HN user

chasb

803 karma

Hi, my name is Chas Ballew. I'm one of the co-founders of Aptible (YC S14). We spun Conveyor out of Aptible in 2021, now I work on that.

I know security, privacy, and software development. If you have questions related to those concepts, or HIPAA, SOC 2, ISO 27001, GDPR, HITRUST, or other frameworks, please feel free to email me at chas@conveyor.com.

Posts11
Comments135
View on HN

Premise: > In North America (perhaps elsewhere) you are required to have at least a Master's degree to practise Psychology and you should have a doctorate if you want any mobility with your practise.

Conclusion: > This leads people who have no interest in academia having to find a way to convince people they've discovered something new and novel so that they can go apply what has already been discovered.

I'm not rejecting the premise, I'm saying the conclusion is not supported by this article. None of the figures mentioned in the article (Daryl Bem, John Bargh, Susan Fiske, Brian Wansink, Amy Cuddy, Simine Vazire, etc) are clinical psychologists. None of the research described in the article is clinical psychology, or even appears to have been performed for clinical psychology.

Maybe clinical psychology has a replication crisis, I don't know, but there is no evidence here for the idea that clinical psychology degree candidates are causing the replication crisis in social psychology.

(Just a heads up "Ask HN" generally refers to asking the community, not YC itself. I don't think the YC legal team reads this.)

I'm a lawyer, YC alum, and have a CIPP/E cert. I took a crack at the "Does GDPR apply to HN?" question here: https://news.ycombinator.com/item?id=16615351

The answer is "probably not" because HN is neither established in the EU nor do they target the EU specifically. Maybe there are facts I don't know, but YC itself is also probably out of scope (read more here: https://gdpr-info.eu/art-3-gdpr/)

I'm also CEO of Aptible. We make a SaaS platform (Gridiron) that a bunch of YC companies are using for GDPR prep.

It really depend on your reasons for retaining the backups in the first place.

GDPR forces you to be able to articulate why you collect or process regulated personal data.

If you provide a service that collects or processes data for fair and transparent purposes, you'll be ok.

Under Article 17, the right of erasure, you're only obligated to delete upon request of the data subject, and only in certain circumstances, the most common being:

- If the data are no longer necessary for the purposes for which they were collected

- If the legal basis for the processing was based solely on consent and no other legal basis exists

- If the processing was based on the balancing test of your "legitimate interests" outweighing the data subject's interests or fundamental rights and freedoms (such as for security or availability), the data subject objects, and your interests don't override theirs

- If you are processing for direct marketing and the data subjects at all

If you're a SaaS provider and they are necessary to meet your availability commitments to your customers, and you can document that necessity, then you're probably going to be able to retain them even if the data subject objects. Data subjects rights are not absolute.

If you're retaining the data for marketing, or based on consent alone, you're going to have to delete them or have a very good excuse for not doing so. If you don't have a great reason, you should probably delete them anyways, or better yet avoid collecting the data in the first place ('data minimization,' Article 5(1)(c)).

Not in your personal capacity, no. As mentioned in the other comments to this parent, HIPAA only applies to "covered entities" like doctors that take insurance and insurance companies, and their "business associates" that process PHI on their behalf.

HN probably doesn't fall within the material scope of GDPR, unless they perform business activity that falls within the scope of EU law that I'm not aware of.

That would be different if they marketed/promoted/sold in the EU, offered European language or currency support, or somehow otherwise took action to position themselves for the EU.

As a thought experiment, if HN was regulated by GDPR:

1. Yes, all kinds of user generated content can contain GDPR Art. 9's special categories of personal data. HN would probably rely on the exemption in Art. 9(2)(e), which permits processing "personal data which are manifestly made public by the data subject." The purpose of HN is to let you share your own data on the Internet, that's the entire point. That's fine under GDPR.

2. HN would still need a lawful basis for processing under Art. 6. For a paid service, a Terms of Service would normally be fine. I don't think HN has or wants one of those, and they don't track users at all before registration, so they could collect an explicit consent from users on registration. If they did track prior, a cookie popup could collect the consent. Also, under Art. 8, the default minimum age of consent is 16, so we'd want to consider age confirmation too.

3. Archiving posts on the Internet forever is not a problem, if that's the intended use of the site, which it is. My guess is that deleting a user and their posts is feasible at the application/database layer. The problem would be deleting personal data from backups of the site if the user withdraws their consent and requests Art. 17 erasure. In that case, only retaining the backups as long as necessary and documenting that justification internally is probably sufficient.

4. Article 22 restricts "automated processing, including profiling, which produces legal effects concerning [the data subject] or similarly significantly affects" the data subject. Ranking, voting, and anti-spam probably don't qualify as weighty enough subjects to be restricted. Recital 71 ("Profiling" https://gdpr-info.eu/recitals/no-71/) sheds some light on what the EU is trying to prevent.

5. They'd have to get a data protection agreement or other Art. 46 agreement with hosting vendors. Cloudflare is on top of this: https://www.cloudflare.com/gdpr/introduction/ Not sure what other subprocessors are involved.

6. Being able to see most of your own data on HN means you have Art. 15 access, which is nice. I think they'd have to also give you any hidden metadata as well. Not sure what that might be (vote weight score?).

