Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

171–180 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#171

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data.

Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data”.

GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive liabilities that most companies outside the EU won’t be willing to take on. While Instapaper likely will eventually relaunch in the EU because of its footprint there, the reality is that EU residents are going to be blocked from a large percentage of the world’s websites. The liability is just too great and the rewards too small for most companies outside the EU. You guys chose to make your traffic radioactive. These are the consequences.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#172

Earlier quoted context omitted.

sounds like a technical reason to me. what provision of gdpr does it break? contact the regulator about what?

The ability of users to access their data, to edit their data, to delete their data and to export their data.

is there a requirement that this ability is 24/7/365?

I mean , knowing GDPR , i would guess at best the provision would be something like "a reasonably long amount of time but not long enough to be unreasonable based on appropriate considerations of data subject's patience"

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#173

Earlier quoted context omitted.

Regulators only have so many hours in the day. Prioritizing high visibility infringers can persuade lower visibility infringers to get into compliance.

Not sure how they could persuade if they won't go after lower visibility infringers? I can't follow your logic.

No one said "they won't go after small timers". Hitting the big players hard makes everyone wary of violating and they will absolutely catch some small fish as well.

It's just silly to expect any enforcement body to go after everyone equally. It doesn't even make sense; company A has data on 1.5B people, company B has data on 27 people and the owner's mother. Why would you go after B before A?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#174

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Let me know if you have any questions...

Which parts of GDPR do you think you're in violation of?

Why do you think removing access for users currently in the EU puts you in the clear legally?

What are you doing with European users data currently, have you deleted it all?

A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy, just by tightening up how they hold data, and making sure they are clear on permissions with users.

Are you sure you have good legal advice on this?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#175

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

Yes, I'm sure their legal team missed that one...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#176

Earlier quoted context omitted.

And how much revenue does the Instapaper service generate for Pinterest? Lower profile groups within big companies are probably most likely to shut off their services to European users because they have the cautious legal departments of the large company without the important profit center designation which would make compliance a priority.

> And how much revenue does the Instapaper service generate for Pinterest? Who cares? That's not a factor in whether or not you should comply with the law. > Lower profile groups within big companies are probably most likely to shut off their services to European users because they have the cautious legal departments of the large company without the important profit center designation which would make compliance a pr…

> That's not a factor in whether or not you should comply with the law.

speaking generally here, you know laws aren't always right? we had plenty bad laws to draw from to challenge this particular point, from racial to abortion laws.

gdpr isn't as draconian as these but still has plenty trash in it between the vague wording, the moving target 'state of the art' represents and the weird requirements and absurd implications of the 'right to be forgotten'.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#177

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#178

Earlier quoted context omitted.

The ability of users to access their data, to edit their data, to delete their data and to export their data.

is there a requirement that this ability is 24/7/365? I mean , knowing GDPR , i would guess at best the provision would be something like "a reasonably long amount of time but not long enough to be unreasonable based on appropriate considerations of data subject's patience"

It certainly isn't a provision in the law that if you feel that you won't be able to deal with your users legitimate requests that you have the option to lock them out entirely.

I can imagine something to the effect of stopping further gathering of data (to stop digging the hole deeper), to give your users the option to request what is their right through some kind of form and to park those requests until you're done with the implementation and in the meantime give them continued access.

After all, the law already has a provision in it that you have 30 days to respond, and another 2 months after that if you are for some reason technically incapable and need an extension.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#179

Earlier quoted context omitted.

Have you received genuine legal advice that recommended that you shut down business instead of continuing to work towards compliance? The agencies that can enforce the GPDR want you to be compliant, not to fine you... If you're actually working towards compliance past evidence shows they won't fine you.

I've heard this line a lot, but even as a government loving liberal it doesn't sound very compelling to me. The law says, comply or face fines up to 4% of global revenue. It doesn't say, "make a best effort to comply, or face fines up to 4% of global revenue." I'm very reluctant to trust people who can fine me for that much money that they won't do so. This is especially the case because it appears to some of us fore…

True that the text doesn’t say this, but several of the privacy authorities in the different jurisdictions in Europe have been stating this publicly in interviews. The last one I saw was the ICO in the UK today on BBC Click saying exactly this...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#180
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

> Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

I find this really ridiculous as well. To run a business, there's lots of rules you have to follow which can result in fines and even jail time if you make mistakes (taxes for example where the rules are complex). If every small transgression for every rule was hit with the maximum penalty, nobody would be able to risk doing anything.

The large GDPR fines to me seem to be aimed at big companies so more than a slap on the wrist can be issued for abusing vast amounts of personal information. I don't think small companies need to be blocking EU users because they're worried they might make a mistake in how they implement their newsletter consent checkbox for example.

Post reply on HN