Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

301–310 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#301

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Epic fail

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#302
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

Why would a government impose anything other than the maximum?

Because having every single fine rescinded by the courts looks bad and brings you exactly no money.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#303
post #271
post #256

Earlier quoted context omitted.

> Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". No they absolutely do not.

Really? "effective" = large amount, so company won't do it again, "proportionate" = relative to revenue, "dissuasive" = make them an example so no one else will dare. I bet you are going to tell me proportionate somehow makes it all better, but for companies that make money this way, the amount of money they make this way in proportion to their income is basically all of it. So you can bet regulators will go for the…

Horseshit.

Proportionate means „proportionate to the infraction“. That is simply not up for debate or „internet troll‘s opinion“, that‘s established law.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#304
post #92
post #18

Earlier quoted context omitted.

'European' - e.g., EU - culture is still quite new in this regard, and plenty of companies have gotten very large fines for gross non compliance of other regulations/directives. Since GDPR compliance is enforced by EU members, many small companies are exposed to (have customers in) most or all EU jurisdictions, and the EU is very heterogeneous when it comes to regulatory enforcement by member states, I think that the…

> plenty of companies have gotten very large fines for gross non compliance of other regulations/directives Gross, wilful, intentional, deceptive non-compliance. To be honest you have to put quite a lot of effort into managing to get fined for non-compliance with EU regs/dirs.

I don't know why people think this. The European Commission Directorate General for Competition lists around 35 thousand cases in their Antitrust and General Registry alone.

EU directives are transposed to member states, who are the ones who enforce EU policy. If you're talking about EU members getting hit for non compliance with directive implementation - sure. If you're talking about private sector non compliance with transposed EU directives, that's largely up to how individual member states enforce EU requirements, since EU directives effectively become separate laws once they're transposed by each EU member.

As far as I'm aware, there's little aggregated data on how individual member states enforce (as in, number of cases and total amount of fines per year) EU directives. The EU takes in ~4-5 billion Euros per year in assessed fines, but the total amount should be significantly higher once you account for all of the cases/fines that are assessed on private companies, by individual member states, for non compliance with individual state laws implemented to enforce EU directives.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#306

Earlier quoted context omitted.

Most other companies haven't made the same decision, what's different about Instapaper? Do they share reading habits with multiple third parties perhaps?

GDPR has basically turned the lights on all of the companies doing questionable things with user data. Shutting down or turning off the EU is a huge red flag.

No it’s not. The way big companies are dealing with the GDPR is to ask their lawyers what to do. The lawyers define compliance very expansively since they’re not the ones doing the work and they are the ones who will be blamed if the EU comes after the company. So they say, “every single trace of anything related to user data must be purged.” So the company asks every engineering team to fill out a 200 point checklist about what they are doing with user data.

So, unless you’re saying that “Pinterest’s site reliability team can’t answer question 192 about how user data is deleted from the incident management system logs when an event is traced” is a “huge red flag” then you are exaggerating the issue.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#307

Earlier quoted context omitted.

Probably worth reading this. https://jacquesmattheij.com/gdpr-hysteria EU agencies would prefer compliance over fines and would work with businesses to help them. As the article suggests, prosecution/fines will come when all other avenues are exhausted not the starting point.

Says some random dude on the Internet that seems to be a tremendous fan of GDPR. I prefer to base my understanding of laws on the text of the law. This one says that no warnings are required and that fines can be up to 20M EUR.

Neither of you are right. The EU is not going to go out guns blazing with $20m fines for small companies. They’re also not going to host a drum circle for companies to harmoniously join the movement towards better user privacy. They’re going to get some big fines out there on big companies (who doesn’t love free money) and also go after smaller companies actively doing bad things with user data. Yes, they could, but in the same way that the person standing at the bus with you could punch you in the face. It might happen, but realistically, it probably won’t, and you’re probably not actively prepping for it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#308

Earlier quoted context omitted.

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

"- IPs are personal private infromation" IPs combined with other user data could be PII. "- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically, advertising is optional in EU sites as of today." Wrong. You need opt-in consent for non personalized ads, but this can be the "soft consent" type where you only present the "Accept" button. Advertising is no more optional tomorrow than it wa…

> IPs combined with other user data could be PII.

1) Bob signs up for a service and is logged

2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained.

3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account.

This seems like a likely violation, if so you would have to treat ip address like personal information.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#309

Earlier quoted context omitted.

The scope of work for GDPR was underestimated by me, we were not able to complete that work for the deadline on Friday, and this was the required alternative. We are working very hard to minimize the service interruption.

Have you received genuine legal advice that recommended that you shut down business instead of continuing to work towards compliance? The agencies that can enforce the GPDR want you to be compliant, not to fine you... If you're actually working towards compliance past evidence shows they won't fine you.

The EU actually loves levying huge fines against rich US tech companies. Why do you think they prefer compliance to fines?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#310
post #127

Earlier quoted context omitted.

> it is the company that is violating the law, not the lower profile group. I work in a company that was acquired and we're still our own legal entity. Would our owner be affected if we violate GDPR?

No, in that case the owner is just a shareholder. But if the original legal entity no longer exists (which I believe is the case with Instapaper) then it doesn't matter that you've been acquired, you are now part of the mothership.

But if the original legal entity no longer exists (which I believe is the case with Instapaper)

Unlikely. "Instapaper Holdings, Inc." is right in their footer.

Post reply on HN