3 ms·
How does shutting down fix GDPR issues? Does all user data magically disappear by shutting down?
by rollulus 8y ago
How does shutting down fix GDPR issues? Does all user data magically disappear by shutting down?
- latk 8y agoIt doesn't. But if you notice you might be doing something illegal, it's a great first step towards compliance to stop doing _more_ of it. Here, Instapaper is likely not misusing user data, but has to catch up on compliance documentation and small details (e.g. signing data processing agreements with services they use, raising the age limit from 13 to 16, …)
- linker3000 8y agoUm, no - The GDPR treats the simple act of storing personal data as 'processing', so turning off the service while still keeping the data resolves nothing. It doesn't even matter if you take the data offline, or temporarily obfuscate it.
- taysic 8y agoBut what would you be violating exactly? How could those violations be detected? It seems if the EU is so generous in not wanting to fine and you and walking you through the process, then shutting down would look like a reasonable thing to do if you are still attempting to comply.
- Hamuko 8y ago>How could those violations be detected? You can tip off the regulators if you believe that there is a violation and they will then investigate it. Instapaper is giving a pretty good reason to be suspicious.
- taysic 8y agoWhat would be in violation exactly? Not clear on this. How would regulators investigate? Do they require full access to your database/ backend?
- latk 8y agoYou are completely correct that simply blocking access does not make them compliant while they are still storing that data. But compliance isn't binary. I'm sure the data protection authorities understand the difference between “LOL I'm already noncompliant so I'll just continue business as usual” versus “Working hard to fix this – in the meanwhile, let's prevent covered Subjects from sending us more data until we are prepared to handle it compliantly.”