Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

91–100 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#91
post #52

Earlier quoted context omitted.

GDPR applies to data processors in the EU or for data subjects in the EU. Citizenship is irrelevant.

It might be not. But those falls into weird space and we will see how things are going to be played out in practice. I still think they have to conform GDPR, especially having prior data on EU users and involvement of parent company.

There are many unclear things in the GDPR, but the relevance of citizenship is not among them: Nothing in the text of the GDPR or any official guidance mentions citizenship or nationality.

The only sources which do mention those are informal and imprecise third-party summaries. But yes, this mistake has been spread widely.

The more precise compliance guides from, say, European law firms don't mention citizenship or nationality either.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#92
post #18
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

'European' - e.g., EU - culture is still quite new in this regard, and plenty of companies have gotten very large fines for gross non compliance of other regulations/directives. Since GDPR compliance is enforced by EU members, many small companies are exposed to (have customers in) most or all EU jurisdictions, and the EU is very heterogeneous when it comes to regulatory enforcement by member states, I think that the…

> plenty of companies have gotten very large fines for gross non compliance of other regulations/directives

Gross, wilful, intentional, deceptive non-compliance. To be honest you have to put quite a lot of effort into managing to get fined for non-compliance with EU regs/dirs.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#93
post #34

Earlier quoted context omitted.

It doesn't. But if you notice you might be doing something illegal, it's a great first step towards compliance to stop doing _more_ of it. Here, Instapaper is likely not misusing user data, but has to catch up on compliance documentation and small details (e.g. signing data processing agreements with services they use, raising the age limit from 13 to 16, …)

Um, no - The GDPR treats the simple act of storing personal data as 'processing', so turning off the service while still keeping the data resolves nothing. It doesn't even matter if you take the data offline, or temporarily obfuscate it.

But what would you be violating exactly? How could those violations be detected? It seems if the EU is so generous in not wanting to fine and you and walking you through the process, then shutting down would look like a reasonable thing to do if you are still attempting to comply.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#95
post #86
post #75

Earlier quoted context omitted.

If you were going to make apps that didn't safeguard the users data, and this law deterred you from doing so, then the law is working as intended.

GDPR could have safeguarded data by demanding more transparency, still allowing apps to accept data as a form of payment through personalized ads. It's not obvious why they are requiring apps to provide the same service for free 'without detriment'. That destroys a number of business models. Why not just allow they give an option to not give their data if they are willing to pay?

> GDPR could have safeguarded data by demanding more transparency

That would be a toothless regulation. It would just cause businesses to add more crap to their privacy policies, which nobody reads anyway, and doesn't impact user behavior.

> It's not obvious why they are requiring apps to provide the same service for free 'without detriment'

So that users can opt-out of having unnecessary data collected. You should only be collecting the data needed to run the service. If your business collapses when users opt-out, your business model was nothing but data harvesting to begin with, and probably doesn't deserve to exist.

> That destroys a number of business models

A number of exploitative business models that harm society and democracy. Works for me!

> Why not just allow they give an option to not give their data if they are willing to pay?

You can do that now. Stop collecting data that isn't necessary to run your service, and charge people money.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#96
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

> Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come. A lot of the responses to the GDPR shutdowns have been like this - "you don't need to shutdown, because you won't be fined yet." But I have to ask, isn't shutting down a better alternative to knowingly breaking the law? W…

> shouldn't following the law be most important?

More or less everyone has given up on following the letter of the law on copyright and has resorted to all sorts of "fair use" ideas that probably wouldn't stand up in court.

Instapaper makes copies of web pages. Does it have permission from the copyright holders for every copy of every web page? No. Are they going to enforce this? Almost certainly not.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#97

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data.

From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate that’s what’s happening. In other words, good faith and best practice will get you far.

Your current reaction seems like a huge and unnecessary over reaction that is just harming your users, and unlikely to have any material impact to your legal risk.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#98

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I'm sorry, I don't buy it.

(1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit.

(2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually.

(3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating the impact of the law or you do not know what you have or you changed strategies internally recently and now you're not going to be ready in time because you started way too late.

So in all, all you've managed to achieve with this action is to get the spotlight on you, and it is a 100% certainty that at least Instapaper will be solidly violating the GDPR come tomorrow.

If I were in your shoes I would use my designated representative to contact the authorities for guidance after explaining in detail what the problem is before I would let my end users pay the price for my own incompetence.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#99
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

> Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come. A lot of the responses to the GDPR shutdowns have been like this - "you don't need to shutdown, because you won't be fined yet." But I have to ask, isn't shutting down a better alternative to knowingly breaking the law? W…

Problem is - a shutdown doesn't really make any difference. Dropping the data would make a difference, but just shutting down access could potentially (very unlikely though) mean additional infractions - the customers' requests for data access, corrections, removals etc. still need to be handled, and this could be seen as an attempt to skirt those rights.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#100
post #95
post #86

Earlier quoted context omitted.

GDPR could have safeguarded data by demanding more transparency, still allowing apps to accept data as a form of payment through personalized ads. It's not obvious why they are requiring apps to provide the same service for free 'without detriment'. That destroys a number of business models. Why not just allow they give an option to not give their data if they are willing to pay?

> GDPR could have safeguarded data by demanding more transparency That would be a toothless regulation. It would just cause businesses to add more crap to their privacy policies, which nobody reads anyway, and doesn't impact user behavior. > It's not obvious why they are requiring apps to provide the same service for free 'without detriment' So that users can opt-out of having unnecessary data collected. You should o…

If they were smart about how transparent a business needed to be, I don't think it would be toothless at all. It would have given users more information about what is happening behind the scenes and allowed them to make their own decisions.

> So that users can opt-out of having unnecessary data collected. You should only be collecting the data needed to run the service. If your business collapses when users opt-out, your business model was nothing but data harvesting to begin with, and probably doesn't deserve to exist.

This is a really rosy view of things. The reality is that there are tons of apps / games / sites that people use and enjoy but would not pay for. And there are people who could not otherwise afford to pay for them but are able to enjoy them because personalized ads can be used as a form of payment. I would argue most of these things make the world a better place not a worse place. And that people should be able to choose how they want to pay for those services.

Post reply on HN