If I used Instapaper I'd be filing a complaint with my local DPA about this.
If I used Instapaper I'd be filing a complaint with my local DPA about this.
No, it can something as simple as "we cannot guarantee that all your data is deleted with our current storage system". It would be a lot better if people stop being so alarmist.
The fact of not giving an explanation implies that the real explanation is worse that you would expect.
So if it was just that, they wouldn’t shut down.
Indeed. It's odd looking at discussions about the GDPR on HN.
On the one hand, we have people who argue that compliance isn't really that big a deal if you're not doing anything horribly wrong, most ethical businesses would already be mostly compliant anyway, etc.
On the other hand, we have people who argue that even if that is the case, the length and ambiguity of the regulations and guidance combined with the potential penalties still cause significant overheads and risks, particularly for smaller businesses without dedicated resources to deal with compliance matters.
There is some truth behind both of those positions, I think.
But then I've seen so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped. A noticeable number of people are advocating obviously vexatious use of the new subject rights, not in response to any specific concern or after some unsatisfactory attempt to resolve concerns reasonably, but as a weapon with the clear goal of causing maximum disruption and cost to organisations. I wonder how anyone can think giving so much "legal ammunition" to these people is a good idea.
> so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped
I think it's pretty reasonable to have that premise when those businesses can't tell their users what they did or will do with personal data. No one could even tell whether it's evil or good if you don't show me some details. And sometimes, you assume it's good for me, but I think it's bad for me. Thank you for your good intention but all I want is just an opt-in option, not opt-out, is that so hard to accept? When you drag me into something I don't want, why would I assume you are doing something good? Users being alarmist is not users' fault, data companies' unethical use of data made users react this way. > "we cannot guarantee that all your data is deleted with our current storage system".
If so, just say it. But after that, you may want to explain to me why you can't even take care of my data while claiming you respect it. Did you collect my data then just forget where you store it? If the deletion is that hard, why should users trust such company in the first place?GDPR is an action of defense, not a weapon for invasion. Only predator would think it's a weapon and be afraid. GDPR is not perfect for now, but complaining the ambiguity of it doesn't make internet companies' vague ToS or Privacy Policy clear as crystal. Let's not play double standards here.
I'm quite aware HN is full of people work in data industries, I just have to say it.
But what part of GDPR was it that caused you to have to close off European Union users?
> Starting tomorrow May 24, 2018, access to the Instapaper service will be temporarily unavailable for residents in Europe
You'd think a real company would have talked to a lawyer about this.
GDPR makes no mention of EU citizens or residents.
The 2 main groups it applies to are:
1. activities of an establishment of a controller or a processor in the Union (so if the company is in the EU, ALL processing has to be GDPR compliant regardless of where the user is)
2. processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union (if the company is not in the EU, processing of data of people in the EU - note they just have to be in the EU and not residents or citizens - so if you are from the US and on holiday in the EU and you order pizza delivery to your hotel, that personal data has to be handled in a GDPR compliant way, notwithstanding that the pizza company is probably in group 1 anyway but hopefully you get the point. And the converse of that, if you live in the EU and are on holiday in America and order pizza, that personal data does NOT need to be GDPR compliant as you are not IN the EU)
There are a few other scenarios included too.
Edit: It's worth pointing out that 1 seems to have been completed missed in almost all GDPR coverage I have seen, possibly because most of the coverage has been heavily US centric. If the company is established in the EU, it has to comply with GDPR for ALL users, not just people in the EU. This is why Facebook [1] and others changed their terms so that only EU users have a contract with Facebook Ireland, and everyone else now has a contract with Facebook Inc (US) - previously everyone had a contract with Facebook Ireland.
[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
There's no real difference in "Facebook US" and "Facebook Ireland". The only difference is this methodology skirts the law.
Hopefully, the EU will climb up these jokes of shell companies and rightly smack them down.
EDIT: I've just read through your privacy policy and I wish other companies had a privacy policy as clear, straightforward and detailed.
They probably sell your data or use it to show you ads or targeted content. Who cares?
P.S. I still have access in the UK...
In the end, companies whom don't go through with the GDPR prep and implementation tell me precisely one thing: there's something in their process that makes it hard for them to comply. But not seeing "We're in progress to comply at $date" tells me that they're doing some pretty nefarious stuff. Is that actually the truth? Well, we don't know and can't figure that out.
It's either you comply with the GDPR globally, or for $reasons you don't. I choose to work with GDPR compliant orgs first. I know how my data will be used. And if I buy European IoT hardware, I know its not a spy-station.
Edit: FUCK rate limiting. Here's my response.
Given that I'm an American who has had many accounts exfiltrated or otherwise leaked, I'm frankly sick of companies treating me as a data pinata.
I could go on to cite countless examples, but that dead horse has been beaten time and again. And in many cases, my data is used even without my permission (sending to gmail addresses, facebook ghost profiles, etc).
It might be charitable initially, but I've seen my own impact on bad data practices. It was the wild west... And now the GDPR finally puts a stop to a lot of badness.
I'm not sure there's anything they're doing that's not compliant, but uncertainty about whether that's true might be sufficient for them to consider it too risky to conclude that they are.
I think, if anything, the facts that the law is written is relatively 'simple' language, doesn't specifically mention any technical examples, and is widely expected to be enforced 'spiritually' and not literally, makes it particularly hard for lots of organizations to know with reasonable certainty whether they're in compliance or not.