When you have duties of protect user's data and you don't comply with it, I'm done. Months ago I changed to Pocket (Mozilla owned) and I'm ok with that. I missed little stuff like the text render and other minimum things.
Just wanted to say that because protecting user's privacy is also a business model.
The compliance risk is what's dangerous and challenging, not the actual "fixing" of systems. Many people in these comments seem to have no experience with business risk management. They think it's as simple as "just make data deletable." But, the technical side is the easy part. It's the getting sued part that's potentially catastrophic. Even if you "win" you still have spent thousands or tens of thousands defending. And even if you do win, you could be sued again the very next day.
GDPR is more than just deleting data, it's a massive business risk to even companies doing it "right."
You can be sued at essentially anytime for any reason, long before the GDPR. If you're worried about a GDPR lawsuit ruining your company then you're either violating the GDPR or you should have shut down already because the risk was already there.
X is guilty of violating Y because they're worried about being sued for Y. Interesting legal principle.
> or you should have shut down already because the risk was already there
X should shut down because of the risk of being sued for Y? What?
No luck at home with Virgin Media's "ehhh we'll look at IPv6 eventually"
I will never again trust instapaper, independent company or not.
That Instapaper blocks EU users is fishy to say the least. What it means is that they are probably selling user data and cannot keep doing it without informing users of it.
I can’t express how grateful I am for GDPR.
It seems like you'd have to willfully misunderstand the requirements of GDPR to argue that the only reason for non-compliance is that 'they are probably selling user data'.
However, if you can instead imagine that two employees might not want to manually manage GDPR requests for a userbase of two million users (in their free time, no less!) then you might come up with other likely reasons for non-compliance. For example, I wouldn't want to architect a backup system that deletes user info from my backups whenever I receive a GDPR request.
Also I do know what the GDPR requirements are, as I’ve been in charge of GDPR compliance. While we may disagree on how easy or hard it is to implement it, there’s nothing in it that’s not common sense, which shouldn’t need a law for companies to implement.
Tip: if you’re doing backups, encrypt them with the user’s key and on deletion just throw away the key. Not rocket science.
2) Giving (reportedly) one day notice that they are shutting down access is definitely a trust hit. They should have known long before that.
I don't use Instapaper and I'm not in the EU, but those of these points are raised elsewhere in this thread, and both seem valid concerns in terms of "trust" regardless of whether you approve/disapprove of the GDPR.
1. There was no certainty GDPR was going to pass.
2. There was no certainty as to what language would be used in the final document.
3. There was no certainty as to how/when it would be enforced.
By the time GDPR was actually passed, the lead time to enforcement was a slap in the face.
And to be honest, the compliance dates felt like a calculated attack to further the EUs moronic crusade against Facebook and Google, knowing full and well they were unrealistic deadlines.
Collateral damage to Instapaper and others is somehow a worthwhile trade off in the name of burning witches.
So I say, let there be consequences.