deal with it, and be glad that at least someone is legislating this crazy situation we find ourselves in.
Additionally, for emerging Saas companies it would be wise to avoid an EU subsidiary, to lower the cost of GDPR compliance
Please consider not stating things as facts that you havnt bothered to research.