6 ms·
Was GDPR so terrifying that they had to sell it off?
by bonaldi 8y ago
Was GDPR so terrifying that they had to sell it off?
- jakobegger 8y agoBackground Info for users outside of Europe: Instapaper has been geoblocked for European users for the last two months.
- rjvbk 8y agoIs it still blocked? It works here, but some geo DBs locate me in Russia because my ISP bought the IP address I use from there recently.
- bumholio 8y agoStill blocked for me. C'mon now, I get it as an emergency measure, I get it when LA Times does it since they aren't interested in European visitors; but this here is just plain lazy.
- deleted 8y ago[deleted]
- chmars 8y agoNobody is really GDPR-ready, however, data privacy law is about being good enough. Yep, there isn’t full compliance ever. Instapaper looks very desperate with its GDPR-lockout of EU users. I guess the EU market is mostly lost …
- adtac 8y agoIf only the EU gave these companies a 2-year headstart to become compliant. Oh wait.
- mherdeg 8y agoYeah it was weird -- I remember very clearly reading about GDPR in early 2016 and then I also remember it appearing in people's development plans in late 2017/early 2018 and seeming like it was a big surprise.
- briandear 8y agoEven if you are 100% compliant, that doesn't protect you from getting sued or having to answer potentially hundreds of thousands of inquiries. The compliance risk is what's dangerous and challenging, not the actual "fixing" of systems. Many people in these comments seem to have no experience with business risk management. They think it's as simple as "just make data deletable." But, the technical side is the easy part. It's the getting sued part that's potentially catastrophic. Even if you "win" you still have spent thousands or tens of thousands defending. And even if you do win, you could be sued again the very next day. GDPR is more than just deleting data, it's a massive business risk to even companies doing it "right."
- flukus 8y ago> Even if you are 100% compliant, that doesn't protect you from getting sued or having to answer potentially hundreds of thousands of inquiries. You can be sued at essentially anytime for any reason, long before the GDPR. If you're worried about a GDPR lawsuit ruining your company then you're either violating the GDPR or you should have shut down already because the risk was already there.
- throwaway37585 8y ago> If you're worried about a GDPR lawsuit ruining your company then you're either violating the GDPR X is guilty of violating Y because they're worried about being sued for Y. Interesting legal principle. > or you should have shut down already because the risk was already there X should shut down because of the risk of being sued for Y? What?
- denzil_correa 8y agoIt redirects to : https://www.instapaper.com/gdpr https://www.instapaper.com/gdpr
- mtmail 8y agoMy home computer (in the center of Europe) is not blocked, but I see that as ip2country mapping issue (in my favor). That would explain the couple of "works for me" reports I've seen on Twitter. Still useless to me because I can't safe URLs at work or on mobile.
- corobo 8y agoIt also works for me at the office because the connection there has native IPv6 No luck at home with Virgin Media's "ehhh we'll look at IPv6 eventually"
- msh 8y agoAnd only gave the users one days notice before locking them out. I will never again trust instapaper, independent company or not.
- bad_user 8y agoPocket (https://getpocket.com https://getpocket.com) isn’t blocked and is now owned by Mozilla. I’m an European and a heavy Pocket user and it had no downtime. That Instapaper blocks EU users is fishy to say the least. What it means is that they are probably selling user data and cannot keep doing it without informing users of it. I can’t express how grateful I am for GDPR.
- Permit 8y ago>What it means is that they are probably selling user data and cannot keep doing it without informing users of it. It seems like you'd have to willfully misunderstand the requirements of GDPR to argue that the only reason for non-compliance is that 'they are probably selling user data'. However, if you can instead imagine that two employees might not want to manually manage GDPR requests for a userbase of two million users (in their free time, no less!) then you might come up with other likely reasons for non-compliance. For example, I wouldn't want to architect a backup system that deletes user info from my backups whenever I receive a GDPR request.
- bad_user 8y agoIf the service can’t delete a couple hundred links, representing private interests I might want to erase, then it’s not a service I’d like to use. Deleting my data is an ability that I want in all the services that I use. Also I do know what the GDPR requirements are, as I’ve been in charge of GDPR compliance. While we may disagree on how easy or hard it is to implement it, there’s nothing in it that’s not common sense, which shouldn’t need a law for companies to implement. Tip: if you’re doing backups, encrypt them with the user’s key and on deletion just throw away the key. Not rocket science.
- bcoates 8y agoI don't think that helps unless I don't back up the user's key too.
- draw_down 8y agoSure, but why should we believe that’s related to the sale?
- clapsclaps 8y agoI was a hardcore Instapaper premium user from the early beginnings. Nothing stopped me for continuing using the app, BUT the GDPR. When you have duties of protect user's data and you don't comply with it, I'm done. Months ago I changed to Pocket (Mozilla owned) and I'm ok with that. I missed little stuff like the text render and other minimum things. Just wanted to say that because protecting user's privacy is also a business model.
- mstolpm 8y agoAt least, they have burned a lot of trust from once loyal EU users. And the GDPR "shutdown" for EU citizens with no given warning was a topic in every major newspaper here, not only computer/internet focused sites and papers.
- joshenders 8y agoBurned a lot of trust? How is this a violation of trust? If a company can’t meet their GDPR obligations under this law, EU citizens have successfully voiced through legislation that they don’t want these businesses operating in the EU. You can’t have your tea and drink it too. This is a consequence.
- ergothus 8y ago1) But why can't they meet their GDPR obligations? Are they doing something they've not been up front about? 2) Giving (reportedly) one day notice that they are shutting down access is definitely a trust hit. They should have known long before that. I don't use Instapaper and I'm not in the EU, but those of these points are raised elsewhere in this thread, and both seem valid concerns in terms of "trust" regardless of whether you approve/disapprove of the GDPR.
- xienze 8y agoIt's a bit of a mischaracterization to label US companies that punt on GDPR with the "well they're obviously shitty companies that wantonly toss around their users's personal information, so good riddance" brush. As someone very deeply involved with a medium-sized company's move to GDPR compliance, I can confirm that there are about a million different legal opinions about what GDPR means and it's causing a LOT of anxiety at all levels of the company. Whether that's right or wrong, that's an experience been echoed all over the country by companies big and small. And that's not even getting into the seismic shift involved in making sure that a "delete me" request is properly distributed to all downstream consumers of data, assuming that we even know who all those groups in the company are. And is this service my app uses GDPR-compliant? It goes on and on. It's not at all surprising to me that some companies are just punting on it because they're terrified that they will somehow get knocked for millions of dollars over something like that.
- msh 8y agoDeleted, was overly negative.
- deleted 8y ago[deleted]