Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>No; tokyodude is asking what happens if you request that (for example) Google erases your data, and he has your email address in his Gmail contacts.

Oh, well in that case this is explicitly handled in recital 18. https://gdpr-info.eu/recitals/no-18/

> Point (b) seems to suggest that it applies by default if the basis for originally processing the data was the subject's consent... but that the controller can override that if they have another legal ground for processing.

Yes.

>So even if the legitimate interests argument above would hold, if you're a 12-year-old, I think you absolutely can demand that your email address be purged from tokyodude's address book and he can't do anything about it?

Yes.

>How about your actual emails to him? Can you demand that Google deletes them from his inbox?

Covered in recital 18.

I totally agree with all your interpretations, well done. See what I mean about it not being that complex?

Not that you shouldn't run all this past your company lawyer to make sure they agree mind you. After all, companies keep lawyers around for input on exactly these kinds of issues, might as well get your moneys worth.

It's ok for you as a software developer to be unsure about some of these things, you're not a trained lawyer. What I'm being condescending about is software developers wailing "oh it's impossibly byzantine, oh it's impenetrable, oh woe, oh drat, oh heavy is the burden of being me in a GDPR-compliant era". Software developers regularly read documentation more complex than the GDPR legislation. Jesus, you'd think it was written in latin the way some people on hacker news cry about it.



I think part of the issue here is that a plain English reading of the GDPR implies such appalling totalitarian overreach that most people find it hard to believe that it can really be what's meant.

I mean, you've just agreed with my reading that the GDPR gives me the power to reach into your personal inbox and censor your records of communications with me. That sort of power for bad actors to carry out historical revisionism on what until now we'd've thought of as someone else's data is unprecedented and - at least to me - a pretty frightening threat to freedom of information and a culture of truth. And meanwhile we've got people running around Hacker News saying "GDPR is all wonderful, it's just common-sense privacy protections, and if your business isn't spying on users without their consent and selling their data you'll be fine".

You're clearly confident that the (to me, somewhat dystopian) interpretations we discussed just above will hold up in court. I'm not, even though they worry me and seem to me to be the most straightforward plain English reading of the bill. That doubt - and associated anger at the failure of the EU to bring greater clarity to these sorts of points before now - seem to me to be reasonable, and not a worthy target for condescension.


>I mean, you've just agreed with my reading that the GDPR gives me the power to reach into your personal inbox and censor your records of communications with me.

That's quite literally the opposite of what recital 18 explicitly says?


recital 18 clearified absolutly nothing for me. My plain reading of recital 18 is that it has to do with personal records stored on paper or my own computers. it in no way covered emails I received from you via Gmail and whether or not you can demand Google delete emails you sent to me from my Gmail account.


That's the opposite of totalitarian, btw, if we're interested in words.


In what way is government-mandated censorship and falsification of history "the opposite of totalitarian"?


In that the government isn’t using people as tools. People are using the government as a tool.

(Edit: without addressing your questionable definition of what it means to control one’s data.)


> I think part of the issue here is that a plain English reading of the GDPR implies such appalling totalitarian overreach that most people find it hard to believe that it can really be what's meant.

Do you think this level of hyperbole is necessary?


In what sense do you think I'm being hyperbolic? I'm pretty sure I mean every word of what I wrote literally.

(Though perhaps "authoritarian" would be a better choice of word than "totalitarian"; I mean it only in the broader sense of "infringing unjustly on individual freedom" and not in the stricter sense of "mandating total subservience to the state" that a Google 'define:' search yields as the first result. I thought it was correct to use "totalitarian" in the former sense, but don't have time to confirm; if I'm wrong, and that word choice is what you take issue with, then I'll concede that it was an erroneous word choice and I should've written "authoritarian" instead.)


> Oh, well in that case this is explicitly handled in recital 18. https://gdpr-info.eu/recitals/no-18/

I disagree. One's GMail contacts is a clear (ha) example of a fuzzy scenario that I think is ... questionably handled by the language at the link you reference. It's difficult especially because it's a weird hybrid of a very personal or household activity that runs inside a commercial activity.

From the text:

> 1 This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity

Ok!

> and thus with no connection to a professional or commercial activity.

...wait, GMail is clearly a professional or commercial product. An online addressbook in GMail... does that count as having a "connection" or not? My purpose of the addresses is personal. But it's clearly connected (at least by tcp, haha) to a commercial activity.

> 2 Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities.

Ok ... wait, social networking clearly involves commercial entities (e.g. twitter). So my personal actions for personal non-business uses of twitter are not regulated. Fine. But twitter itself is?

> 3 However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.

Ok so the regulation applies to the controllers/processors (e.g. GMail, twitter).

So: the regulation does not "apply" to me for my personal use, but my (personally defined for personal use) GMail contacts could get deleted by the other person?

I am definitely not a lawyer, but this does seem at least somewhat contradictory, or at least would benefit greatly from a few more clarifying sentences.

Comparison to complex documentation is not apt to your pro-condescension argument. Complex and vague can be very different.

Documentation can be complex, but if it's rigorous and not vague, I am totally fine with that. Software can be very complex. When it is complex, I would hope the documentation has sufficient detail to cover their intricacies. I'm glad that the postgres documentation is huge and complex -- it has to be.

I do however complain pretty often about vague documentation haha. I feel like it's pretty common for people to complain about an under-documented quirk shooting them in the foot (e.g. mongodb and durability back in the day).

One last thing: If your interpretation is right (and it seems plausible, maybe even likely), then I really need to locally archive my emails and contacts more often haha.


I think your interpretation is correct. In particular, I think that your first two quotes from the text are saying that the "personal or household" user themselves has no obligations under the GDPR. It's coherent to include social networking in here; without that clause, a child writing on Facebook about how another child smells bad would presumably themselves be a data controller and subject to an erasure request, whereas with the clause, Facebook can be compelled by a regulator to remove the post but the child who posted it cannot.

Or at least that's my interpretation. Like you, I remain uncertain and troubled.


>One last thing: If your interpretation is right (and it seems plausible, maybe even likely), then I really need to locally archive my emails and contacts more often haha.

I mean, yeah, you probably should if you care about it. Most office exchange servers are configured to allow some users to "unsend" emails. Outlook dutifully deletes the email from my co-workers inboxes, but my thunderbird client simply tells me that someone sent a recall request and lets me choose what to do with it.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: