HN's privacy policy is freely readable here:
http://www.ycombinator.com/legal/They go out of their way to ensure you need to give them absolutely minimal data - IP communications won't work without IP addresses, and logging them is pretty harmless in my mind. Geolocation for analytics purposes is also fine in my book.
The biggest part of GDPR is to give individual end users control over their personal data and the way it's processed. The easiest way to sidestep GDPR is to not collect this data in the first place.
As a European and as someone involved in my company's GDPR implementation, I am fully in favour of it, it's what 'normal' users have clamoured for. EU laws are quite powerful and can be applied to any member state, equivalent to federal law in the US. This grants a very good standard of basic rights and legal protection, and I am very glad we have it.
Edit: in fact, I view it as a massive cop-out that so many non-EU sites have chosen to block requests from the EU rather than face up to the fact they do not need to collect and process this data for general operation of their sites - I'm looking at you, US news sites. Frankly, that is also fine by me - if visiting such a site requires me to submit to being clinically profiled and categorised for reading a news article, I'll go somewhere else.