Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh, it’s simple. Just comply with EU law, and it’s all okay.

That includes:

1. You can not collect anything without explicit opt-in

2. You can not transmit any data to a third party

3. If a user requests it, you have to provide all data stored about them, and have to provide a way for them to delete all of that. (And you have to provide this at least once every 12 months via letter, fax or email for free) (compare §34 BDSG)



I wonder which kind of data it actually applies to though.


All and any.

That includes IP addresses (just connecting to a socket without a user explicitly starting that action), names, emails, hashed IPs, it includes usernames, CC data, messages, interactions with webpages.

Anything that in any way is connected to a person is covered by this.

This directive is also the origin of the cookie disclaimers, which require opt-in before collecting statistics or loading any third party tracking solution.


Does it only require permission if the IP address is being stored?


Read this comment, it cites the relevant laws for Germany: https://news.ycombinator.com/item?id=15072474

But be aware, in May 2018 it all changes as the new EU GDPR comes into force, and that’s a bit more restrictive (and even applies to anyone processing or storing data of EU citizen, no matter where the processing entity is located)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: