Ask HN: Is Hacker News GDPR Compliant?
- While most users use pseudonyms, there are some users who do not, and most users (hypothesis from my side here) use their actual email address, and not a throw away email address or an email address exclusively created for HN.
- Hacker News has an API, though they (obviously) do not disclose the email addresses of any of its users in the API, they do however include HN usernames which alongwith the public posts also available in the API are attributable to given users, and therefore is indirectly personal information.
- Hacker News doesn’t support the deletion of comments and posts after a certain 24-48 hour period. Upon research I’ve learnt that one can contact PG or the HN News mods to have your content deleted on the platform, however this delete wouldn’t be enforceable on API consumers of HN, who may have a cache or a permanent archive of the data in any location (analogous to how FB is getting Cambridge Analytica to delete any of the user data which CA still has).
- HN’s severs with all user data is (I believe) located in California. Data residency in the EU doesn’t seem the case. Even if the case is made that all HN user information is in public forum, personal data such as users’ email addresses and favorites are private information stored on HN.
- Finally, the point about consequences. All the above points would seem null if HN really doesn’t have any revenue for it to be charged the 2-4% of global revenue as penalty for violating GDPR. However to this point I would like to issue a reminder that Hacker News is by all legal matters owned by Y Combinator (also on the company domain name *.ycombinator.com), and YC sure does rake in the revenue. Would HN legally be argued as some sort of a free non-profit forum, and thus not connected to YC for any GDPR violation? Currently YC companies have their hiring posts artificially promoted on HN’s front page, so there’s that thorn.