16 ms·
Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue t
by bthdonohue 8y ago
Hey all – Brian from Instapaper here. We worked really hard to try to avoid a service interruption in the EU, but unfortunately we were unable to. We continue to work hard to ensure that the service interruption is as brief as possible.
Let me know if you have any questions...
- deleted 8y ago[deleted]
- Angostura 8y ago> Let me know if you have any questions... It sounds as if you're unwilling to talk about the issues that you're facing. So what can you say? The only reason I can think of that you can't say is that are trying to get some infrastructure suppliers to be compliant and those talks are confidential. Correct?
- bthdonohue 8y agoThe email we sent to EU users (quoted in linked article) has the important details regarding the service interruption in the EU. Additionally, I can say that our privacy policy is concise, clear, and accurate with respect to the types of information we collect and how the data is used: https://www.instapaper.com/privacy https://www.instapaper.com/privacy If you have other specific questions, I will do my best to answer them.
- yoz-y 8y agoWeirdly enough I am an European citizen, haven't received the mail and the service is working. Not complaining, I prefer it this way. Hope you will sort the issues quickly.
- kingosticks 8y agoMe too. And I can see I am definitely subscribed to "account update" emails. I'm not sure how they would decide if I was European or not, can't see a tick box for that in the profile page.
- pkaye 8y agoWhere are you located?
- kingosticks 8y agoThe UK.
- balls187 8y agoThanks to Brexit, there is going to be a similar GDPR law for the UK. Interesting times these are.
- kingosticks 8y agoWhy is brexit relevant?
- balls187 8y agoPost brexit, GDPR will no longer apply to the UK.
- kingosticks 8y agoRight. So without brexit there is this and with brexit there will be something very similar. Thank god for brexit.
- balls187 8y agoJust got back from a road trip throughout Ireland, and occupied Ireland. I wonder what will happen to those two countries post brexit. As I refer to my first comment: interesting times.
- bthdonohue 8y agoThe ban will be IP-based for IPs in EU countries, and it goes into effect at approximately 2PM Pacific Time.
- Angostura 8y agoWell, as The Verge says in the article: 'While we don’t know exactly what’s holding up Instapaper' I'm naturally curious as to what's holding up Instapaper. As you say, your Privacy Policy is very good, other than the disclaimer that says 'we may pass your personal data to others - who knows what they do with it eh?'. I imagine that this is the issue which is holding you up.
- bthdonohue 8y agoThe scope of work for GDPR was underestimated by me, we were not able to complete that work for the deadline on Friday, and this was the required alternative. We are working very hard to minimize the service interruption.
- Dayshine 8y agoHave you received genuine legal advice that recommended that you shut down business instead of continuing to work towards compliance? The agencies that can enforce the GPDR want you to be compliant, not to fine you... If you're actually working towards compliance past evidence shows they won't fine you.
- sdhgaiojfsa 8y agoI've heard this line a lot, but even as a government loving liberal it doesn't sound very compelling to me. The law says, comply or face fines up to 4% of global revenue. It doesn't say, "make a best effort to comply, or face fines up to 4% of global revenue." I'm very reluctant to trust people who can fine me for that much money that they won't do so. This is especially the case because it appears to some of us foreigners that the EU particularly loves to fine foreign companies for large amounts despite what appears, from our perspective, to be a good faith attempt that to comply with the law.
- Tomte 8y agoThe EU regularly fines domestic companies huge amounts in anti-trust enforcement.
- bo1024 8y agoIronically, I am unable to read that page without enabling javascript for a third-party domain (amazonaws.com)...
- mantas 8y agoAre you hard-banning or is it possible to use it over VPN or in some other way? Asking for a friend!
- bthdonohue 8y agoThe ban will be an IP-based ban for IPs from countries in the EU.
- Hamuko 8y agoAnd how hard are you going to be dropping EU users' data?
- deleted 8y ago[deleted]
- jazoom 8y agoI'm curious what an example of a "hard ban" might be?
