Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

81–90 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#81

Earlier quoted context omitted.

The email we sent to EU users (quoted in linked article) has the important details regarding the service interruption in the EU. Additionally, I can say that our privacy policy is concise, clear, and accurate with respect to the types of information we collect and how the data is used: https://www.instapaper.com/privacy If you have other specific questions, I will do my best to answer them.

Well, as The Verge says in the article: 'While we don’t know exactly what’s holding up Instapaper' I'm naturally curious as to what's holding up Instapaper. As you say, your Privacy Policy is very good, other than the disclaimer that says 'we may pass your personal data to others - who knows what they do with it eh?'. I imagine that this is the issue which is holding you up.

The GDPR fines based on global revenues.

I'd bet Pinterest is very risk averse given how little money they make from Instapaper.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#82
post #34

How does shutting down fix GDPR issues? Does all user data magically disappear by shutting down?

It doesn't. But if you notice you might be doing something illegal, it's a great first step towards compliance to stop doing _more_ of it. Here, Instapaper is likely not misusing user data, but has to catch up on compliance documentation and small details (e.g. signing data processing agreements with services they use, raising the age limit from 13 to 16, …)

Um, no - The GDPR treats the simple act of storing personal data as 'processing', so turning off the service while still keeping the data resolves nothing. It doesn't even matter if you take the data offline, or temporarily obfuscate it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#83
that’s causing companies trouble because it’s not entirely clear right now what information residents will request, what format that information needs to be in, how to locate it and package it, and whether new infrastructure needs to be created to manage this request pipeline. Personal info is a somewhat nebulous concept, and the fact that experts are describing the GDPR as “staggeringly complex” is not making it easy to cover all the bases. (Granted, companies have had two years to prepare for this.)

That is bollocks. The most stupid excuse I have ever read.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#84
post #39

What are good alternatives to Instapaper? There is Pocket, any other recomendation? Maybe it is also time for somebody to create new app as tiny side apps owned by corporations seems to be sunseted sooner or later.

There's Wallabag [1], which you can host your own instance of.

I'm the creator of BeeLine Reader [2], which has a reading list feature. The app is free to download and if you want to use it as a reading list app that's totally free. There are some IAPs that hook into Kindle or provide other functionalities, but they're unnecessary if you just want a read-later app.

1: https://wallabag.org/en

2: https://itunes.apple.com/us/app/beeline-reader/id938026867?m...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#85
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

> What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. Can you point to the section of the legislation that says this? It would probably go a long way to stopping folks from freaking out.

There is none.

BTW: our privacy counsel, at a very good law firm, rates France as amongst the most aggressive of the regulators, given to assessing large fines.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#86
post #75

I'm still struggling with the fact that the EU can compel me to add what will be a funnel shattering dialog to my onboarding. I've shelved a bunch of side projects that I was excited to work on because I have no interest in dealing with any of this ambiguous law. Implementing it would most likely cause a large percentage of users to uninstall my app, because who wants to be greeted with a scary sounding dialog as the…

If you were going to make apps that didn't safeguard the users data, and this law deterred you from doing so, then the law is working as intended.

GDPR could have safeguarded data by demanding more transparency, still allowing apps to accept data as a form of payment through personalized ads. It's not obvious why they are requiring apps to provide the same service for free 'without detriment'. That destroys a number of business models. Why not just allow they give an option to not give their data if they are willing to pay?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#87

Earlier quoted context omitted.

> it’s not entirely clear right now what information residents will request, If they ask for something specific in an informal way, that can be provided But from the GDPRs data portability point of view, it's everything that's linked to the account. Export your Facebook data for a good example of this. HN example: it would be the information in your profile, the links/text you submitted (but not the content of the li…

From the HN example, does this include other comments that referenced my username? What about comments that might have linked to my GitHub profile? What if there are server logs that include my IP and a time which can correlate to when I posted a comment or something? What about this information on Algolia, must I contact them separately? Also, I wasn't aware...I can ask for my password hash? Can I request all of thi…

Starting from the end

> Can I request all of this information be deleted?

Yes, the ones that are on HN. I'm not sure how it works for 3rd parties that obtain your data

> does this include other comments that referenced my username?

I don't think so, this is unlikely, especially as you didn't create it and HN doesn't link this (as opposed to reddit)

> What about comments that might have linked to my GitHub profile?

I'd say that being required is even less likely as HN has no way of knowing what's your GH profile

GDPR is what they know about you. If they're actively trying to link pasted GH profiles and usernames then this would apply, otherwise no.

> What if there are server logs that include my IP and a time which can correlate to when I posted a comment or something?

That thing with IPs being PII I'd say this would apply, but then again, this doesn't bring any new information.

So if they keep track of users access times then yes, but if this information is rotated, sent to /dev/null then no.

You're not obligated to connect all the dots, or track user login times. That being said, IP (especially + times) are PII so better anonymize it and discard once not needed.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#90
post #66

Earlier quoted context omitted.

Huh. This is interesting. People were talking it'd be the other way. That EU citizens would be guarded no matter where they're.

I'm sure that's what the policy makers originally wanted (protecting the rights of all EU citizens). That being said, it would be nigh-on-impossible to implement.

Websites would run into the same situation as banks: anytime you open an account at most banks in Europe and probably around the world, they specifically make sure that you're not American, because then they have to comply with American laws if they don't want to get blacklisted.
Post reply on HN