Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

151–160 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#151

Earlier quoted context omitted.

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

Then you'll have all sorts of disputes for example someone could claim their cat stepped on a touchscreen and consented without the user knowledge or someone consented whilst being completely drunk - such consent is not valid. That means potentially companies are keeping the data illegally thinking they comply.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#152

Earlier quoted context omitted.

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

Then you'll have all sorts of disputes for example someone could claim their cat stepped on a touchscreen and consented without the user knowledge or someone consented whilst being completely drunk - such consent is not valid. That means potentially companies are keeping the data illegally thinking they comply.

i don't follow, do you mean that's a possible scenario? That's the last thing you need to worry about yet. I expect first random emails from hackers demanding coins for 'not reporting you' in the first awkward month.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#153
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

Why would a government impose anything other than the maximum?

Because the regulation is meant to enforce lawful behavior, not make the government richer. If they break out the maximum penalty for a minor violation, it will obviously stifle business and cause economic harm to the EU.

But they do need a credible threat to really punish wilful disregard of the law, for companies that profit from breaking the rules. We see how well it works when the fine costs less than the profits from breaking the rules. The EU is making sure that this will not be the case for the GDPR.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#154
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

Why would a government impose anything other than the maximum?

Why doesn’t petty theft carry the death penalty? Penalties for any crime must be, in a democracy, be reasonable to the general population (which of course contains a lot of people who both are data subjects and data controllers via owning smaller and larger businesses) - otherwise the legislative body will be voted out, laws changed, etc. Equilibrium. Yes, EU laws might have more red tape around them, but we still vote for our representatives.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#155
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

It is not the same in all the countries - for example in Poland the goal is to get you to pay fine and if you go bankrupt then civil servants get special points. There is a culture of hatred towards private businesses coming back from the communist times.

Second, you don't know that - bored civil servants eager to hit targets and get bonuses for scoring big fines could have gone for a low hanging fruit that is small companies without legal teams scared and paying instantly.

Third, as its current state GDPR doesn't feel like ready "for production", so why would companies want to implement something with so many unknowns?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#156
post #99

Earlier quoted context omitted.

> Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come. A lot of the responses to the GDPR shutdowns have been like this - "you don't need to shutdown, because you won't be fined yet." But I have to ask, isn't shutting down a better alternative to knowingly breaking the law? W…

Problem is - a shutdown doesn't really make any difference. Dropping the data would make a difference, but just shutting down access could potentially (very unlikely though) mean additional infractions - the customers' requests for data access, corrections, removals etc. still need to be handled, and this could be seen as an attempt to skirt those rights.

I would say that a shutdown essentially freezes the data and prevents it from being used internally, hacked, misused, disseminated, etc. For all intents and purposes, at the moment it doesn't exist. Once they believe they are back in compliance with the law, it will be "unfrozen" and users will be able to retrieve their data or opt-out completely by cancelling their accounts.

And who's to say that Instapaper did not contact the authorities and discuss a plan such as this to mitigate the problem temporarily?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#157
post #110

Earlier quoted context omitted.

It is not retroactive, the law has been there for 2 years, becoming _active_ in 40 minutes. Secondly, it is not the collection of data, it is the storing of data. So if you store the data without user confirmation in 40 minutes, there might be a problem. The action which is the problem is the storing of private data. There is nothing retroactive here.

Is three year old data covered? Sounds retroactive to me.

Yes, three year old data was already covered by the DPD.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#158
post #19

Earlier quoted context omitted.

Weirdly enough I am an European citizen, haven't received the mail and the service is working. Not complaining, I prefer it this way. Hope you will sort the issues quickly.

Me too. And I can see I am definitely subscribed to "account update" emails. I'm not sure how they would decide if I was European or not, can't see a tick box for that in the profile page.

Where are you located?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#159

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

> will be solidly violating the GDPR come tomorrow

how do you know that? i mean technically he says they re violating it today, just like we all did the past 2 years because it wasnt enforceable. what changes with their ban tomorrow?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#160

Earlier quoted context omitted.

The general global legal principal here is that you can't charge someone for something that happened before the law came into effect. So you are not correct on #1.

The law has been in effect for two years. And before that one there was another one.

>The law has been in effect for two years.

"It was adopted on 14 April 2016, and after a two-year transition period, becomes enforceable on 25 May 2018."

Source: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

>And before that one there was another one.

Yes, but that was a different law. It required different things.

Post reply on HN