That Instapaper blocks EU users is fishy to say the least. What it means is that they are probably selling user data and cannot keep doing it without informing users of it.
I can’t express how grateful I am for GDPR.
It seems like you'd have to willfully misunderstand the requirements of GDPR to argue that the only reason for non-compliance is that 'they are probably selling user data'.
However, if you can instead imagine that two employees might not want to manually manage GDPR requests for a userbase of two million users (in their free time, no less!) then you might come up with other likely reasons for non-compliance. For example, I wouldn't want to architect a backup system that deletes user info from my backups whenever I receive a GDPR request.
Also I do know what the GDPR requirements are, as I’ve been in charge of GDPR compliance. While we may disagree on how easy or hard it is to implement it, there’s nothing in it that’s not common sense, which shouldn’t need a law for companies to implement.
Tip: if you’re doing backups, encrypt them with the user’s key and on deletion just throw away the key. Not rocket science.
I will never again trust instapaper, independent company or not.
The compliance risk is what's dangerous and challenging, not the actual "fixing" of systems. Many people in these comments seem to have no experience with business risk management. They think it's as simple as "just make data deletable." But, the technical side is the easy part. It's the getting sued part that's potentially catastrophic. Even if you "win" you still have spent thousands or tens of thousands defending. And even if you do win, you could be sued again the very next day.
GDPR is more than just deleting data, it's a massive business risk to even companies doing it "right."
You can be sued at essentially anytime for any reason, long before the GDPR. If you're worried about a GDPR lawsuit ruining your company then you're either violating the GDPR or you should have shut down already because the risk was already there.
X is guilty of violating Y because they're worried about being sued for Y. Interesting legal principle.
> or you should have shut down already because the risk was already there
X should shut down because of the risk of being sued for Y? What?
No luck at home with Virgin Media's "ehhh we'll look at IPv6 eventually"