Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

291–300 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#291
post #248

Earlier quoted context omitted.

Indeed, it is not service to EU users which is governed by GDPR, it is data processing of data subjects in the EU. Obviously the data processing as defined by the GDPR doesn't stop simply because the service stops since storage is considered processing. Seems to me Instapaper painted a big target on their chest: "We're not compliant, and we're going to give EU users the middle finger in the meanwhile." Whereas, their…

So if someone traveling in the EU gets GDPR protections, does someone traveling in the US lose GDPR protections? Are the GDPR protections only for the data that was collected while someone was in the EU or for all data once they've traveled to the EU once?

> So if someone traveling in the EU gets GDPR protections, does someone traveling in the US lose GDPR protections? Are the GDPR protections only for the data that was collected while someone was in the EU [...]?

Roughly speaking, yes. E.g. a Brazilian business not specifically targeting transactions within the EU or EU nationals doesn't come under the GDPR. Conversely, an EU business basically has to apply the GDPR to any data collected inside the Union, regardless of the individual's nationality. (Obviously, this gets messier online, but if the currency was e.g. Euros and the company is in Belgium, probably covered.)

Having said that, you might have trouble as a non-EU resident to get the data protection agencies to care for trivial, individual cases. (My opinion as a European, not a fact.)

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#292

Earlier quoted context omitted.

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

The general global legal principal here is that you can't charge someone for something that happened before the law came into effect. So you are not correct on #1.

By that standard, if you had purchased a child porn magazine in the 1970s when it was legal to do so, you would be in the clear if the police searched your house and found it. I am not a lawyer, but that doesn’t seem likely.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#293
post #290
post #31

Asked a lawyer: If Instapaper doesn't delete the data from its EU users tomorrow, all the rules of the GDPR might still fall on their head. Most likely, they are then storing EU user data without given consent and have to follow all the requests about data storage, use, deletion and so on. Denying service without data deletion is not an option.

It would be MUCH easier to legally argue against the retroactiveness of the GDPR while coming into compliance than to risk being active during the actual deadline while coming into compliance. I strongly suspect that the GDPR applying retroactively will get litigated and will have a very difficult time legally.

If only it hasn't come into law two years ago, then this argument might have a change.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#294

Earlier quoted context omitted.

I don't agree, but at least I understand where you're coming from. Here is the stasis of our dispute: > I would argue most of these things make the world a better place not a worse place. And that people should be able to choose how they want to pay for those services. I'm not convinced any of the apps we pay for in data really improve our lives. The price we pay in control over our identity and our information usual…

I'm not convinced any of the apps we pay for in data really improve our lives. The price we pay in control over our identity and our information usually outweighs the benefits. Hundreds of millions of Google and Facebook users disagree. If you ask people what Google does with the data they collect, a large percentage both incorrectly believe that they directly sell it to advertisers (rather than just using it for ad…

That's fine, the problem is there was no choice before. OK, Google Analytics is somewhat easier to block, but e.g. Facebook with their shadow profiles? How do you block that? Is it feasible to expect teenagers to not use FB/Snapchat/Instagram when all their friends are just to protect their privacy?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#295
post #257

Earlier quoted context omitted.

I wonder why someone hasn't created a browser extension to just automatically accept them, yet.

Because AFAIK there's no standard way to identify them because each website comes up with its own design... This is all rather silly, given that the choice to allow/refuse cookies, and the prompt, could have been better implemented at the level of the Web browser...

Like Do Not Track (DNT)? Oh, wait, that exists, and almost all companies ignore it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#296
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

I’m sorry, but blind trust in the benevolence of regulators in a country you’re not even a citizen of is no way to run a business. I don’t blame US companies unwilling to deal with GDPR uncertainty any more than I blame EU banks unwilling to deal with American customers because of our insane FATCA regulations.

I'm pretty sure even in the US, sentences for breaking the law vary depending on the case. And what's the point living in civilisation if you can't trust the judiciary?

There are options to appeal, so you're not at the mercy of one regulator/judge/. Europe and the GDPR are no different.

EU banks not dealing with Americans/FATCA is simply down to it not being worth the effort. Luckily, the GDPR wasn't written in such an absolute way. It doesn't apply to non-EU companies doing business outside the EU, even if they might get the occasional European using their services (unless they specifically go after EU subjects). For example, a Japanese company selling specialty arcade joysticks and I, as a UK resident buy one using yen, not pound sterling. Even though they might ship to the UK, as they ship to loads of places, they aren't doing business in the Union, and they don't have to follow the GDPR.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#297
post #117
post #113

Earlier quoted context omitted.

>It still seems like the safest option given the massive risk this legislation is exposing companies. The safest option was actually to comply with the GDPR during the two years it has been in force now. I refuse to believe that the changes required were impossible to perform in two years. I'd love to know when exactly did Instapaper start looking into the GDPR.

The founder has said that he underestimated the amount of work it was going to take. Anyone who has ever worked on software knows how this stuff happens. You don't truly know how long something is going to take until you dig into the hairy details of implementation. Plus there are still tons of unknown variables at play with GDPR... even among companies who did spend sufficient time beforehand, as I quoted from the a…

> The founder has said that he underestimated the amount of work it was going to take.

Source?

Pinterest which owns Instapaper (2 years ago mind you!) has raised $1.47B to date. There's no legitimate excuse here.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#298

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You had two years to get ready. Why wasn't this announced months ago.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#299
post #127

Earlier quoted context omitted.

> it is the company that is violating the law, not the lower profile group. I work in a company that was acquired and we're still our own legal entity. Would our owner be affected if we violate GDPR?

No, in that case the owner is just a shareholder. But if the original legal entity no longer exists (which I believe is the case with Instapaper) then it doesn't matter that you've been acquired, you are now part of the mothership.

So a LLC with owned by a larger company would that allow for the owner to be a shareholder ?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#300
post #136

Earlier quoted context omitted.

So which part of the law is ridiculous? Disclaimer: I believe the principles that are applied within the law, data autonomy, data ownership, usage-binding of data etc., are sound. And just because people have aggregated any data on people that they could get to better manipulate them into buying crap for so long that it‘s hard to change track today, doesn‘t mean it‘s wrong for lawmakers to enforce parting ways with t…

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

Advertising can be done without cookies. It‘s a simple tag.

Unless you mean user-tracking advertising.

Post reply on HN