- mantas 8y agoFreezing account if it seems to be owned by EU citizen? GDPR applies to all EU citizens regardless of their location after all.
- latk 8y agoGDPR applies if (1) the Controller or a Processor is “established” in the EU, or if (2) the Subject is in the EU. Citizenship doesn't matter, and geoblocking is the legally correct solution. As an example: U.S. tourists on a trip to Paris are protected by the GDPR, but a Polish expat in California is not. (See Art. 3 GDPR https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/)
- mantas 8y agoHuh. This is interesting. People were talking it'd be the other way. That EU citizens would be guarded no matter where they're.
- apricot13 8y agomy question - why am I finding out about this on HN and not through the email supposedly sent out?
- kevingrahl 8y agoI did not receive any email notification about this either, just double checked all Spam folders..
- princekolt 8y agoYou know that you're still liable for European customer's data, even if you're offline, right? Going offline won't change anything. You can't effectively grab the database and run away.
- dmix 8y agoIt still seems like the safest option given the massive risk this legislation is exposing companies. Especially low margin per user businesses like Instapaper. From The Verge: > because it’s not entirely clear right now what information residents will request, what format that information needs to be in, how to locate it and package it, and whether new infrastructure needs to be created to manage this request pipeline. So in the meantime they can at least stop the flow of new data from the EU into their system until they are 'compliant' and have systems in place to deal with the existing large amount of EU users/data they already have. It makes sense to me to be cautious here, plus it has the dual benefit of drawing attention to the real costs/risks the bill has on smaller firms without teams of lawyers and internal human resources (developers, CSRs) to deal with the new obligations imposed on them.
- Hamuko 8y ago>It still seems like the safest option given the massive risk this legislation is exposing companies. The safest option was actually to comply with the GDPR during the two years it has been in force now. I refuse to believe that the changes required were impossible to perform in two years. I'd love to know when exactly did Instapaper start looking into the GDPR.
- dmix 8y agoThe founder has said that he underestimated the amount of work it was going to take. Anyone who has ever worked on software knows how this stuff happens. You don't truly know how long something is going to take until you dig into the hairy details of implementation. Plus there are still tons of unknown variables at play with GDPR... even among companies who did spend sufficient time beforehand, as I quoted from the article above. So additionally, the non-obvious requirements further makes the underestimation make sense.
- danpalmer 8y agoI feel like you’re making a bigger deal out of this than necessary, unless you’re doing some shady stuff with our data. From what I can tell from various legal advice that I’ve read, as long as you’re working on implementing the changes, and have been following security best practices, nothing really changes on May 25th, and you’ll be able to take your time to become fully compliant, as long as you can demonstrate that’s what’s happening. In other words, good faith and best practice will get you far. Your current reaction seems like a huge and unnecessary over reaction that is just harming your users, and unlikely to have any material impact to your legal risk.
- pembrook 8y agoInstapaper is owned by Pinterest. Pinterest is a large high profile company with millions of European users and would be a potential target of regulators looking to establish precedents of enforcement with a big name. I highly doubt this decision was made lightly and was probably informed by actual legal professionals with knowledge of the regulators in question and not the 3rd party opinion of some guy on the internet who "feels like its not that big of a deal."
- jacquesm 8y agoBut he's spot on about contacting the regulators because they already know they won't be in compliance. Now would be a good time to do just that, and if the actual legal professionals thought it was a good idea to ban EU citizens but keep their data then maybe they should get better lawyers because that certainly won't work.
- deleted 8y ago[deleted]
- Normal_gaussian 8y agohmmm... If I had an instapaper account it would be interesting to submit a GDPR request tomorrow, and see what kind of reply I got. Now I don't, but I'm sure there are plenty of other interested people around.
