Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

331–340 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#331

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

Don't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.

You don't need a new employee, just someone who is assigned the task to deal with queries that come in. For a small start-up this is not likely to amount to many requests, and even then the requests from the public first go through the regulator. So many requests will be weeded out at that stage with the aim of reducing the burden on businesses, only requiring them to act when the regulator has identified a breach. At this point they have to fix it, if they don't fix it, or don't try to fix it (fizimg it is usually by deleting the customer data) then they are open to prosecution. If they fix it the regulator isn't then going to seek huge fines, they are aimed at non-compliance firms who have no intention of complying (e.g because it is their entire business model).

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#332

Earlier quoted context omitted.

Weren't you the one previously saying that don't panic ( https://jacquesmattheij.com/gdpr-hysteria ) because of GDPR back in the day? And now you are advocating that they should have already complied with GDPR given its impact! Make up your mind. And this is exactly why this is such a shitshow. Stop attacking people who haven't complied because small developers have other things rather than trying to figure out wheth…

He's also the same guy who said, and I quote, "compliance is easy, just read the law." It surprises me how much this community tolerates such combative cluelessness.

Have you read the law?

Did you start working on compliance in a timely manner or did you become aware of this a few weeks ago?

Does your company have a clue about what it is doing in general?

Do you take a user centric approach to data ownership?

If those are all 'yes' then compliance is easy. If you don't care, do illegal stuff, are clueless or don't care about your users then compliance is going to be hard, that's what the law intends because those companies should change their ways.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#333

Earlier quoted context omitted.

But that's the reality. At least they're working on it and the fact that a lot of companies massively overreact means they at least take data protection serious now.

You don't ignore a law for 2 years and then just after it comes into force say "at least we're working on it". Honestly I thought the GDPR was a bit of an over reaction when it came out 2 years ago but seeing how little respect companies have for our data over the last few weeks I've been convinced it was necessary.

> You don't ignore a law for 2 years

And that's only GDPR. We've had PECR (in UK) since 2002 and DPA since 1995.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#335
post #321

Earlier quoted context omitted.

Weren't you the one previously saying that don't panic ( https://jacquesmattheij.com/gdpr-hysteria ) because of GDPR back in the day? And now you are advocating that they should have already complied with GDPR given its impact! Make up your mind. And this is exactly why this is such a shitshow. Stop attacking people who haven't complied because small developers have other things rather than trying to figure out wheth…

His posts were clearly politically motivated, zealot-type propaganda. Either self-interest or useful-idiot. For some reason he is such a fan of this legislation that he is willing to overlook its glaring problems. No objectivity there, I am afraid.

> His posts were clearly politically motivated, zealot-type propaganda.

Oh my. Terribly sorry for putting up a political manifesto.

> Either self-interest or useful-idiot.

Take your pick. No third options? Such as a genuine desire to take some of the heat off for SMEs, of which I own several and participate in several others?

> For some reason he is such a fan of this legislation that he is willing to overlook its glaring problems.

Yes, I'm a fan of this legislation. I also was a fan of its predecessor and it's a joy to see companies that don't have their house in order make all kinds of panicked moves. I have a pretty good behind the scenes view of what goes on with respect to privacy abuse by corporations due to the nature of my work. Those companies that do illegal stuff, don't give a damn about their users and that in general are clueless (and which in turn increases the chances of their online properties being compromised) will be the ones that run into the 'glaring problems' The only thing that I see as troublesome with the law is the lack of reciprocity and enforcement across borders. The EU picked a complex and for really small companies expensive way to resolve that and that's something that I see as a real issue.

> No objectivity there, I am afraid.

I think you mean to say you don't agree with me.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#336
post #12

Earlier quoted context omitted.

An email-address to send requests to and someone setting up a process for those requests along with a definition of which data to be returned to the user, all that isn't hard to implement. GDPR has caused some panic that's unnecessary. The violations won't be fined with 4%/€20m (€ not $) right away, there's more steps before that, starting with "a warning in writing in cases of first and non-intentional noncompliance…

> GDPR has caused some panic that's unnecessary. Maybe some companies have overreacted, but dismissing them feels a bit like blaming the user for bad UX. Couldn't you argue that a law that causes a panicked overreaction was a poorly written law in at least one respect, given that laws have a communicative function? Especially if all these complaints were raised well in advance of the passage of the law, so that the d…

Seems pretty clear to me that a lot is taken into account and that the regulators can't go straight to huge fines.

https://gdpr-info.eu/art-83-gdpr/

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#337
post #61

> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant. Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.

You seem so incredibly confident in this that you must be able to point to some evidence or a case study to support your claims?

Here's the law. Notice that there's a bunch of stuff taken into account before setting the fines.

https://gdpr-info.eu/art-83-gdpr/

Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...

Here's an organisation that had video interviews with children who were the victims of sexual abuse. The organisation put these videos on DVDs with no encryption, and sent them through regular mail. The DVDs were lost. This is a repeat of a previous data loss from this organsition. Despite the severity of this breach, and the repeat, and the lack of protective action, the organisation was not fined the maximum available fine. https://ico.org.uk/action-weve-taken/enforcement/crown-prose...

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#338

Earlier quoted context omitted.

"- IPs are personal private infromation" IPs combined with other user data could be PII. "- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically, advertising is optional in EU sites as of today." Wrong. You need opt-in consent for non personalized ads, but this can be the "soft consent" type where you only present the "Accept" button. Advertising is no more optional tomorrow than it wa…

> IPs combined with other user data could be PII. 1) Bob signs up for a service and is logged 2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained. 3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account. This seems like a likely violation, if so you would have to treat ip ad…

The personal information here is the IP-Bob tuple, not the IP on its own. Bob might as well be assigned a new address from DHCP on a daily basis. His friends might be using his address. He might have used the address of some public network in the first place. All or these are pretty likely scenarios. The IP is only interesting given the context of who uses it and when, so as to separate Bob from Alice, and Bob's favorite cafe and Bob's workplace from Bob's home, and to figure out if Bob is ever visiting Alice.

So if Bob asks for his personal information to be cleared and the system leaves Bob-IP tuples behind, it clearly didn't do what he told it to do.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#339

Earlier quoted context omitted.

Says some random dude on the Internet that seems to be a tremendous fan of GDPR. I prefer to base my understanding of laws on the text of the law. This one says that no warnings are required and that fines can be up to 20M EUR.

>> Says some random dude on the Internet that seems to be a tremendous fan of GDPR. Let's be a little self-conscious here, shall we? Of all the articles on HN that discuss the GDPR that I've read, I've found one that you didn't contribute to and your contributions never show an "understanding of laws based on the text of the law". For instance, you have consistently claimed that there will be 28 (btw, not 27) differe…

I’m not on the warpath, but I will consistently dispute rosy predictions about the “good natured enforcers” (a direct quote from Jacques) of GDPR. No law or regulation this easy to violate, with fines this large, that claims extraterritorial powers, has ever not been abused, and this will be no exception.

With regard to your claim that it will not be subject to unique interpretations in each country within the EU, that simply isn’t true. Each country will have its own enforcement agencies. They’ll enforce it in different ways, and to different degrees. Since this regulation is so vague, it simply isn’t possible that they will all interpret and enforce it in the same way.

You seem to be in Jacque’s corner, claiming that our new self-appointed privacy overlords will be perfectly coordinated and “good natured”. As someone with quite a bit of experience dealing with government agencies, I can tell you that few of those that seek out relatively low-paying government jobs where the primary perk is having power over other people are “good natured”. There will be abuses.

The good news is that D-Day is here, and now we can all stop arguing and watch to see whose predictions come true.

Post reply on HN