Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

271–280 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#271
post #256
post #244

Earlier quoted context omitted.

Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". So yah, people are right to block the EU first, and figure out the details later.

> Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". No they absolutely do not.

Really? "effective" = large amount, so company won't do it again, "proportionate" = relative to revenue, "dissuasive" = make them an example so no one else will dare.

I bet you are going to tell me proportionate somehow makes it all better, but for companies that make money this way, the amount of money they make this way in proportion to their income is basically all of it.

So you can bet regulators will go for the full amount.

No company in their right mind is going to rely on the mercy of an EU court toward a non-EU company.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#272

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Let me know if you have any questions... Which parts of GDPR do you think you're in violation of? Why do you think removing access for users currently in the EU puts you in the clear legally? What are you doing with European users data currently, have you deleted it all? A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy, just by tightening up…

Which parts of GDPR do you think you're in violation of?

Answering those questions in a public forum would be extremely foolish. ("Do you know why I pulled you over?")

A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy

And how many of them are actually in compliance?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#273
post #269

Earlier quoted context omitted.

You don't ignore a law for 2 years and then just after it comes into force say "at least we're working on it". Honestly I thought the GDPR was a bit of an over reaction when it came out 2 years ago but seeing how little respect companies have for our data over the last few weeks I've been convinced it was necessary.

As an engineer, with as much else is going on on a day to day basis it's not surprising. A lot of the vagueness around the GDPR still hasn't been resolved, nobody wanted to get a head start just to be told "oops, we actually meant this" and have wasted countless engineering/lawyer hours as a result.

You would only take that liberty if you didn't have much respect for the law and its ability to touch you. I suspect companies are a lot more careful with each years new IRS rules even though they don't yet have case law and are often issued on much shorter notice.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#274
post #269

Earlier quoted context omitted.

As an engineer, with as much else is going on on a day to day basis it's not surprising. A lot of the vagueness around the GDPR still hasn't been resolved, nobody wanted to get a head start just to be told "oops, we actually meant this" and have wasted countless engineering/lawyer hours as a result.

You would only take that liberty if you didn't have much respect for the law and its ability to touch you. I suspect companies are a lot more careful with each years new IRS rules even though they don't yet have case law and are often issued on much shorter notice.

Companies directly lobby the laws that affect the IRS on a year-to-year basis and have a lot more knowledge about it. It is hardly as vague as this was. I very much do respect the laws when I can, but I'm a US citizen, and my projects don't make enough money for me to ultimately care about the GDPR/EU. I just blocked them for .. ever, probably. You're really targeting people here, sorry I disagree?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#275

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

based on my understanding, i think if you're not marketing to eu visitors, data doesn't fall under the gdpr. does the gdpr retroactively apply to data from the past?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#276

Earlier quoted context omitted.

> Let me know if you have any questions... It sounds as if you're unwilling to talk about the issues that you're facing. So what can you say? The only reason I can think of that you can't say is that are trying to get some infrastructure suppliers to be compliant and those talks are confidential. Correct?

The email we sent to EU users (quoted in linked article) has the important details regarding the service interruption in the EU. Additionally, I can say that our privacy policy is concise, clear, and accurate with respect to the types of information we collect and how the data is used: https://www.instapaper.com/privacy If you have other specific questions, I will do my best to answer them.

Ironically, I am unable to read that page without enabling javascript for a third-party domain (amazonaws.com)...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#277

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

What would the regulators do? Block the service?

But that is one part which is confusing to me, from the UK ICO:

The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU.

Additionally, the GDPR does not apply to actions taken before and during the transition period (which ends now).

In this case, Instapaper does not offer goods or services to individuals in the EU. It actively blocks any user inside the EU.

Does that mean that Instapaper is no longer subject in any way to the GDPR?

In other words, if you had a company that had operations in the EU, but left the continent 2 years ago, and no longer has any activities with any EU individuals, does the GDPR suddenly apply to you?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#278

I'm still struggling with the fact that the EU can compel me to add what will be a funnel shattering dialog to my onboarding. I've shelved a bunch of side projects that I was excited to work on because I have no interest in dealing with any of this ambiguous law. Implementing it would most likely cause a large percentage of users to uninstall my app, because who wants to be greeted with a scary sounding dialog as the…

I think if your app isn't available in European regional Play/App Stores, you aren't considered to be targeting EU residents and you can safely ignore the GDPR.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#279
post #117
post #113

Earlier quoted context omitted.

>It still seems like the safest option given the massive risk this legislation is exposing companies. The safest option was actually to comply with the GDPR during the two years it has been in force now. I refuse to believe that the changes required were impossible to perform in two years. I'd love to know when exactly did Instapaper start looking into the GDPR.

The founder has said that he underestimated the amount of work it was going to take. Anyone who has ever worked on software knows how this stuff happens. You don't truly know how long something is going to take until you dig into the hairy details of implementation. Plus there are still tons of unknown variables at play with GDPR... even among companies who did spend sufficient time beforehand, as I quoted from the a…

The founder hasn't said a damn thing about it.

The requirements are clear enough to figure out a solution in the last couple of years. What takes time is if you're trying to skate as close as you possibly can to the legal line and not go over it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#280
post #274

Earlier quoted context omitted.

You would only take that liberty if you didn't have much respect for the law and its ability to touch you. I suspect companies are a lot more careful with each years new IRS rules even though they don't yet have case law and are often issued on much shorter notice.

Companies directly lobby the laws that affect the IRS on a year-to-year basis and have a lot more knowledge about it. It is hardly as vague as this was. I very much do respect the laws when I can, but I'm a US citizen, and my projects don't make enough money for me to ultimately care about the GDPR/EU. I just blocked them for .. ever, probably. You're really targeting people here, sorry I disagree?

I am not speaking of you specifically because this is about the behavior of companies and not personal projects.

There are companies, OP being one (a subsidiary of Pinterest) that have presence in the EU and are essentially playing chicken with the regulators. Blocking users but keeping their data is not compliance, nor are dialogs telling users you plan to carry on as normal. Companies do not do this with the IRS because they would be afraid of the consequences.

Post reply on HN