Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

EU data protection does, but only if the notes are computerized.


I used to be the IT Director for a document scanning business in the UK.

Scanning paper HR records was the single most painful job we had to do. The entire file became a complete legal nightmare purely because it stopped being paper and became covered by Data Protection.

Usually the HR department had to go through every single employee file and shred any documents that might be grounds for legal action before they got scanned.

The process before scanning was: - employee is annoyed - employee requests their HR file - HR sanitise file and sends it to employee

after scanning, every single page was indexed. So they couldn't react to a request by destroying pages (because there'd be holes in the index). So they had to sanitise every single file before scanning.

I understand the point of Data Protection law, but in this case it was really counter-productive. Evidence was destroyed wholesale.


That sounds like "working as intended" - after all, if instead of just requesting their file the employee had initiated legal action against you, it would have been illegal to destroy those documents. And it also raises the question of which part of your HR process is generating incriminating documents in the first place?


not so much "incriminating" as "not required to be kept and could possibly be misconstrued".

Not our HR process, our customer's. What was actually destroyed depended on their interpretation of the law.

One common one was the Data Protection requirement to not keep inaccurate data meant that all but the latest employee change of address forms had to be destroyed. Easy to implement post-scanning, pain in the arse to do pre-scanning.


Why would that be so? It's not the candidate's personal information...


If you store I formation about me, it is by definition my information. It may be your thoughts but if there is a link to me, I should get to see it.

Think multi device ad retargeting. How cool would it be to get back information on what the ad exchange thinks I am like...


Wow. No. My thoughts are none of your business.


It's not thoughts, it only applies to data stored in a computer.


Thank you. I guess I didn't articulate it well enough for the grand parent comment here. I guess we could make an exception for personal AND non-commercial diaries but if you make business decisions that affect me based on information you store about me, then I should have a right to see them.

I'm also thinking about the rights of everyone including criminal (including terror) suspects to see (I am specifically not asking permission to alter or delete, that's another conversation) all the information the government (and their agents in the private sector) stores about them.

I know it sounds onerous specially because of the issue of authentication (how does the CIA know that it is me who is asking for information about me and not someone impersonating me?) and I don't have a good solution for these questions.


This is a ridiculous idea to me. If I run a business, my internal evaluations of candidates and employees are no one's business but my own. They are my observations about the world, with the productive end of hiring better employees. Whether my decisions affect you or not is really not relevant; we make free decisions that affect other people all the time. I take issue with any claim that people have legally-binding private obligations to each other beyond abiding by contracts, and refraining from violence and fraud.


OK, what about a compromise: you can keep your conclusions private, you only need to disclose to me the raw data you used to reach such conclusions. Is that better?


Let's do some reductio ad absurdum here:

"We're not banning thoughts, just those that are inside books."




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: