GDPR Article 17 expressly requires the removal of things from the global internet
> You're free to not serve your site in the EU
Geoblocking is functionally impossible
GDPR Article 17 expressly requires the removal of things from the global internet
> You're free to not serve your site in the EU
Geoblocking is functionally impossible
And geo blocking may be functionally impossible but the law cares about intent and actions, not if you prevented someone who used a VPN or lied about their location from using your service.
If you say so
And yet still an attempt at extraterritorial overreach. Regardless, I imagine that the rest of us who don't do business in the EU will continue to disregard its very existence. (Except in principle when we write negative comments about it on the internet that don't in practice matter whatsoever, such as this one that you're reading right now.)
I can't recall HN asking/requiring PII from me in any fashion, so I don't see the relevance. If a commenter published some PII about me, then I wonder if HN would remove the comment if I complained to them about it. As I see it, HN isn't acting as a data controller.
Edit: it's covered by HN Privacy policy which is available here: https://www.ycombinator.com/legal/
TLDR: email privacy@ycombinator.com for privacy concerns which should cover removing comments.
In my opinion, that seems compliant with GDPR.
...as part of compliance with GDPR, if you choose to be compliant. Please name one instance of the EU suing and successfully removing an American website from the internet under this article, or any part of the GDPR? Considering we're talking about an actual case of the US seizing the domain of a European website, whataboutting a hypothetical with the GDPR which has never done the reverse despite being in force for 10 years is incredibly disingenuous.
---
Rate-limit edit:
> Are you saying that you don’t think that the GDPR text is written to apply outside of the EU, or that it does say that but it’s not relevant because it’s not viable for anybody to enforce that?
The GDPR is European legislation, written for the territory the EU has legal jurisdiction over. Why would anybody think it's meant to apply outside of the EU? Plenty of businesses choose to operate by two sets of privacy policies, one where they continue fucking over their American users and one where they adhere to the GDPR for European users, and that is perfectly acceptable. There is no "think" about it, the legislation obviously does not apply outside the EU, nor is it intended to.
Because it's clearly worded in such a manner, similar to US financial laws. The key difference is that the EU so far lacks the leverage to throw its weight around outside its own territory to the extent that the US does. (Also presumably politicians won't be willing to burn bridges over PII handling violations to the same extent that they do over financial crimes.)