Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

351–360 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#351
post #257

Earlier quoted context omitted.

Because AFAIK there's no standard way to identify them because each website comes up with its own design... This is all rather silly, given that the choice to allow/refuse cookies, and the prompt, could have been better implemented at the level of the Web browser...

Like Do Not Track (DNT)? Oh, wait, that exists, and almost all companies ignore it.

The cookie warnings are about refusing cookies, which is something that is completely up to the Web browser.

Specifically, Web browsers could warn when a website sets a cookie and ask for user consent before storing it (and if the user does not consent then the website becomes unavailable).

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#352

Earlier quoted context omitted.

hmmm... If I had an instapaper account it would be interesting to submit a GDPR request tomorrow, and see what kind of reply I got. Now I don't, but I'm sure there are plenty of other interested people around.

In all likelihood, the answer from most companies would be "sorry we don't yet have the ability to provide that data, it's on the roadmap, you'll have to wait".

Anything that doesn't say "We will do just that! It might take up to 30 days" and asks for up to two extensions afterwards is not compliant, so this would be an exceptionally dumb response.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#353

Earlier quoted context omitted.

True that the text doesn’t say this, but several of the privacy authorities in the different jurisdictions in Europe have been stating this publicly in interviews. The last one I saw was the ICO in the UK today on BBC Click saying exactly this...

The text is what matters. You cannot defend yourself in court with the content of interviews.

Of course you can. Otherwise what would be the point of them in the first place?

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#354
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

> Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come. A lot of the responses to the GDPR shutdowns have been like this - "you don't need to shutdown, because you won't be fined yet." But I have to ask, isn't shutting down a better alternative to knowingly breaking the law? W…

Shutting down is not the better alternative because you still are breaking the law, as siblings explained.

Working into getting compliant and have a paper trail to demonstrate how you are progressing in case of control is the only realistic way to do it. That's exactly what a lawyer (in my country of course, perhaps not applicable to other countries) advised me to do. And this lawyer works closely with the public institution doing the enforcing in my country.

From my understanding, I'd be surprised if even 1% of companies were fully compliant today. Yeah, even big ones like Google (I actually spotted something I'm almost certain is non-compliant yesterday on their TestMySite service).

Don't be mistaken, the mails everyone receive about changes of terms for the GDPR and validating consent to receive newsletter are just the tip of the iceberg, they are the easy cosmetic changes.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#355
post #9

Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. S…

> What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. Can you point to the section of the legislation that says this? It would probably go a long way to stopping folks from freaking out.

I can't, since I'm pretty sure it's not in the legislation.

The law is enforced by humans, not robots, and those persons have a culture and habits.

Of course I could be wrong and they could start enforcing heavily on everyone on day one.

But they just don't have the manpower to do that, for starter. And that's just not in the culture either. Law is enforced differently in different part of the world. The US is known for punishment. Other parts are focused on redemption.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#356
post #234

Earlier quoted context omitted.

Risk management is part of every decision a business faces, legal or compliance risks aren't any different. Can we risk the CEO and chairman travelling on the same airplane? Can we risk having our disaster recovery site in the same city as our main? Same country? Same continent? Can we risk buying all this trends-sensitive inventory? Etc. (Potential savings or revenue) - (Somewhat easy to calculate cost) * (Difficult…

That's not what I was referring to at all. I mean that the sentiment of 'probably'/'likely' from a random stranger online, to a business which might have EU users but never interacted with EU regulators doesn't mean much.

Of course Instapaper shouldn't take advise from me, a random stranger online, but from lawyers.

But from my shoes (someone that run a business in the EU, is not compliant right now and is talking to a lawyer), Instapaper decision is a bad risk-management decision.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#357

Earlier quoted context omitted.

Let me know if you have any questions... Which parts of GDPR do you think you're in violation of? Why do you think removing access for users currently in the EU puts you in the clear legally? What are you doing with European users data currently, have you deleted it all? A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy, just by tightening up…

Which parts of GDPR do you think you're in violation of? Answering those questions in a public forum would be extremely foolish. ("Do you know why I pulled you over?") A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy And how many of them are actually in compliance?

