Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

131–140 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#131

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Don't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#132
post #77
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

Running on 'i would be really surprised if', and 'aren't likely to be' aren't really how businesses work.

Isn't it? We're in talks with lawyers right now about some stuff (not GDPR) and they've used both those phrases. We have to assess a risk and do what seems like the best risk/reward assessment, and the lawyers can only give us advice and guidance not 100% solid answers. With GDPR not having a single enforcement action yet I can imagine the guidance there being even more vague.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#133
post #110
post #105

Earlier quoted context omitted.

I don't know if (1) is true but the data was collected under previous laws. In my opinion laws like this should not be retroactive. Retroactive laws, especially when affecting billions of dollars of commerce, are unfair and draconian.

It is not retroactive, the law has been there for 2 years, becoming _active_ in 40 minutes. Secondly, it is not the collection of data, it is the storing of data. So if you store the data without user confirmation in 40 minutes, there might be a problem. The action which is the problem is the storing of private data. There is nothing retroactive here.

Is three year old data covered? Sounds retroactive to me.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#134

Earlier quoted context omitted.

Instapaper is owned by Pinterest. Pinterest is a large high profile company with millions of European users and would be a potential target of regulators looking to establish precedents of enforcement with a big name. I highly doubt this decision was made lightly and was probably informed by actual legal professionals with knowledge of the regulators in question and not the 3rd party opinion of some guy on the intern…

But he's spot on about contacting the regulators because they already know they won't be in compliance. Now would be a good time to do just that, and if the actual legal professionals thought it was a good idea to ban EU citizens but keep their data then maybe they should get better lawyers because that certainly won't work.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#135

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#136

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Don't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.

So which part of the law is ridiculous? Disclaimer: I believe the principles that are applied within the law, data autonomy, data ownership, usage-binding of data etc., are sound. And just because people have aggregated any data on people that they could get to better manipulate them into buying crap for so long that it‘s hard to change track today, doesn‘t mean it‘s wrong for lawmakers to enforce parting ways with the past.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#137
post #105

Earlier quoted context omitted.

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

I don't know if (1) is true but the data was collected under previous laws. In my opinion laws like this should not be retroactive. Retroactive laws, especially when affecting billions of dollars of commerce, are unfair and draconian.

The law doesn't make it illegal to have collected the data in the past. However, it introduces new rights for people for which you have collected data. I don't think this is unfair

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#138
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

Why would a government impose anything other than the maximum?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#139
post #8

Earlier quoted context omitted.

What...data are they collecting? It's a site that pins articles people have saved, the only piece of user data they should hold would be email address and maybe IP address? Simple to put in policies to expire the IP address data after a reasonable amount of time.

We detail the types of information we collect and how we use the data in our privacy policy here: https://www.instapaper.com/privacy

If that's the only info you collect, it would take you way less than two years to get compliant with GDPR.

So there's something you're not telling.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#140

Earlier quoted context omitted.

Instapaper is owned by Pinterest. Pinterest is a large high profile company with millions of European users and would be a potential target of regulators looking to establish precedents of enforcement with a big name. I highly doubt this decision was made lightly and was probably informed by actual legal professionals with knowledge of the regulators in question and not the 3rd party opinion of some guy on the intern…

But he's spot on about contacting the regulators because they already know they won't be in compliance. Now would be a good time to do just that, and if the actual legal professionals thought it was a good idea to ban EU citizens but keep their data then maybe they should get better lawyers because that certainly won't work.

hmmm...

If I had an instapaper account it would be interesting to submit a GDPR request tomorrow, and see what kind of reply I got. Now I don't, but I'm sure there are plenty of other interested people around.

Post reply on HN