Live data from Hacker News

GDPR and Google Analytics

adactio.com

51–60 of 130 posts

Re: GDPR and Google Analytics

#51
post #10

My problem with the GDPR is the EU can't even be bothered to tell us what it is before the effective date. And the GDPR itself is quite vague; lots of balancing tests and blah blah with very little guidelines on what those mean in practice. So where do the guidelines come from? Funny you should ask. Consider the ICO -- the UK privacy commission -- has been promising final GDPR guidance for perhaps half a year now, an…

While I largely agree with you, for the most part enough guidance has been available that many companies have been preparing to handle GDPR. They should have done a far, far better job with this but it's not entirely a "We won't know anything until late Feb" kind of thing.

That's true, however, there's no fixed limit to the possible distance between draft and final guidance.

Say you have a large marketing database and you're trying to figure out the nuances of consent. Or you are a large bank and run on a fidgety mix of consent and legitimate interests. Three months is nowhere near enough time to get everything finished.

Re: GDPR and Google Analytics

#52

Earlier quoted context omitted.

Indeed. The idea that a country would zealously protect it's citizens' rights is practically unheard of these days, but that's what's starting to happen. GDPR is a great example, another one was Canada pushing a Right To Be Forgotten ruling worldwide as well. It's a statement that someone's private data and intellectual property is theirs. You aren't free to steal it just because you're in another country. Google and…

>It's a statement that someone's private data and intellectual property is theirs Private data is data you don't share. Under some very limited circumstances, you might entrust private data to a third party for safekeeping, i.e. Dropbox, Google Photos, iCloud Drive, and it's important that they not leak or abuse it. But that's only a tiny portion of what the GDPR is about. It concerns records of your interactions wit…

You are anthropomorphizing companies here, and I think it's a pretty poor analogy. Corporations do not have a memory, they have records, and those records comprise the personal data of everyone who encounters them; data those companies don't own. You seem to be characterizing GDPR as unfair towards the corporate end of the interaction, but that ignores the massive power differential that currently exists.

Corporations have incredible power compared to the individual, and before GDPR, it was commonplace for services to require unreasonable privacy violations: And consumers had to either accept it, or be cut off. (In many cases, the companies doing this have monopolies, making this even more problematic.)

Realistically, this is not going to impact small companies a lot. This is about big ad and tech companies, and giving citizens some minor semblance of tools to resist them.

Re: GDPR and Google Analytics

#53
post #43

Earlier quoted context omitted.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website." The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.

Against small companies with almost no footprint in EU maybe. But against huge multinational corporations that want access to the 500m+ people market they sure can.

Re: GDPR and Google Analytics

#54
post #29

Earlier quoted context omitted.

A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

If I'm a US company, with a non-GDPR compliant website, and a visitor from the EU visits my site, under what jurisdiction does the EU have to reprimand me? Or will my site just be blocked in the EU?

Re: GDPR and Google Analytics

#55
post #46
post #43

Earlier quoted context omitted.

> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website." The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.

Looking at the EUs antitrust fine for Google - https://www.google.ch/amp/s/www.bloomberg.com/amp/news/artic... it's clear it does have the ability. The message is "you want to profit from EU citizens? You follow the rules"

No, you're confused. Google has a physical presence and business partners in Europe; I do not. (Profiting from EU citizens is beside the point.)

Re: GDPR and Google Analytics

#56
post #34
post #21

Edit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen o…

> I'm going to block access to my services to anyone based in Europe... I'm tired of governments that I don't care about expect me to follow some nonsense I have no part of under the guise of compliance. Ever been on a plane? ... Used a cellphone outside your own borders? ... Eaten a beautifully ripened imported cheese along with a stunning imported wine? Put your money where your mouth is: boycott all benefits of tr…

Sorry, wrong example.

When I take a plane to some country I will follow their rules, protocols, yes.

But imagine, I had a museum that can be accessed world wide, instantly and some guy from a specific country/region had a problem with one of my showcases in the museum, do you expect me to alter my museum for this guy and his groupies so they'll be happy?

Re: GDPR and Google Analytics

#57
post #53
post #43

Earlier quoted context omitted.

> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website." The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.

Against small companies with almost no footprint in EU maybe. But against huge multinational corporations that want access to the 500m+ people market they sure can.

Exactly, that's the distinction.

Re: GDPR and Google Analytics

#58

Earlier quoted context omitted.

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

>. You can get reasonably good statistics by just using a local log analyzer that does not upload your visitor's data to an analytics/ad company. 1) Has your user consented to your webserver's access logging? 2) Has your user consented to the use of access log entries about them for analytical purposes? 3) How will you delete the access log entries corresponding to a user upon request? 4) How will you provide a user…

from what i catched talking to our lawyer, there are other levels of consent than explicit by the user explicit consent that might be revoked, in this case.

1. concerns of security and quality of service (gathering logs with full ip addresses is allowed for a reasonable time, a few days for example).

2. you don't need to delete the logs if you use them for this specific purpose only.

3. for analytical purpose it is enough to use pseudonomic identifiers, in case of ip address zero out the last part and you are fine.

4. using Piwik or your own cookies? Suddenly its not a third party cookie anymore and you are more free to do things.

The problems for operators begin when they are handing this over to a third party.

Re: GDPR and Google Analytics

#59

Earlier quoted context omitted.

I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."

If I'm a US company, with a non-GDPR compliant website, and a visitor from the EU visits my site, under what jurisdiction does the EU have to reprimand me? Or will my site just be blocked in the EU?

It's unlikely foreign sites catered to foreign viewers would be impacted. When I buy something from a site that only sells in another country's currency, I know I'm probably going outside my own nation's protections a bit.

But if you're a company specifically soliciting EU customers, and especially if you have a presence in the EU physically, expect to have issues if you're collecting data on them without consent.

Bear in mind, the US will extradite people for committing crimes against US entities who live fully within other countries. Presumably if the act is bad enough... that sort of thing starts to play in. (Seriously, if the EU tried to extradite Sundar Pichai... that'd be something, wouldn't it?) The crime has to be befitting such effort though. One EU citizen's data sweeped up in your Google Analytics data does not make you worthy of a legal case. Do it several million times... maybe.

tl;dr: If you're an average company not operating in or marketing to the EU, this doesn't affect you. If you're the size it's likely to be an issue for you, you're likely big enough to handle the additional requirements and do fine.

Re: GDPR and Google Analytics

#60
post #11

Earlier quoted context omitted.

It's not their money, it's if you store or process personal data about individuals in the European Economic Area (slightly larger than the EU). If you're running a Chinese site aimed at Chinese you're good. If you're running an Indonesian site aimed at Germans you need to honour the GDPR.

Probably... not really? Maybe? For starters, if you don't take payment and aren't in the EU, EU enforcement power is going to be extraordinarily limited. And even if you do require payment, if you don't have a physical nexus in the EU, it's unclear what exactly the EU can do? I think the GDPR was basically aimed at some of the scummier adtech practices and businesses like Facebook, and for those, it will be very enfo…

> And even if you do require payment, if you don't have a physical nexus in the EU, it's unclear what exactly the EU can do?

You need an EU VAT ID to accepts payments from EU citizens. So they will revoke that and then you can't accept payments from EU.

Post reply on HN