Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

111–120 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#111
post #73

Earlier quoted context omitted.

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

It raises interesting question. What if some publisher, say, newspaper, can show highly targeted ads for $3 CPM, or generic ads for $1 CPM. Can such publisher claim that collecting data is strictly necessary to provide the service? With threefold difference in ad revenue, that could be actually the case.

Good question. This would be an appeal to "legitimate interest" as a legal basis for collecting personal data. GDPR explicitly states that if the legitimate interest is direct marketing, then the user may always object to such processing, and this right must be clearly indicated.

[1] https://gdpr-info.eu/art-21-gdpr/

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#112
post #75
post #53

Earlier quoted context omitted.

If I have an IRC service that shows quotes from people and has 'last seen' functionality is that covered by GDPR? Some of the users are from EU countries, does that mean those features need to be turned off or have some sort of acceptance exchange with users? Would filtering out EU IP ranges be sufficient, or does this also apply to EU citizens traveling outside of the EU? The referenced page says that asking users t…

IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.

Article 3, "Territorial Scope":

---- begin quote ----

(1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

(2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

 a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

 b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

---- end quote ----

Based on this, it looks like for GDPR to apply to an establishment in regard to a particular person, at least one of those two parties must be in the Union. An EU citizen traveling outside the Union dealing with an establishment that is not in the Union appears to not be covered.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#114

Does this mean every site will need to ask permission for Google Analytics?

A very good question which I don't know the answer. But what I do know is that since IP addresses are considered personal information, then you can tell the GA script to anonymise it.

https://support.google.com/analytics/answer/2763052?hl=en

Of course, that doesn't stop that IP address becoming aware to the GA servers, but they should stop it being used further down the line.

I suspect it's similar to using a CDN where the IP address again is passed to a third party.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#115

Earlier quoted context omitted.

Ok, let's say I, as a publisher, don't set user cookie if user hasn't registred/logged in, and don't store IP in logs, and don't do browser fingerprinting. Why can't I load some 3rd party tools? What author is claiming, essentially, that in a mere 2 month from now, you can sue almost any European publisher for data privacy breach. Outrageous claim require outrageous proof.

> Why can't I load some 3rd party tools? You can, you just need assurance that they're also GDPR compliant if you want to be GDPR compliant. If the third-party violates GDPR, but requires your website to run on (e.g. third-party JS, other types of beacons), I think judges are going to have a dim view on that, and so you can't simply claim that it's them, not you. (There may be mitigations, e.g. if you have a contract…

Also user can require the service to remove his personal information and that means that service provider has to notify services he uses to stop using and remove that PI.

How will this work with Google Analytics and things like that? Will random e-shop be required to notify Google to stop using/delete PI for random persons upon request?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#116
post #101
post #73

Earlier quoted context omitted.

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

How is "strictly" defined? I'm going to guess it's define as "the magistrate knows it when it sees it", so take to be both "don't use the most egregious interpretation", and "don't be a populist punching bad that governments can make hay out of attacking".

I assume it's "you cannot provide said service without having said data".

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#117
post #101
post #73

Earlier quoted context omitted.

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

How is "strictly" defined? I'm going to guess it's define as "the magistrate knows it when it sees it", so take to be both "don't use the most egregious interpretation", and "don't be a populist punching bad that governments can make hay out of attacking".

Any data you collect that you do not unambiguously need to provide the service would be an appeal for "legitimate interest" as a legal basis for collecting it. There are a number of things GDPR writes about it and of course you cannot be sure how this will play out in practice, but the main points are:

* it must be reasonable from the user's perspective

* there must be alternative; you cannot achieve the goal (your "legitimate interest") without it

* it must be balanced with the rights of the user, and not infringe on their freedom or fundamental rights

* if your "legitimate interest" is direct marketing, the user can always object, and you are required to actively inform the user of this right

See also [1]

[1] https://gdpr-info.eu/recitals/no-47/

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#118

Would this mean for example I can’t load the Facebook pixel without consent?

Yes. Facebook's terms and conditions explicitly mention that you have to do this. https://developers.facebook.com/policy/?locale=en_us

> 12. In jurisdictions that require informed consent for the storing and accessing of cookies or other information on an end user’s device (such as the European Union), ensure, in a verifiable manner, that an end user provides the necessary consent before you use Facebook technologies that enable us to store and access cookies or other information on the end user’s device. For suggestions on implementing consent mechanisms, visit Facebook’s Cookie Consent Guide for Sites and Apps.

13. Obtain consent from people before you give us information that you independently collected from them.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#119
post #6
post #3

> Today, for instance, we see that a majority of people who install an ad blocker don't actually do it to block ads (that's just an added bonus). They are actually doing it to block tracking. Is there any evidence for this at all?

No, and I would say that statement is laughably wrong. Users install ad blockers to prevent annoying stupid things from monopolizing their time and space. Telling a person "if you install this they'll stop tracking you in some abstract way" is way less effective than "install this and you wont have to wait to watch youtube videos."

> install this and you wont have to wait to watch youtube videos

Exactly the reason I installed an ad blocker. If YouTube had released their Red subscription in the UK I might never have installed the blocker (actually probably would have eventually, but later than I did)

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#120
post #3

> Today, for instance, we see that a majority of people who install an ad blocker don't actually do it to block ads (that's just an added bonus). They are actually doing it to block tracking. Is there any evidence for this at all?

I'd completely reverse the phrase: "majority of people who install an ad blocker do it to block ads. Blocking trackers is just an added bonus".
Post reply on HN