Live data from Hacker News

Ask HN: Has anyone leveraged GDPR to overturn automated bans?

news.ycombinator.com

51–60 of 77 posts

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#51
post #47

Earlier quoted context omitted.

Same goes the for 'cookie law'. A significant fraction of the web is in violation. The lack of enforcement sends the message that non-compliance is acceptable, so it's become the norm.

What cookie law? The one that states I have to make my website worse for everybody to use? Yeah, I definitely ignore that law, and I wish 100% of website owners did. It feels to me like 99% of them follow it.

There is no law stating you have to make your website worse.

Making your website worse is just a what certain analytics providers want you to do so you keep paying for their services.

https://github.blog/2020-12-17-no-cookie-for-you/

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#52

Earlier quoted context omitted.

I don't disagree that there's been a few successful fines, but by that logic I should quit my job tomorrow because I happened to get lucky at the casino a couple times. GDPR enforcement has been extremely lacking as demonstrated by the web being littered by non-compliant data processing consent forms. A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of ser…

> A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of services currently don't comply (including big names like Google or Facebook) and entire businesses such as TrustArc have been built on providing non-compliant consent forms as a service. Nothing in the text of the GDPR, nor of any regulatory guidance that I've seen, suggests that the "decline" option h…

The following is from the ICO, which I don't think has any reason to interpret the guidelines any stronger than what they have to, since they aren't willing to enforce any of it anyway:

https://ico.org.uk/for-organisations/guide-to-data-protectio... :

> Consent means offering individuals real choice and control. Genuine consent should put individuals in charge, build trust and engagement, and enhance your reputation.

> Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent.

> Be specific and ‘granular’ so that you get separate consent for separate things. Vague or blanket consent is not enough.

> Make it easy for people to withdraw consent and tell them how.

https://ico.org.uk/for-organisations/guide-to-data-protectio... :

> What is an unambiguous indication (by statement or clear affirmative action)?

> It must be obvious that the individual has consented, and what they have consented to. This requires more than just a confirmation that they have read terms and conditions – there must be a clear signal that they agree. If there is any room for doubt, it is not valid consent. [emphasis mine]

At this point you could already argue that unless the decline option is as prominent (if not more) than the accept option then the user didn't actually intend to consent and just couldn't figure out how to decline.

> Consent should be given by a clear affirmative act [...] Silence, pre-ticked boxes or inactivity should not therefore constitute consent.

> The key point is that all consent must be opt-in consent, ie a positive action or indication – there is no such thing as ‘opt-out consent’. Failure to opt out is not consent as it does not involve a clear affirmative act. You may not rely on silence, inactivity, default settings, pre-ticked boxes or your general terms and conditions, or seek to take advantage of inertia, inattention or default bias in any other way. All of these methods also involve ambiguity – and for consent to be valid it must be both unambiguous and affirmative. It must be clear that the individual deliberately and actively chose to consent. [emphasis mine]

Seems like that's cut and clear.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#53

We seriously need an Internet Bill of [Personal] Rights and get it into law and use it against the FAANGs. Europe at least seems to be trying, along with California sometimes.

Agreed. We're overdue for a Magna Carta for our new era, lest we be absolutely ruled by the ever-growing myriad of algorithms and models that govern our participation in society and economy.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#54
post #48

Earlier quoted context omitted.

> Which I guess means my question is why don’t you believe them and how likely is it that they are lying when they claim thy appeals are reviewed by a human? Why would we believe them? It's Google's responsibility to prove their assertion, versus regulators taking them for their (not so good) word. The default should be the assumption that the corporation is being dishonest.

If you’re taking them (or anyone else) to court, isn’t the burden of proof on you?

Highly dependent on the law or regulation in question.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#55
post #47

Earlier quoted context omitted.

Same goes the for 'cookie law'. A significant fraction of the web is in violation. The lack of enforcement sends the message that non-compliance is acceptable, so it's become the norm.

What cookie law? The one that states I have to make my website worse for everybody to use? Yeah, I definitely ignore that law, and I wish 100% of website owners did. It feels to me like 99% of them follow it.

I, personally, like it more when I can say "no, don't track me".

It's only worse for the user when the cookie notification is blocking the content, there is no "no, I don't agree" button or clicking it means clicking trough 100 extra toggles.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#56
post #37
post #8

Earlier quoted context omitted.

I don’t see how you get from Google’s statement “Was taken down for legal reasons and cannot be appealed“ to “no human was involved” .

Because once a human did get involved, via noise from here and twitter, Google admitted that there was a problem. Also, just the absurdity that a human would review a file containing only "1" and decide the decision to flag it was correct. https://twitter.com/googledrive/status/1486038872928792576

What's interesting is there's another user there that followed up 2 days after the tweet noting that other numbers weren't fixed. But this is ignored.

Problems shouldn't get fixed just because they got enough likes and reshares on Twitter.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#57
getting anything sensitive data out of large companies with the GDPR seems to be impossible unless you want to resort to lawyers

I was trying to get my matchmaking data out of Activision Blizzard and they flat out refused, saying my data was their property

their exact response was:

> "the information requested are trade secret and/or intellectual property needed to preserve our game integrity"

I complained to the regulator, who agreed with my assessment, but to enforce it I'd have to go to court

seems the GDPR is basically useless

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#58

Earlier quoted context omitted.

> A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of services currently don't comply (including big names like Google or Facebook) and entire businesses such as TrustArc have been built on providing non-compliant consent forms as a service. Nothing in the text of the GDPR, nor of any regulatory guidance that I've seen, suggests that the "decline" option h…

The following is from the ICO, which I don't think has any reason to interpret the guidelines any stronger than what they have to, since they aren't willing to enforce any of it anyway: https://ico.org.uk/for-organisations/guide-to-data-protectio... : > Consent means offering individuals real choice and control. Genuine consent should put individuals in charge, build trust and engagement, and enhance your reputation.…

What I would call "cut and clear" would be a specific description of how prominent the decline button must be. "Inertia, inattention, or default bias" is a very nonspecific phrase, and even if it does include UI, it's not obvious why the implied standard would be "as prominent" rather than, say, 50% as prominent.

Don't get me wrong, I'd really like companies to design this way on principles of general user friendliness, but I don't see much evidence that anyone involved in creating the GDPR intended to require it.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#59
post #57

getting anything sensitive data out of large companies with the GDPR seems to be impossible unless you want to resort to lawyers I was trying to get my matchmaking data out of Activision Blizzard and they flat out refused, saying my data was their property their exact response was: > "the information requested are trade secret and/or intellectual property needed to preserve our game integrity" I complained to the reg…

I hear people saying laws that require police reports, police enforcement or interactions with the court are useless. For people like yourself who feel this way, what alternatives do you propose?

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#60
post #4

The data subject shall have the right not to be subject to a decision based solely on automated processing Lots of leeway for FAANG/BigCo management to wriggle out of that one. "Sure, Jones in Legal gets an email notification every time an account is banned and has the option to review it." I can only imagine the lobbying and "negotiation" that takes place to have legislators water down the requirement for real human…

I doubt that would hold legally speaking because that would essentially be purely automated data processing.
Post reply on HN