- jacquesm 8y agoI'm sorry, I don't buy it. (1) you still hold the data, you are still required to comply with the law and cutting off access does not change that one bit. (2) the period for a response is long enough that once you would receive requests you could handle them in time even if you processed them manually. (3) you have been - or should have been - aware of all this for a very long time, either you failed at estimating the impact of the law or you do not know what you have or you changed strategies internally recently and now you're not going to be ready in time because you started way too late. So in all, all you've managed to achieve with this action is to get the spotlight on you, and it is a 100% certainty that at least Instapaper will be solidly violating the GDPR come tomorrow. If I were in your shoes I would use my designated representative to contact the authorities for guidance after explaining in detail what the problem is before I would let my end users pay the price for my own incompetence.
- guelo 8y agoI don't know if (1) is true but the data was collected under previous laws. In my opinion laws like this should not be retroactive. Retroactive laws, especially when affecting billions of dollars of commerce, are unfair and draconian.
- jacquesm 8y agoThe law has been on the books for two years, it just wasn't enforced and for a long time before that there was another law with much the same effect. So even if the data was collected under previous laws there is not much that would convince me that denying the users access to their data or to the legally mandated data life-cycle features is the right thing to do. In fact that attitude goes exactly against what the law is trying to achieve in the first place.
- fiter 8y ago> In fact that attitude goes exactly against what the law is trying to achieve in the first place. I think this is an important realization for any regulator.
- 8y ago
- joering2 8y agoDon't feel bad. The law is ridiculous and most startups cannot even afford salary for another programmer not to mention GDPR-law compliance officer. Hopefully if enough services get interrupted, bureaucrats at EU will rethink the law.
- sveme 8y agoSo which part of the law is ridiculous? Disclaimer: I believe the principles that are applied within the law, data autonomy, data ownership, usage-binding of data etc., are sound. And just because people have aggregated any data on people that they could get to better manipulate them into buying crap for so long that it‘s hard to change track today, doesn‘t mean it‘s wrong for lawmakers to enforce parting ways with the past.
- zerostar07 8y ago- IPs are personal private infromation - You need opt-in consent for all (ad) cookies, including non-tracking ones. Basically,advertising is optional in EU sites as of today. - I could argue the right to download your data is superfluous, mostly because it creates potential holes for data leaks/phishing etc. The law is confusing "privacy" with "invisibility".
- merinowool 8y agoThen you'll have all sorts of disputes for example someone could claim their cat stepped on a touchscreen and consented without the user knowledge or someone consented whilst being completely drunk - such consent is not valid. That means potentially companies are keeping the data illegally thinking they comply.
- deleted 8y ago[deleted]
- zerostar07 8y agoi don't follow, do you mean that's a possible scenario? That's the last thing you need to worry about yet. I expect first random emails from hackers demanding coins for 'not reporting you' in the first awkward month.
- grey-area 8y agoLet me know if you have any questions... Which parts of GDPR do you think you're in violation of? Why do you think removing access for users currently in the EU puts you in the clear legally? What are you doing with European users data currently, have you deleted it all? A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy, just by tightening up how they hold data, and making sure they are clear on permissions with users. Are you sure you have good legal advice on this?
- orangecat 8y agoWhich parts of GDPR do you think you're in violation of? Answering those questions in a public forum would be extremely foolish. ("Do you know why I pulled you over?") A lot of other companies have navigated the changes to the law without significant changes to their service or privacy policy And how many of them are actually in compliance?
- grey-area 8y agoAnswering those questions in a public forum would be extremely foolish Perhaps asking for questions was foolish? And how many of them are actually in compliance? If you're not in the business of selling customer data to third parties, it's not very hard to comply, just requires some discipline on how data is stored and who it is shared with, and a point of contact for enquiries about data.
- mtaksrud 8y agoMaybe something like this will be of help to you https://ico.org.uk/for-organisations/resources-and-support/data-protection-self-assessment/ https://ico.org.uk/for-organisations/resources-and-support/d... ?
- anonymouz 8y agoDid you delete all EU users' data?
- icedchai 8y agoYou could've just done absolutely nothing. That would've avoided service disruption.
- redwood 8y agoExtremely bizarre move frankly. I assume this was some kind or vigilante decision rather than based on recommendation of counsel.
- Animats 8y agoYou had two years to get ready. Why wasn't this announced months ago.
- yani 8y agoEpic fail