Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

341–350 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#341
post #337

Earlier quoted context omitted.

You seem so incredibly confident in this that you must be able to point to some evidence or a case study to support your claims?

Here's the law. Notice that there's a bunch of stuff taken into account before setting the fines. https://gdpr-info.eu/art-83-gdpr/ Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/arti…

There is no caselaw on the GDPR and no way to predict how fines will be levied. You can speculate how it will be enforced (as you have), but businesses tend to avoid speculation when assessing risk.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#342
post #300

Earlier quoted context omitted.

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

Advertising can be done without cookies. It‘s a simple tag. Unless you mean user-tracking advertising.

i mean content-based (still requires cookies)

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#343

Earlier quoted context omitted.

- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".

"- IPs are personal private infromation" IPs combined with other user data could be PII. "- You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically, advertising is optional in EU sites as of today." Wrong. You need opt-in consent for non personalized ads, but this can be the "soft consent" type where you only present the "Accept" button. Advertising is no more optional tomorrow than it wa…

- Ips in general are not bound to some specific person. It's only because laws require that ISPs keep PII allocation data that they become personally identifying. Perhaps it would be easier to plug that leak right there.

- ah, well google suggests you ask consent even for content-based ads

- 99% of the sites show you what they have on you when you use them. The provision could be to have a separate download page when that is not the case. If every business must have an unauthenticated download page, it becomes easier to get other people's data via phishing.

its not fud. this is the internet. lets talk again in a few months.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#344

Earlier quoted context omitted.

There is also a thing when user closes consent popup and the site won't redirect to invalid ip address. I have seen plenty of sites where you can close the consent popup and continue to use the site - that means they collect your data without your consent. Grotesque.

how do you know they collect your data?

Because they say that in the popup.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#345
post #317

Earlier quoted context omitted.

If there is so much ambiguity and interpretations what kind of manager would risk getting into doing such project if a risk of failure is equal to not doing it at all?

Courts are not black/white in interpretations of law. Demonstrating you put significant effort into being compliant is not for nothing. Plus you can't really figure it out until you try. Especially with something as complex as this and how the implications of the law will be different for different companies.

I don't think that makes a difference, perhaps it depends on the country. Some EU countries are hostile towards entrepreneurs and wrong action or inaction would get the same treatment.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#346

Earlier quoted context omitted.

In all likelihood, the answer from most companies would be "sorry we don't yet have the ability to provide that data, it's on the roadmap, you'll have to wait".

At which point the data subject can report them to the regulator. Hopefully everyone receiving such a response will do so. Companies have had 2 years warning. For most small business and startups this is no big deal as 1 or 2 reports to the regulator isn't going to trigger anything. For those companies of a certain size, the regulator might take note of 1,000 reports in the first week. I imagine some of those will ha…

I keep reading the "two years warning" notion on HN. While that might be technically correct, the real problem was that nobody UNDERSTOOD what GDPR meant (including the legislators) and so to this day, its practical implementation will to no small part depend on the iterative conclusions and learning various implementors (eg. companies) made in an arduous process since.

In other words, the first to think they were GDPR compliant might have had to redo a ton of work to adjust to more recent interpretations.

And let's not forget, for large orgs with complex infrastructure, this is a behemoth of an effort. There's been year long projects in the two large tech companies I've had insight to since.

And while I'm at it, let me comment on the frequently expressed notion of "if you've respected your users in the past, you'll be fine!". Just to pick one counter argument: the right to be forgotten. That can only be implemented thoroughly and in the way the users expect it to work (ie. delete everything but what you're legally required to retain) by finding a way to connect all user data so you know what to drop if need be. That is exactly the kind of action that's caused public outrage at big tech to begin with and it's not only potentially a huge effort, it also increases risk of abuse.

This all being said, I still think GDPR is a good idea at least in principle. And believe it or not, while everyone around me is really of compliance work, GDPR seems widely considered a good idea in principle across engineering in big tech.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#347

Earlier quoted context omitted.

No one said "they won't go after small timers". Hitting the big players hard makes everyone wary of violating and they will absolutely catch some small fish as well. It's just silly to expect any enforcement body to go after everyone equally. It doesn't even make sense; company A has data on 1.5B people, company B has data on 27 people and the owner's mother. Why would you go after B before A?

They have said this. a) they have said they don't want to punish companies for the sake of it, they want to use it as an incentive to fundamentally change the approach to the handling of user data. This means not suing tiny companies for more money than they are worth. b) they have said that the standards will roughly increase with the size of the company and resources it has. A company with 27 users (and few employe…

> This means not suing tiny companies for more money than they are worth.

Which effectively kills that company even if court finds their violation was minimal.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#348

Earlier quoted context omitted.

At which point the data subject can report them to the regulator. Hopefully everyone receiving such a response will do so. Companies have had 2 years warning. For most small business and startups this is no big deal as 1 or 2 reports to the regulator isn't going to trigger anything. For those companies of a certain size, the regulator might take note of 1,000 reports in the first week. I imagine some of those will ha…

I keep reading the "two years warning" notion on HN. While that might be technically correct, the real problem was that nobody UNDERSTOOD what GDPR meant (including the legislators) and so to this day, its practical implementation will to no small part depend on the iterative conclusions and learning various implementors (eg. companies) made in an arduous process since. In other words, the first to think they were GD…

But there are not massive differences between the laws we've had for many years - for a UK example PECR and DPA implement EU regulations and contain many of the same principles around lawful basis, limiting the amount of data that's held and the length of time it's held for, etc.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#349

Earlier quoted context omitted.

True that the text doesn’t say this, but several of the privacy authorities in the different jurisdictions in Europe have been stating this publicly in interviews. The last one I saw was the ICO in the UK today on BBC Click saying exactly this...

The text is what matters. You cannot defend yourself in court with the content of interviews.

Actually, you can in Europe. Context of law is more important than letter of law, as opposed to the US.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#350

Earlier quoted context omitted.

Have you received genuine legal advice that recommended that you shut down business instead of continuing to work towards compliance? The agencies that can enforce the GPDR want you to be compliant, not to fine you... If you're actually working towards compliance past evidence shows they won't fine you.

The EU actually loves levying huge fines against rich US tech companies. Why do you think they prefer compliance to fines?

Well, let's take a famous example. The €4.2bn fine given to Google in 2017 for abuse of its market position in pushing its own shopping results.

https://www.theguardian.com/business/2017/jun/27/google-brac...

Shocking stuff.

Except the Commission actually gave Google quite detailed advice over 5 years earlier about what it needed to do to be compliant.

https://www.ft.com/content/564a284a-a334-11e1-8f34-00144feab...

Post reply on HN