Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

281–290 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#281

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

You seem to be presuming guilt before innocence. Most strong advocates of GDPR seem to have this attitude. Perhaps the regulators will, too.

Using that line of reasoning, Pinterest is making a very prudent decision.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#282
post #100

Earlier quoted context omitted.

If they were smart about how transparent a business needed to be, I don't think it would be toothless at all. It would have given users more information about what is happening behind the scenes and allowed them to make their own decisions. > So that users can opt-out of having unnecessary data collected. You should only be collecting the data needed to run the service. If your business collapses when users opt-out,…

I don't agree, but at least I understand where you're coming from. Here is the stasis of our dispute: > I would argue most of these things make the world a better place not a worse place. And that people should be able to choose how they want to pay for those services. I'm not convinced any of the apps we pay for in data really improve our lives. The price we pay in control over our identity and our information usual…

I'm not convinced any of the apps we pay for in data really improve our lives. The price we pay in control over our identity and our information usually outweighs the benefits.

Hundreds of millions of Google and Facebook users disagree. If you ask people what Google does with the data they collect, a large percentage both incorrectly believe that they directly sell it to advertisers (rather than just using it for ad targeting) and don't have a problem with that.

I'm not saying that you're wrong, but I am saying that you aren't so clearly right that your preferences should be forcibly imposed on everyone.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#283

I'm still struggling with the fact that the EU can compel me to add what will be a funnel shattering dialog to my onboarding. I've shelved a bunch of side projects that I was excited to work on because I have no interest in dealing with any of this ambiguous law. Implementing it would most likely cause a large percentage of users to uninstall my app, because who wants to be greeted with a scary sounding dialog as the…

I think if your app isn't available in European regional Play/App Stores, you aren't considered to be targeting EU residents and you can safely ignore the GDPR.

I've heard conflicting reports about that as well.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#284

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

If you get a request today, you've got a month to comply, so in a way you're right. However, it really depends on how big your company is and how little you have prepared. Your absolute minimum is to have a statement that says that you are going to use the data you gather for contract purposes and to list the 3rd parties that you need to send that data to for contract purposes.

But then, if you are using data for other purposes, it's a bit complicated because you'll have to refrain from doing so until you are compliant. It doesn't necessarily have to be shady stuff. Even if you aren't sure if what you are doing is contract basis or not, it can be a pain. It's not necessarily massively difficult, but if you woke up yesterday and thought "OMG! We haven't done GDPR! What are we going to do?", then I can see this.

I've written earlier about how the company I'm working for now has changed what it is doing with data, even though I don't think they were doing anything shady previously. But it's more like, "Do we really want to list a lot of things and piss off the customer?" So now there are heated discussions of what 3 (or whatever other small number) of things we might collect data for because we believe that's the kind of limit that the customer will tolerate.

All of these discussions take time -- especially in a large organisation. And you can see in discussions on HN, there is going to be a large backlash of "Why do we have to do this anyway? Can't we just ignore it?" which wastes a lot more time.

Sounds like they want to be compliant, but are just not ready yet. A miss on their part, but hopefully they will get things in order quickly.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#285

Earlier quoted context omitted.

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data” . GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive…

>I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. This sentiment and the hilariously large fines (regardless of company size, even) on relatively-ill-defined requirements make the whole GDPR process feel like it was designed to bully businesses into compliance. Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of c…

> while the real "bad guys" that are actually doing bad things with our data are going to continue ignoring the law.

This is already happening without the GDPR (carders, dumps, etc), so I don't buy it. The black-market analogy (e.g. illegal drugs) also doesn't hold when applied to companies.

> the hilariously large fines (regardless of company size, even)

Oh no, proportional fines! How socialist!

The whole point is to make it somewhat independent of the company size, so bigger companies won't just swallow the fines. This is typically what Google et al do, they just factor it in to the cost of business. The GDPR wasn't written in a vacuum.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#286
post #232
post #166

Earlier quoted context omitted.

> And who's to say that Instapaper did not contact the authorities and discuss a plan such as this to mitigate the problem temporarily? If that's the case, why can't they simply tell this? I side with the GP: Preventing access doesn't absolve you from complying with the law.

Does GDPR make it illegal to shut a site down for a period of time? While they are shut down, what could be noticeable that they are not complying with?

GDPR doesn't care about your site, it cares about user data.

The big thing with shutting the site down is it might make it impossible for users to request information about their data and/or request to have it deleted. That would violate the GDPR and could land the site in trouble.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#287

Earlier quoted context omitted.

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data” . GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive…

>I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. This sentiment and the hilariously large fines (regardless of company size, even) on relatively-ill-defined requirements make the whole GDPR process feel like it was designed to bully businesses into compliance. Some pieces of GDPR are definitely for the benefit of the end-user (at the expense of c…

> “bully businesses into compliance“

I am not sure I understand this sentence. That’s what laws do. “Bully” you into compliance. I think you might have meant something else?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#288
post #110

Earlier quoted context omitted.

It is not retroactive, the law has been there for 2 years, becoming _active_ in 40 minutes. Secondly, it is not the collection of data, it is the storing of data. So if you store the data without user confirmation in 40 minutes, there might be a problem. The action which is the problem is the storing of private data. There is nothing retroactive here.

Is three year old data covered? Sounds retroactive to me.

If you bought designer drugs 10 years ago, the act of buying was legal, even though storing it today no longer is. Same here, collecting it or using it 10 years ago might have been legal. Storing it today is not. You might be confused which action is covered by the law, and that action is "storing". You can decide to stop doing that action today, so it is not retroactive at all.

I don't really see where the age of the data you store comes into play.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#289
post #242

Earlier quoted context omitted.

In such a world, it would make more sense to limit the scope of the law until enforcement can catch up. Minimally enforced laws that are enforced subjectively are problematic regardless of why.

Are you suggesting that the US government suspend income tax while they hire enough people in the IRS to go through every individual's tax return?

Minimal enforcement can be used to make everyone a criminal. You then selectively apply the law against people you don’t like.

Taxation (I would hope) is not minimally enforced.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#290
post #31

Asked a lawyer: If Instapaper doesn't delete the data from its EU users tomorrow, all the rules of the GDPR might still fall on their head. Most likely, they are then storing EU user data without given consent and have to follow all the requests about data storage, use, deletion and so on. Denying service without data deletion is not an option.

It would be MUCH easier to legally argue against the retroactiveness of the GDPR while coming into compliance than to risk being active during the actual deadline while coming into compliance.

I strongly suspect that the GDPR applying retroactively will get litigated and will have a very difficult time legally.

Post reply on HN