Answering those questions in a public forum would be extremely foolish

Perhaps asking for questions was foolish?

And how many of them are actually in compliance?

If you're not in the business of selling customer data to third parties, it's not very hard to comply, just requires some discipline on how data is stored and who it is shared with, and a point of contact for enquiries about data.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#358
post #248

Earlier quoted context omitted.

Indeed, it is not service to EU users which is governed by GDPR, it is data processing of data subjects in the EU. Obviously the data processing as defined by the GDPR doesn't stop simply because the service stops since storage is considered processing. Seems to me Instapaper painted a big target on their chest: "We're not compliant, and we're going to give EU users the middle finger in the meanwhile." Whereas, their…

So if someone traveling in the EU gets GDPR protections, does someone traveling in the US lose GDPR protections? Are the GDPR protections only for the data that was collected while someone was in the EU or for all data once they've traveled to the EU once?

It seems that once you are in the EU, the GDPR applies to you. So you could move to Europe for a year and demand that Facebook provide you with all the benefits of the GDPR. Residency is probably a practical requirement but is not a written legal requirement since you will need to complain to the data authorities, and if you leave after complaining they will likely not follow up on your complaint.

Travel is probably one of the hairier issues. For companies which are big enough and do have an EU legal presence, they might get pushed to comply. Obviously, while someone is in the EU, EU laws regarding the treatment of that person apply. If you (as a data controller) are in the EU, of course you should comply, even if the basis of your legal relationship was formed outside of the EU.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#359

Earlier quoted context omitted.

At which point the data subject can report them to the regulator. Hopefully everyone receiving such a response will do so. Companies have had 2 years warning. For most small business and startups this is no big deal as 1 or 2 reports to the regulator isn't going to trigger anything. For those companies of a certain size, the regulator might take note of 1,000 reports in the first week. I imagine some of those will ha…

I keep reading the "two years warning" notion on HN. While that might be technically correct, the real problem was that nobody UNDERSTOOD what GDPR meant (including the legislators) and so to this day, its practical implementation will to no small part depend on the iterative conclusions and learning various implementors (eg. companies) made in an arduous process since. In other words, the first to think they were GD…

> the real problem was that nobody UNDERSTOOD what GDPR meant (including the legislators

There we have to disagree. It's not like this is something new and untried.

GDPR is a development from long-standing, and now very well understood, Data Protection. The legislation seems mainly intended to modernise some of the definitions and scope (eg adding biometrics to PII), catch some newer practices, and make very plain and explicit that it doesn't just apply to EU companies.

In 1996 and 97 in the run up to the 1998 Data Protection Directive I recall a couple of common confusions and misunderstandings. Nothing like the ridiculously poor and simply incorrect reporting we have for this.

Any large org should have been fully compliant with DPA for years. They have to add extra mechanisms for explicit opt-in or deletion and get a little less time to retrieve full data and can't charge. That doesn't seem to need a "behemoth of effort", but not to say it's necessarily entirely trivial.

In other words they survived DPA with no apparent effect, yet it's >80% of GDPR with the same definitions. No one should be iteratively fumbling toward an unclear target at all. Even reading the UK ICO's old guide to 1998 Data Protection from a few years ago gets you most of the way there including understanding personal data.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#360
post #34

Earlier quoted context omitted.

It doesn't. But if you notice you might be doing something illegal, it's a great first step towards compliance to stop doing _more_ of it. Here, Instapaper is likely not misusing user data, but has to catch up on compliance documentation and small details (e.g. signing data processing agreements with services they use, raising the age limit from 13 to 16, …)

Um, no - The GDPR treats the simple act of storing personal data as 'processing', so turning off the service while still keeping the data resolves nothing. It doesn't even matter if you take the data offline, or temporarily obfuscate it.

You are completely correct that simply blocking access does not make them compliant while they are still storing that data.

But compliance isn't binary. I'm sure the data protection authorities understand the difference between “LOL I'm already noncompliant so I'll just continue business as usual” versus “Working hard to fix this – in the meanwhile, let's prevent covered Subjects from sending us more data until we are prepared to handle it compliantly.”

Post reply on HN