Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

311–320 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#311

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#312

Earlier quoted context omitted.

Probably worth reading this. https://jacquesmattheij.com/gdpr-hysteria EU agencies would prefer compliance over fines and would work with businesses to help them. As the article suggests, prosecution/fines will come when all other avenues are exhausted not the starting point.

Says some random dude on the Internet that seems to be a tremendous fan of GDPR. I prefer to base my understanding of laws on the text of the law. This one says that no warnings are required and that fines can be up to 20M EUR.

Under existing law companies can be fined somewhat ridiculous amounts for data breaches and essentially never are, so why exactly would the enforcement strategy change for the GDPR? Maximum sentences just aren’t an EU thing, nobody gets them unless they’re wilfully causing damage to people and this isn’t their first time. I don’t know if America does things differently, but based on what I know, it doesn’t - maximum fines and sentences are essentially never passed out there either.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#313

Earlier quoted context omitted.

hmmm... If I had an instapaper account it would be interesting to submit a GDPR request tomorrow, and see what kind of reply I got. Now I don't, but I'm sure there are plenty of other interested people around.

In all likelihood, the answer from most companies would be "sorry we don't yet have the ability to provide that data, it's on the roadmap, you'll have to wait".

At which point the data subject can report them to the regulator. Hopefully everyone receiving such a response will do so. Companies have had 2 years warning.

For most small business and startups this is no big deal as 1 or 2 reports to the regulator isn't going to trigger anything. For those companies of a certain size, the regulator might take note of 1,000 reports in the first week. I imagine some of those will have the regulator check if they have had a self-report from the company for non-compliance. Maybe then an email to colleagues at other ICOs across Europe.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#314

Earlier quoted context omitted.

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

What would the regulators do? Block the service? But that is one part which is confusing to me, from the UK ICO: The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU. Additionally, the GDPR does not apply to actions taken before and during the transition period (which ends now). In thi…

If you continue to hold data from EU residents, it’s somewhat likely that the GDPR applies, or that a court will decide it does some way down the line. If you employed a competent lawyer for about an hour they’d ask you why you’re storing that data if you’re never going to use it again, given the risks.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#315
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

It’s absolutely not true that the goal is compliance rather than fines: https://mobile.nytimes.com/2018/05/05/world/europe/margrethe...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#316
post #232

Earlier quoted context omitted.

Does GDPR make it illegal to shut a site down for a period of time? While they are shut down, what could be noticeable that they are not complying with?

GDPR doesn't care about your site, it cares about user data. The big thing with shutting the site down is it might make it impossible for users to request information about their data and/or request to have it deleted. That would violate the GDPR and could land the site in trouble.

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#317
post #113

Earlier quoted context omitted.

>It still seems like the safest option given the massive risk this legislation is exposing companies. The safest option was actually to comply with the GDPR during the two years it has been in force now. I refuse to believe that the changes required were impossible to perform in two years. I'd love to know when exactly did Instapaper start looking into the GDPR.

If there is so much ambiguity and interpretations what kind of manager would risk getting into doing such project if a risk of failure is equal to not doing it at all?

Courts are not black/white in interpretations of law. Demonstrating you put significant effort into being compliant is not for nothing. Plus you can't really figure it out until you try. Especially with something as complex as this and how the implications of the law will be different for different companies.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#318

Earlier quoted context omitted.

> it’s not entirely clear right now what information residents will request, If they ask for something specific in an informal way, that can be provided But from the GDPRs data portability point of view, it's everything that's linked to the account. Export your Facebook data for a good example of this. HN example: it would be the information in your profile, the links/text you submitted (but not the content of the li…

> for table in tables: select * from table where ... Arguably much or all of the entries with FKs to those rows as well, transitively. Unless you don't believe in normalisation :)

Yes, you are correct!

(I'll leave the normalization debate for later :) )

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#319
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

Why would a government impose anything other than the maximum?

Article 49 of the EU Charter of Fundamental Rights. All penalties under EU law must be proportionate. As a result there is already considerable case law, from multiple individual laws and countries, at the CJEU to define the extent of proportionate.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#320

Earlier quoted context omitted.

Probably worth reading this. https://jacquesmattheij.com/gdpr-hysteria EU agencies would prefer compliance over fines and would work with businesses to help them. As the article suggests, prosecution/fines will come when all other avenues are exhausted not the starting point.

Says some random dude on the Internet that seems to be a tremendous fan of GDPR. I prefer to base my understanding of laws on the text of the law. This one says that no warnings are required and that fines can be up to 20M EUR.

As Jacques and me as well have said; that simply means panic and it is not needed. You maybe do not live in the EU but the letter of the law is not such a thing here as it might be in the US (and although punishment is harsher and often far harsher than it is here, US also looks at intent). The EU is not going to punish any company that has the intent to offer its users privacy under this law, but made some mistakes or forgot things. They made this especially vague simply because a) we know they are not going to blanket destroy all violators anyway (we have many crazy vague laws for many decades; no one cares) b) if someone is clearly violating (and I am looking at you, obfuscating user tracking ad companies who, until now, got around pervious regulations by moving servers to other countries and other tricks) they want to be able to enforce, no matter what. This is all very clearly based on user intent, not letter of the law. It might be incredibly hard for litigious country citizens to understand, but we have been living all our lives (and it differs per country as well) with this.
Post reply on HN