Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

161–170 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#161

Earlier quoted context omitted.

Instapaper is owned by Pinterest. Pinterest is a large high profile company with millions of European users and would be a potential target of regulators looking to establish precedents of enforcement with a big name. I highly doubt this decision was made lightly and was probably informed by actual legal professionals with knowledge of the regulators in question and not the 3rd party opinion of some guy on the intern…

> would be a potential target of regulators looking to establish precedents of enforcement with a big name. Shouldn't law apply equally to everyone? One could have thought that setting an example "to show them!" wouldn't have occurred in a civilised country.

Regulators only have so many hours in the day. Prioritizing high visibility infringers can persuade lower visibility infringers to get into compliance.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#162

Earlier quoted context omitted.

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

> will be solidly violating the GDPR come tomorrow how do you know that? i mean technically he says they re violating it today, just like we all did the past 2 years because it wasnt enforceable. what changes with their ban tomorrow?

That they are still violating it tomorrow and they are giving their users an excellent excuse to contact the regulators because they cut off communications. This is about as dumb as it comes.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#163

Earlier quoted context omitted.

Then you'll have all sorts of disputes for example someone could claim their cat stepped on a touchscreen and consented without the user knowledge or someone consented whilst being completely drunk - such consent is not valid. That means potentially companies are keeping the data illegally thinking they comply.

i don't follow, do you mean that's a possible scenario? That's the last thing you need to worry about yet. I expect first random emails from hackers demanding coins for 'not reporting you' in the first awkward month.

There is also a thing when user closes consent popup and the site won't redirect to invalid ip address. I have seen plenty of sites where you can close the consent popup and continue to use the site - that means they collect your data without your consent. Grotesque.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#164

Earlier quoted context omitted.

The law has been in effect for two years. And before that one there was another one.

>The law has been in effect for two years. "It was adopted on 14 April 2016, and after a two-year transition period, becomes enforceable on 25 May 2018." Source: https://en.wikipedia.org/wiki/General_Data_Protection_Regula... >And before that one there was another one. Yes, but that was a different law. It required different things.

The law came into effect on the 14th of April. The 'enforceable' does not mean it comes into a effect, it means that regulators have their powers unlocked to go after offenders.

> Yes, but that was a different law. It required different things.

It actually required a lot of the same things, but because companies decided to ignore it it was revised.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#165

Earlier quoted context omitted.

> would be a potential target of regulators looking to establish precedents of enforcement with a big name. Shouldn't law apply equally to everyone? One could have thought that setting an example "to show them!" wouldn't have occurred in a civilised country.

Regulators only have so many hours in the day. Prioritizing high visibility infringers can persuade lower visibility infringers to get into compliance.

Not sure how they could persuade if they won't go after lower visibility infringers? I can't follow your logic.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#166
post #156
post #99

Earlier quoted context omitted.

Problem is - a shutdown doesn't really make any difference. Dropping the data would make a difference, but just shutting down access could potentially (very unlikely though) mean additional infractions - the customers' requests for data access, corrections, removals etc. still need to be handled, and this could be seen as an attempt to skirt those rights.

I would say that a shutdown essentially freezes the data and prevents it from being used internally, hacked, misused, disseminated, etc. For all intents and purposes, at the moment it doesn't exist. Once they believe they are back in compliance with the law, it will be "unfrozen" and users will be able to retrieve their data or opt-out completely by cancelling their accounts. And who's to say that Instapaper did not…

> And who's to say that Instapaper did not contact the authorities and discuss a plan such as this to mitigate the problem temporarily?

If that's the case, why can't they simply tell this?

I side with the GP: Preventing access doesn't absolve you from complying with the law.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#167

Earlier quoted context omitted.

> will be solidly violating the GDPR come tomorrow how do you know that? i mean technically he says they re violating it today, just like we all did the past 2 years because it wasnt enforceable. what changes with their ban tomorrow?

That they are still violating it tomorrow and they are giving their users an excellent excuse to contact the regulators because they cut off communications. This is about as dumb as it comes.

sounds like a technical reason to me. what provision of gdpr does it break? contact the regulator about what?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#168

Earlier quoted context omitted.

That they are still violating it tomorrow and they are giving their users an excellent excuse to contact the regulators because they cut off communications. This is about as dumb as it comes.

sounds like a technical reason to me. what provision of gdpr does it break? contact the regulator about what?

The ability of users to access their data, to edit their data, to delete their data and to export their data.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#169

Earlier quoted context omitted.

i don't follow, do you mean that's a possible scenario? That's the last thing you need to worry about yet. I expect first random emails from hackers demanding coins for 'not reporting you' in the first awkward month.

There is also a thing when user closes consent popup and the site won't redirect to invalid ip address. I have seen plenty of sites where you can close the consent popup and continue to use the site - that means they collect your data without your consent. Grotesque.

how do you know they collect your data?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#170

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

This is a good point I haven't run into before (which is itself frightening). So what could they do instead? Could they retain the actual 'read later' content, associated with their EU users, but delete all of their own personal data for now?
Post reply on HN