Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

241–250 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#241

Earlier quoted context omitted.

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data” . GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive…

>I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. This sentiment and the hilariously large fines (regardless of company size, even) on relatively-ill-defined requirements make the whole GDPR process feel like it was designed to bully businesses into compliance. Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of c…

>This sentiment and the hilariously large fines (regardless of company size, even) on relatively-ill-defined requirements make the whole GDPR process feel like it was designed to bully businesses into compliance.

>Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of companies, who happen to be providing those users other benefits). It all feels really heavy-handed, though.

The GDPR isn't vastly different to the old Data Protection Directive, which has been in force since 1997. The panic over GDPR suggests that a lot of companies had simply been ignoring the DPD. If a bit of bullying is required to get businesses to obey the law, then so be it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#242

Earlier quoted context omitted.

In a world of limited resources, it makes sense that regulators would pursue enforcement against entities that impact a large number of people.

In such a world, it would make more sense to limit the scope of the law until enforcement can catch up. Minimally enforced laws that are enforced subjectively are problematic regardless of why.

Are you suggesting that the US government suspend income tax while they hire enough people in the IRS to go through every individual's tax return?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#243

Earlier quoted context omitted.

I've heard this line a lot, but even as a government loving liberal it doesn't sound very compelling to me. The law says, comply or face fines up to 4% of global revenue. It doesn't say, "make a best effort to comply, or face fines up to 4% of global revenue." I'm very reluctant to trust people who can fine me for that much money that they won't do so. This is especially the case because it appears to some of us fore…

True that the text doesn’t say this, but several of the privacy authorities in the different jurisdictions in Europe have been stating this publicly in interviews. The last one I saw was the ICO in the UK today on BBC Click saying exactly this...

The text is what matters. You cannot defend yourself in court with the content of interviews.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#244
post #184

Earlier quoted context omitted.

Is what you say actually written into the law, or is it left up to the discretion of the enforcer? Because I'm sure EU companies will be given lots of leeway, but non EU companies will not, and no one wants to be the example.

Fines must be "effective, proportionate and dissuasive", and there are various factors that the authorities must take into consideration. If you feel they _haven't_ taking the relevant factors into account, you can take it to the courts (especially if there is a history of fining non-EU companies more, as that would suggest they are taking irrelevant factors into consideration. https://gdpr-info.eu/art-83-gdpr/

Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible".

So yah, people are right to block the EU first, and figure out the details later.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#245

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#246
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

I’m sorry, but blind trust in the benevolence of regulators in a country you’re not even a citizen of is no way to run a business. I don’t blame US companies unwilling to deal with GDPR uncertainty any more than I blame EU banks unwilling to deal with American customers because of our insane FATCA regulations.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#247
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

So, if that is the real intention of the EU, why they didn't write that in the law instead of threatening everyone with a 20M fine ?

Because for how the law is written now you could in theory get a 20M fine for the smallest violation, and it's obvious that a lot of companies will be scared of that and will simply cut out European users, especially small companies that don't have money to spend in lawyers and other stuff.

The EU should clarify the situation, put limits on fines based on the company size (it's foolish that a person that has a blog that doesn't generate any revenue risks a 20M fine!), and give a transition period (yes, the law was approved 2 years ago, but what did the Europe to inform companies of that law and so permit them to be compliant in time ? Nothing, given the fact that everyone began to know about it some weeks ago)

As an European citizen I'm really concerned about this law, it risks to cut out a lot of internet services, and that is bad, also now I'm scared to even put Google Analytics on my personal website, because well you know a 20M fine is not a good thing, sure it's unlikely to get it, but in theory you can, and I don't want to risk.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#248
post #31

Asked a lawyer: If Instapaper doesn't delete the data from its EU users tomorrow, all the rules of the GDPR might still fall on their head. Most likely, they are then storing EU user data without given consent and have to follow all the requests about data storage, use, deletion and so on. Denying service without data deletion is not an option.

Indeed, it is not service to EU users which is governed by GDPR, it is data processing of data subjects in the EU. Obviously the data processing as defined by the GDPR doesn't stop simply because the service stops since storage is considered processing. Seems to me Instapaper painted a big target on their chest: "We're not compliant, and we're going to give EU users the middle finger in the meanwhile." Whereas, their…

So if someone traveling in the EU gets GDPR protections, does someone traveling in the US lose GDPR protections? Are the GDPR protections only for the data that was collected while someone was in the EU or for all data once they've traveled to the EU once?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#249
post #240

Earlier quoted context omitted.

I think it's pretty easy to argue that such an intent could be described as "stifling innovation", if it's preventing people from trying new things because of the overhead associated with an impact analysis and continued maintenance of e.g. responding to data requests indefinitely.

I agree, we should also get rid of copyright and property laws in the name of not "stifling innovation". It is absolutely ridiculous that I can't just walk into a peoples homes and install my 'adtreckr' eye tracking cameras on their TVs, even though that has the potential to revolutionise the amount of engagement and make sure that they only receive the most engaging, most relevant ads for their tastes./s Less satiri…

I think there's a very specific motivator behind people who build tech with the intent to sell, and that motivator doesn't cover every reason behind other people who build tech. If I want to start a project and think, "cool, if this works out, i'll sell it 6 months from now so it can actually do cool stuff", I'm just not going to work on that project at all.

Honestly though, I would _love_ to live in a world where you could walk into my home and install your 'adtreckr' eye tracking cameras on my TV. What you're describing is "trust", and I think the amount of it that each person has (for people in general, but also for companies) is a big influence in how they view GDPR (and other regulations that some might argue are unnecessary). Obviously, we're very far away from that world, so this isn't consent for you to come waltzing into my home in the near future. :)

In my eyes, the satirical representation of what's happening here (from a consumer's point of view) is me placing an order for your awesome new eye tracking cameras, looking forward to the delivery and installation, and then seeing delays and delays as you repeatedly come back with, "well, are you sure you want this? are you sure I can enter your home? are you sure I can touch your TV? are you sure I can modify your TV?" I signed up, I paid for it, I told you I want it, just do whatever you need to do to give me it.

From a business POV, I already treat user data with utmost regard, and my users know that. Similarly, I trust that the companies I willingly give my data to do the same. There are probably some bad actors in the mix, but I doubt they're going to bother with compliance anyway. Having to go out of my way to prove that data trust is there to a third party completely uninvolved with the contract I have with my users, and to spend hours and hours implementing new workflows and pipelines for out of scope functionality that needs to be maintained indefinitely -- this is not good for a business. It's bad for small businesses because it sucks up time, money, and other resources, and it's bad for big businesses because it opens up such a huge area for litigating non-issues. It might have some value to users, as I said elsewhere, but it's a heavy-handed regulation that is too overreaching in its implementation, in my personal opinion.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#250

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Don't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.

If you believe GDPR requires you to hire a dedicated compliance officer then you don't understand or have not read the law you're so vehemently against.
Post reply on HN