Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

231–240 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#231
post #77

Earlier quoted context omitted.

Running on 'i would be really surprised if', and 'aren't likely to be' aren't really how businesses work.

Isn't it? We're in talks with lawyers right now about some stuff (not GDPR) and they've used both those phrases. We have to assess a risk and do what seems like the best risk/reward assessment, and the lawyers can only give us advice and guidance not 100% solid answers. With GDPR not having a single enforcement action yet I can imagine the guidance there being even more vague.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#232
post #166
post #156

Earlier quoted context omitted.

I would say that a shutdown essentially freezes the data and prevents it from being used internally, hacked, misused, disseminated, etc. For all intents and purposes, at the moment it doesn't exist. Once they believe they are back in compliance with the law, it will be "unfrozen" and users will be able to retrieve their data or opt-out completely by cancelling their accounts. And who's to say that Instapaper did not…

> And who's to say that Instapaper did not contact the authorities and discuss a plan such as this to mitigate the problem temporarily? If that's the case, why can't they simply tell this? I side with the GP: Preventing access doesn't absolve you from complying with the law.

Does GDPR make it illegal to shut a site down for a period of time? While they are shut down, what could be noticeable that they are not complying with?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#233
post #115
post #93

Earlier quoted context omitted.

But what would you be violating exactly? How could those violations be detected? It seems if the EU is so generous in not wanting to fine and you and walking you through the process, then shutting down would look like a reasonable thing to do if you are still attempting to comply.

>How could those violations be detected? You can tip off the regulators if you believe that there is a violation and they will then investigate it. Instapaper is giving a pretty good reason to be suspicious.

What would be in violation exactly? Not clear on this. How would regulators investigate? Do they require full access to your database/ backend?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#234
post #77

Earlier quoted context omitted.

Running on 'i would be really surprised if', and 'aren't likely to be' aren't really how businesses work.

Risk management is part of every decision a business faces, legal or compliance risks aren't any different. Can we risk the CEO and chairman travelling on the same airplane? Can we risk having our disaster recovery site in the same city as our main? Same country? Same continent? Can we risk buying all this trends-sensitive inventory? Etc. (Potential savings or revenue) - (Somewhat easy to calculate cost) * (Difficult…

That's not what I was referring to at all. I mean that the sentiment of 'probably'/'likely' from a random stranger online, to a business which might have EU users but never interacted with EU regulators doesn't mean much.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#235

Earlier quoted context omitted.

No one said "they won't go after small timers". Hitting the big players hard makes everyone wary of violating and they will absolutely catch some small fish as well. It's just silly to expect any enforcement body to go after everyone equally. It doesn't even make sense; company A has data on 1.5B people, company B has data on 27 people and the owner's mother. Why would you go after B before A?

They have said this. a) they have said they don't want to punish companies for the sake of it, they want to use it as an incentive to fundamentally change the approach to the handling of user data. This means not suing tiny companies for more money than they are worth. b) they have said that the standards will roughly increase with the size of the company and resources it has. A company with 27 users (and few employe…

I think everyone is talking about the UK 's ICO, which is just 1 of the 28. We have heard nothing from others and its best not to make assumptions - the ICO may be following different rules in a year.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#236
post #184
post #153

Earlier quoted context omitted.

Because the regulation is meant to enforce lawful behavior, not make the government richer. If they break out the maximum penalty for a minor violation, it will obviously stifle business and cause economic harm to the EU. But they do need a credible threat to really punish wilful disregard of the law, for companies that profit from breaking the rules. We see how well it works when the fine costs less than the profits…

Is what you say actually written into the law, or is it left up to the discretion of the enforcer? Because I'm sure EU companies will be given lots of leeway, but non EU companies will not, and no one wants to be the example.

Fines must be "effective, proportionate and dissuasive", and there are various factors that the authorities must take into consideration. If you feel they _haven't_ taking the relevant factors into account, you can take it to the courts (especially if there is a history of fining non-EU companies more, as that would suggest they are taking irrelevant factors into consideration.

https://gdpr-info.eu/art-83-gdpr/

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#237

Earlier quoted context omitted.

A significant proportion of the 500 million citizens of the EU are "privacy oriented". If you can't keep our data safe, why should you be trusted with it?

My point is, I have no clue what's collecting data in an improper way, and I'm not going to hire a lawyer for a hobby app. The amount of conflicting information about whether I do or don't need consent based on what services I use is just stupid. And I wouldn't even be showing ads. Part of the apps function is related to location, do I need consent? Maybe. It will use Firebase, do I need consent? Maybe. It will colle…

Welcome to the real world. If your little hobby project leaks the personal information of a real person, then they don't care how much of an unimportant side project it was to you.

For purely personal use "hey guys, this is just a hobby use at your own risk" you won't get hit with gdpr

Imagine if you were building cars for a hobby then selling them. Would you complain about all of those onerous regulations like seatbelts, crunch zones etc when all zou really want to do is tinker with some cool engine tech?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#238
post #105

Earlier quoted context omitted.

I don't know if (1) is true but the data was collected under previous laws. In my opinion laws like this should not be retroactive. Retroactive laws, especially when affecting billions of dollars of commerce, are unfair and draconian.

The law has been on the books for two years, it just wasn't enforced and for a long time before that there was another law with much the same effect. So even if the data was collected under previous laws there is not much that would convince me that denying the users access to their data or to the legally mandated data life-cycle features is the right thing to do. In fact that attitude goes exactly against what the l…

> In fact that attitude goes exactly against what the law is trying to achieve in the first place.

I think this is an important realization for any regulator.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#239

Earlier quoted context omitted.

We detail the types of information we collect and how we use the data in our privacy policy here: https://www.instapaper.com/privacy

If that's the only info you collect, it would take you way less than two years to get compliant with GDPR. So there's something you're not telling.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#240
post #75

Earlier quoted context omitted.

If you were going to make apps that didn't safeguard the users data, and this law deterred you from doing so, then the law is working as intended.

I think it's pretty easy to argue that such an intent could be described as "stifling innovation", if it's preventing people from trying new things because of the overhead associated with an impact analysis and continued maintenance of e.g. responding to data requests indefinitely.

I agree, we should also get rid of copyright and property laws in the name of not "stifling innovation". It is absolutely ridiculous that I can't just walk into a peoples homes and install my 'adtreckr' eye tracking cameras on their TVs, even though that has the potential to revolutionise the amount of engagement and make sure that they only receive the most engaging, most relevant ads for their tastes./s

Less satirically, you are free to innovate by coming up with new tech, then selling to people who care enough to deal with regulations. The 'stifling innovation' copout is so utterly overused by people who want to ignore negative externalities like pollution or the surveillance state we are building up. I am starting to think of it as a type of rent seeking: "I am currently in the privileged situation of having the technology and network effect necessary to exploit this unguarded treasure of X without dealing with the fallout. Please don't pass any regulation requiring me to actually pay my dues"

Post reply on HN