Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

181–190 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#181

Earlier quoted context omitted.

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

This is a good point I haven't run into before (which is itself frightening). So what could they do instead? Could they retain the actual 'read later' content, associated with their EU users, but delete all of their own personal data for now?

Not much. If you're not compliant, you're not compliant. However, that's not the end of the world right there. GDPR takes ill-intent into account, and it also requires warnings before any punishment is applied. They should instead have started working on compliance before they actually did.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#182

Earlier quoted context omitted.

> And how much revenue does the Instapaper service generate for Pinterest? Who cares? That's not a factor in whether or not you should comply with the law. > Lower profile groups within big companies are probably most likely to shut off their services to European users because they have the cautious legal departments of the large company without the important profit center designation which would make compliance a pr…

> That's not a factor in whether or not you should comply with the law. speaking generally here, you know laws aren't always right? we had plenty bad laws to draw from to challenge this particular point, from racial to abortion laws. gdpr isn't as draconian as these but still has plenty trash in it between the vague wording, the moving target 'state of the art' represents and the weird requirements and absurd implica…

What's that got to do with it?

It's the law, it was created by a democratically elected body. Racial and abortion laws are on a different plane altogether, and are not typically the playground of globally acting corporations.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#183

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Don't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.

If that's the case, then perhaps that startup shouldn't be sucking up all the user data it can.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#184
post #153

Earlier quoted context omitted.

Why would a government impose anything other than the maximum?

Because the regulation is meant to enforce lawful behavior, not make the government richer. If they break out the maximum penalty for a minor violation, it will obviously stifle business and cause economic harm to the EU. But they do need a credible threat to really punish wilful disregard of the law, for companies that profit from breaking the rules. We see how well it works when the fine costs less than the profits…

Is what you say actually written into the law, or is it left up to the discretion of the enforcer?

Because I'm sure EU companies will be given lots of leeway, but non EU companies will not, and no one wants to be the example.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#185
post #62
post #58

Earlier quoted context omitted.

Freezing account if it seems to be owned by EU citizen? GDPR applies to all EU citizens regardless of their location after all.

GDPR applies if (1) the Controller or a Processor is “established” in the EU, or if (2) the Subject is in the EU. Citizenship doesn't matter, and geoblocking is the legally correct solution. As an example: U.S. tourists on a trip to Paris are protected by the GDPR, but a Polish expat in California is not. (See Art. 3 GDPR https://gdpr-info.eu/art-3-gdpr/ )

How is geoblocking a solution? How does it absolve the company of their compliance obligations? Does using a VPN mean that Data Subjects in the EU are not covered by GDPR?

Is geoblocking sufficient on its own to show that the Controller/Processor is not doing business in the EU? Even when the Controller/Processor still provides localization to EU languages?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#186

Earlier quoted context omitted.

Then you'll have all sorts of disputes for example someone could claim their cat stepped on a touchscreen and consented without the user knowledge or someone consented whilst being completely drunk - such consent is not valid. That means potentially companies are keeping the data illegally thinking they comply.

i don't follow, do you mean that's a possible scenario? That's the last thing you need to worry about yet. I expect first random emails from hackers demanding coins for 'not reporting you' in the first awkward month.

the weirdest scenario is if people inadvertently leak medical data on a unsolicited email.

"I've a motor impairment do your hotel have accessible rooms?"

say you have your hosted email system, now you're in a huge mess.

people downvoting this should really hear a lawyer about gdpr.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#187
post #136

Earlier quoted context omitted.

So which part of the law is ridiculous? Disclaimer: I believe the principles that are applied within the law, data autonomy, data ownership, usage-binding of data etc., are sound. And just because people have aggregated any data on people that they could get to better manipulate them into buying crap for so long that it‘s hard to change track today, doesn‘t mean it‘s wrong for lawmakers to enforce parting ways with t…

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

"- IPs are personal private infromation"

IPs combined with other user data could be PII.

"- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically, advertising is optional in EU sites as of today."

Wrong. You need opt-in consent for non personalized ads, but this can be the "soft consent" type where you only present the "Accept" button. Advertising is no more optional tomorrow than it was today.

"- I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc."

Knowing what you have on me is not superfluous; it's my data.

Seriously, the FUD around this law is getting tiresome.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#189

Earlier quoted context omitted.

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data” . GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive…

"Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data”."

Says who? If they weren't doing shady stuff, they wouldn't be pulling out of the EU. The excuses of being complex are just that, excuses.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#190
post #31

Asked a lawyer: If Instapaper doesn't delete the data from its EU users tomorrow, all the rules of the GDPR might still fall on their head. Most likely, they are then storing EU user data without given consent and have to follow all the requests about data storage, use, deletion and so on. Denying service without data deletion is not an option.

do you have to have an account to receive service on instapaper? personal data can be used without the consent if falls under article 6 comma b) or c) as long as the user signed up willingly and the personal data is necessary to erogate the service itself - say you need to store the user email to confirm his identity to avoid fraud associated with using multiple anonymous accounts to work around trial limitations.
Post reply on HN