Live data from Hacker News

Instapaper is temporarily shutting off access for European users due to GDPR

theverge.com

371–380 of 388 posts

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#371
post #337

Earlier quoted context omitted.

Here's the law. Notice that there's a bunch of stuff taken into account before setting the fines. https://gdpr-info.eu/art-83-gdpr/ Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/arti…

There is no caselaw on the GDPR and no way to predict how fines will be levied. You can speculate how it will be enforced (as you have), but businesses tend to avoid speculation when assessing risk.

> You can speculate how [GDPR] will be enforced (as you have)

Since the GDPR will be enforced in the UK by ICO, there's very little speculation in the parent post.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#372

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

Instapaper isn’t based in the eu. The eu can’t prosecute individuals on foreign soil. I mean they can try, but good luck getting anyone to show up

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#373

Earlier quoted context omitted.

What would the regulators do? Block the service? But that is one part which is confusing to me, from the UK ICO: The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU. Additionally, the GDPR does not apply to actions taken before and during the transition period (which ends now). In thi…

If you continue to hold data from EU residents, it’s somewhat likely that the GDPR applies, or that a court will decide it does some way down the line. If you employed a competent lawyer for about an hour they’d ask you why you’re storing that data if you’re never going to use it again, given the risks.

Holding the data or not is irrelevant, the tricky part is compliance.

If the GDPR applies to you, you need to hire a DPO based in Europe, as well as having a EU contact that will be responsible for any fees that you incur.

If you did business in the EU but no longer does, do you now have to hire a DPO in the EU and have a local contact responsible for any liabilities?

Managing the data is the easy part.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#375

Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible. Let me know if you have any questions...

You know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.

Just because a law is written to apply to effectively the whole planet, doesn't mean it can be enforced as such. I just don't see the current US administration complying with a EU charge against one of its companies that did go the blocking route, let alone any of the shadier countries that host companies in violation

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#376

Earlier quoted context omitted.

I suppose for most thinking rationally, it seems like "stop doing business in the EU" is different than "make it like you've never done business in the EU". Taken to its conclusion, which Instapaper surely won't, it's not going to be easy to punish a business that has cut ties with the EU because of what they collected before. Granted it appears that with the law, like its predecessors, practicality of reasonable enf…

The rational approach to legislation is to make a (timely) effort to comply. When you're told the highway near your house has a new speedlimit you can either obey the speed limit, use a detour (which will still be slower on account of it being longer) or you can take your car off the road in huff. The first one is the only solution that makes sense.

If we're going with these analogies, there are other approaches if you disagree with the speed limit. You might protest the speed limit if you lived there (hopefully without being berated while you do so) or if you don't live there you might avoid the place with unreasonable speed limits.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#377

Earlier quoted context omitted.

Google Analytics isn't usually used as a revenue stream, but instead for analytics and telemetry.

One motivation for doing analytics/telemetry is being able to set optimal price points, etc. For example, i f 80% of your user population uses your app daily, it is more attractive to switch to a subscription model than if most people use it very irregularly.

Oh my god, that sounds like capitalism.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#378

Earlier quoted context omitted.

There is no caselaw on the GDPR and no way to predict how fines will be levied. You can speculate how it will be enforced (as you have), but businesses tend to avoid speculation when assessing risk.

> You can speculate how [GDPR] will be enforced (as you have) Since the GDPR will be enforced in the UK by ICO, there's very little speculation in the parent post.

The parent post is entirely speculation. It is speculation about how a new law will be enforced. It’s not even very robust speculation since after March 2019, the GDPR will not be enforced by any organisation in the UK.

Re: Instapaper is temporarily shutting off access for European users due to GDPR

#380
post #271
post #256

Earlier quoted context omitted.

> Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". No they absolutely do not.

Really? "effective" = large amount, so company won't do it again, "proportionate" = relative to revenue, "dissuasive" = make them an example so no one else will dare. I bet you are going to tell me proportionate somehow makes it all better, but for companies that make money this way, the amount of money they make this way in proportion to their income is basically all of it. So you can bet regulators will go for the…

> "effective" = large amount, so company won't do it again

Generally true, but it should be read with proportionate as meaning as large as necessary to be effective -- if a warning is sufficient to ensure compliance, then the effective clause suggests a fine is NOT warranted.

> "proportionate" = relative to revenue

_Absolutely_ not - proportionate to the _infringement_. There is no other reading that makes sense here.

> "dissuasive" = make them an example so no one else will dare.

Dissuasive also encompasses encouraging companies to cooperate with regulators and make a best effort to comply. If they are going to get the maximum fine for a minor breach, even if they made a full effort to comply and merely overlooked something, they are _not_ dissuaded from ignoring the GDPR in its entirety.

> So you can bet regulators will go for the full amount.

Certainly not. Going for the full amount, regardless of the circumstances and ignoring the factors they MUST consider, is going to result in the fines being overturned by the courts, which undermines their position, doesn't fulfill the purpose of the fine (if the company successfully challenges it), and doesn't fulfill the aims of the GDPR. Ignoring the law to go for the maximum fine would be a terrible decision for a regulator to make, and you can look at the history of enforcement of the DPD to see that regulators _don't_ generally go for the maximum fine.

Post reply on HN