Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

251–260 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#251

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

I'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating th…

Weren't you the one previously saying that don't panic (https://jacquesmattheij.com/gdpr-hysteria) because of GDPR back in the day? And now you are advocating that they should have already complied with GDPR given its impact!

Make up your mind.

And this is exactly why this is such a shitshow. Stop attacking people who haven't complied because small developers have other things rather than trying to figure out whether they have to redo their logs if a user asks their data to be deleted. This is almost bullying behavior.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#252
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

So, if that is the real intention of the EU, why they didn't write that in the law instead of threatening everyone with a 20M fine ? Because for how the law is written now you could in theory get a 20M fine for the smallest violation, and it's obvious that a lot of companies will be scared of that and will simply cut out European users, especially small companies that don't have money to spend in lawyers and other st…

[deleted]

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#253
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

So, if that is the real intention of the EU, why they didn't write that in the law instead of threatening everyone with a 20M fine ? Because for how the law is written now you could in theory get a 20M fine for the smallest violation, and it's obvious that a lot of companies will be scared of that and will simply cut out European users, especially small companies that don't have money to spend in lawyers and other st…

Dishing out a 20 million euro fine tomorrow would be completely against both the spirit and the wording of the law (fines must be proportional).

So, no, it's not unlikely, it's definite.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#254
post #240

Earlier quoted context omitted.

I agree, we should also get rid of copyright and property laws in the name of not "stifling innovation". It is absolutely ridiculous that I can't just walk into a peoples homes and install my 'adtreckr' eye tracking cameras on their TVs, even though that has the potential to revolutionise the amount of engagement and make sure that they only receive the most engaging, most relevant ads for their tastes./s Less satiri…

I think there's a very specific motivator behind people who build tech with the intent to sell, and that motivator doesn't cover every reason behind other people who build tech. If I want to start a project and think, "cool, if this works out, i'll sell it 6 months from now so it can actually do cool stuff", I'm just not going to work on that project at all. Honestly though, I would _love_ to live in a world where yo…

> Honestly though, I would _love_ to live in a world where you could walk into my home and install your 'adtreckr' eye tracking cameras on my TV. What you're describing is "trust", and I think the amount of it that each person has (for people in general, but also for companies) is a big influence in how they view GDPR (and other regulations that some might argue are unnecessary). Obviously, we're very far away from that world, so this isn't consent for you to come waltzing into my home in the near future. :)

Anarchy is always ruined by all those people! (I'm a big fan of trust, and not a big fan of Hayek,but Hayek had an insight when he talked about the micro and the macro cosma. People are to diverse that we can rely on "trust" to solve things, we need agreed on official rules)

> In my eyes, the satirical representation of what's happening here (from a consumer's point of view) is me placing an order for your awesome new eye tracking cameras, looking forward to the delivery and installation, and then seeing delays and delays as you repeatedly come back with, "well, are you sure you want this? are you sure I can enter your home? are you sure I can touch your TV? are you sure I can modify your TV?" I signed up, I paid for it, I told you I want it, just do whatever you need to do to give me it.

No. If you opt into buying my camera, since it is explicitly necessary to do all of that stuff, the consent is given as part of the buying contract. I just need to clearly state and explain that. If you had to gain access Facebook or instapaper via a huge opt in order form (let's say a pop-up detailing exactly what happens to your data), then it is equivalent...and that is exactly what GDPR requires

> From a business POV, I already treat user data with utmost regard, and my users know that. Similarly, I trust that the companies I willingly give my data to do the same. There are probably some bad actors in the mix, but I doubt they're going to bother with compliance anyway. Having to go out of my way to prove that data trust is there to a third party completely uninvolved with the contract I have with my users, and to spend hours and hours implementing new workflows and pipelines for out of scope functionality that needs to be maintained indefinitely -- this is not good for a business. It's bad for small businesses because it sucks up time, money, and other resources, and it's bad for big businesses because it opens up such a huge area for litigating non-issues. It might have some value to users, as I said elsewhere, but it's a heavy-handed regulation that is too overreaching in its implementation, in my personal opinion.

If you already do everything that is commonsense data protection, which is the bulk of what is required by GDPR, then all you have to do is documen that. If you cannot guarantee that the data is not shared, then the third party isn't uninvolved in the contract you do with your users.

Honestly, think of my data as something I own, like my house or my car, and GDPR becomes easy. Think of it as something you "create" by tracking me on your site, and your point of view becomes easier. I like my world better

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#255

Earlier quoted context omitted.

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate th…

I feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. Seeing this completely false sentiment repeated over and over again is getting exhausting. Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data” . GDPR is highly complex, and as of tomorrow, allowing EU traffic invites massive…

> You guys chose to make your traffic radioactive

Er. I vote in an EU country, but I don't feel like I "chose" anything. GDPR was mostly developed by institutions (Council of Europe, European Commission) formed of people that were not directly elected by European voters. In any case, given that personal data management issues are not a prominent part of the political discourse (even in the EU), I'd be surprised if any of the people in charge were elected because of their position on data protection.

It so happens that European institutions have come up with GDPR, but I don't think it is fair to see it as a conscious choice from EU voters.

> the reality is that EU residents are going to be blocked from a large percentage of the world’s websites

I'd be interested in seeing supporting evidence for this rather surprising claim. I'd conjecture that the "vast majority" is the long tail of small websites who haven't heard about GDPR or don't care about it; so I'm not too worried.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#256
post #244

Earlier quoted context omitted.

Fines must be "effective, proportionate and dissuasive", and there are various factors that the authorities must take into consideration. If you feel they _haven't_ taking the relevant factors into account, you can take it to the courts (especially if there is a history of fining non-EU companies more, as that would suggest they are taking irrelevant factors into consideration. https://gdpr-info.eu/art-83-gdpr/

Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". So yah, people are right to block the EU first, and figure out the details later.

> Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible".

No they absolutely do not.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#257
post #94

Earlier quoted context omitted.

Those of us in the EU hate them too.

I wonder why someone hasn't created a browser extension to just automatically accept them, yet.

Because AFAIK there's no standard way to identify them because each website comes up with its own design...

This is all rather silly, given that the choice to allow/refuse cookies, and the prompt, could have been better implemented at the level of the Web browser...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#258

Earlier quoted context omitted.

"Only a tiny fraction of the companies avoiding EU traffic due to GDPR have any intention of “doing shady stuff with your data”." Says who? If they weren't doing shady stuff, they wouldn't be pulling out of the EU. The excuses of being complex are just that, excuses.

Says who? Says anyone with common sense. What percentage of sites do you think employ data scientists or would even know where to go to sell your data? Most sites do nothing more than throw GA on their website, and maybe some Adsense. You people decided to paint that as something evil. That’s your decision to make, but just understand that most of the rest of the world wants no part of $20M potential fines and will s…

"Says anyone with common sense."

Where "common sense" means "agrees with downandout, not the more traditional definition of "common sense".

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#259

Earlier quoted context omitted.

Regulators only have so many hours in the day. Prioritizing high visibility infringers can persuade lower visibility infringers to get into compliance.

Not sure how they could persuade if they won't go after lower visibility infringers? I can't follow your logic.

I never said they wouldn't. But showing that they're willing to go after infringers is easier when you use high visibility cases to do it.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#260
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

You seem so incredibly confident in this that you must be able to point to some evidence or a case study to support your claims?
Post reply on HN