6. There's a bunch of other stuff they'd probably do, like appoint a data protection officer, publish a privacy policy, add the ability to delete your account, etc.

GDPR puts the burden on the company to comply if it processes any in-scope personal data, regardless of whether it's possible for the data subjects themselves to minimize that data.

I'm a lawyer but not your lawyer and I have no idea about specific YC or HN details, so take this with a grain of salt, but I think the best argument for why HN is exempt or at very low risk for enforcement is that it does not hold itself out into the EU market for business and is not otherwise subject to EU law(as far as I know, and I have no special knowledge). Users may be from the EU, but HN has no particular nexus to EU law that I'm aware of.

This is important because Article 2 of GDPR ("Material scope") expressly says "This Regulation does not apply to the processing of personal data ... in the course of an activity which falls outside the scope of Union law"

There are a lot of businesses that market and sell in the EU, or that recruit or hire contractors in the EU. GDPR affects not only your CRM, but your marketing and sales stack, your HR stack, and any other part of your business that might touch personal data.

With a good system of record, you can track and manage all of the rest of the information and issues raised in the letter.

That said, in a large company with a lot of legacy systems, it may be tough to extract the actual data itself (or even know if your system of record is complete).

GDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/

The right can only be enforced against a "controller," which is the entity that "determines the purposes and means of the processing of personal data."

It's worth noting that GDPR does not give the data subject the right to request everything in the letter. Only a more limited set of things.

The practical effect for SaaS companies is that they should keep track of data and the systems and services where data is processed. With good preparation and a system of record for security/privacy management data, you can prepare for this kind of request very well. My company does just that - helps others prepare.

(OP) I help run a Rock Health portfolio company and sometimes feel divorced from the outcomes we help enable. I thought this was a great project to show how technology helps real people.

GDPR has a lot of parallels to HIPAA and SOC 2. Many developers here have worked with companies subject to HIPAA, or that do SOC 2 reporting.

One big difference is that the material scope of GDPR is so extremely broad: it regulates any PII that can be touched by EU law. That's important because it means that all of your SaaS vendors that touch this data may be in scope, not just your hosting stack. If you're marketing or selling in the EU, your entire growth/CRM/customer success stack will be regulated. If you have EU employees or contractors, all of their HR data is covered. I'm not sure if most companies realize this. It may be less of a problem for B2B, we'll see.

Questions to ask yourself: What is the scope of GDPR personal data across your business? Are you marketing in Europe? Are you selling into Europe? What business processes touch that data?

Aptible | Remote | Multiple technical and non-technical roles for those interested in Internet security

https://www.aptible.com/company/

Aptible makes people-centered security products that help SaaS developer teams build security into their architecture and their organization's culture.

* Enclave is a container orchestration platform built for developers that automates security best practices and controls needed for deploying and scaling Dockerized apps in regulated industries.

* Gridiron is like the missing QuickBooks for security management. It helps developers design and run security management programs that meet and exceed requirements like HIPAA, SOC 2, and ISO 27001. Customers use it to build trust with their own customers and partners, and prepare for certifications.

Important skills we are looking for include: EmberJS, DevOps/Site Reliability, Security & Compliance (HIPAA, HITRUST, ISO 27001, SOC 2, PCI-DSS, GDPR, etc.) expertise, SaaS Operations/Generalists, and more.

We would love to talk with anyone who is interested in Internet security and has one or more of the competencies listed above. Specific roles that we are looking for today:

1. Senior Site Reliability Engineer

2. Senior Software Engineer

3. Support Engineer

4. Director of Operations

5. Web Security Evangelist (think, write, and evangelize security best practices and compliance know how for developers)

6. Security, Compliance, and DevOps Analyst (translate security best practices and compliance requirements into features and content that helps our customers to successfully secure their data)

Reasons to work at Aptible:

* Small team, (relatively) large customer base filled with innovators in challenging industries (namely healthtech and fintech) * Fully remote

* Our products have dramatic impact on important aspects of our customer's business (specifically: the safety and security of their customers' data)

Aptible (YC S14) | Senior Software Engineers, Site Reliability Engineers, and Support Engineers | Remote

At Aptible, we make people-centered security products that help developer teams build security into their architecture and their organization’s culture:

Enclave is a container orchestration platform built for developers that automates security best practices and controls needed for deploying and scaling Dockerized apps in regulated industries.

Gridiron is like the missing QuickBooks for security management. It helps developers design and run security management programs that meet and exceed requirements like HIPAA, SOC 2, and ISO 27001. Customers use it to build trust with their own customers and partners, and prepare for certifications.

Learn more at https://www.aptible.com/company/

For teams that use a DevOps model, fast, predictable deploys that can be safely rolled back are important for security, for this reason.

If deploys are like playing Jenga on a sailboat, you're not going to be able to patch fast or safely.

That said, even becoming aware a CVE exists in the first place is still a problem for many teams. There are plenty of good options, it's just underinvested in early on.

Possibly, but here StubHub would have to explain why they displayed it as unsold with a delay, and why the FTC should not consider that deceptive.

If the ticket was already sold, why the delay? A reasonable consumer think that specific ticket had just been sold at that moment, which sounds like a material misrepresentation.