Live data from Hacker News

GDPR will pop the adtech bubble

blogs.harvard.edu

141–150 of 454 posts

Re: GDPR will pop the adtech bubble

#141
post #97
post #11

Earlier quoted context omitted.

I don't see how self-hosting has anything to do with it honestly. This is about tracking people without their consent. It's about preserving rights of individuals. Self hosting is no more or less acceptable than third party hosting. It's not a technical issue.

> It's about preserving rights of individuals. I'm not sticking up for all the big data perverts, but what about an individuals right to speak freely and disclose information they have observed/recorded? The 'right to be forgotten' seems at odds with everyone else's right to remember and disclose occurances.

That is not the case. The "right to be forgotten" is not absolute. There are lawful bases for processing under which the right to be forgotten does not apply.

Go read GDPR article 17.3, it's easy to read. A few things for which the right to forgotten does not apply:

- exercising the right of freedom of expression and information

- for compliance with a legal obligation (e.g. keeping records for tax reporting)

- for public interest reasons related to health, science, historical research

Seriously, there is too much FUD about the GDPR.

Re: GDPR will pop the adtech bubble

#142

Earlier quoted context omitted.

>Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? Yes the EU invented a new right for its citizens which is the prerogative of the EU because of their bastardized idea of what constitutes privacy. Privacy is a basic human right, that much is obvious. There is no human right however to…

> There is no human right however to be forgotten I don’t see the connection between what’s a right and what’s a law here. If a majority of people want something they tell their lawmakers to turn it into law. It’s not a fundamental human right it’s a law like any other.

The distinction is that violating someone's rights is almost always unethical. Breaking the law is less so.

Re: GDPR will pop the adtech bubble

#143
post #103
post #2

And that’s on top of the main problem: tracking people without their knowledge, approval or a court order is just flat-out wrong. The fact that it can be done is no excuse. Nor is the monstrous sum of money made by it. I use Piwik ( https://github.com/matomo-org/matomo ) and track visitors without their knowledge or consent, because I need analytics. Piwik is also configured to respect the "Do not track" header, so o…

Piwik has several blog post about this very topic, for example: https://matomo.org/blog/2017/09/gdpr-potential-consequences-... You can disable the tracking parts in Piwik, or you can assume a legal stance under one of the 6 exceptions like "Legitimate interests" ( https://matomo.org/blog/2018/04/lawful-basis-for-processing-... ).

Thanks, that's very interesting! I wasn't aware that IP address is considered personal data under GDPR... That seems exploitable...

Re: GDPR will pop the adtech bubble

#144

Earlier quoted context omitted.

You shouldn't need to keep any personal information on your visitors to get meaningful data.

How can AB testing work without storing personally identifiable information?

AB testing doesn't require personally identifiable information.

Re: GDPR will pop the adtech bubble

#145

Earlier quoted context omitted.

> IS there a good reason why you can't analyze the page you put your ad in and decide what category on ads will fit, so on tech pages put tech related ads. There isn't and this is what many people do. But that isn't the argument is it? Can you tell me why observing what people do on my website is unethical and why it should be made illegal? Also can you explain why information that is placed on my server belongs to s…

Ypu can track as much as you want but let me know that you are recording my browser screen, my mouse movement, you try to fingerprint my browser using maybe bugs in the browser, so basically inform me, we can see the tracking code so is better you explain on how you use the data then the users to guess.

I'm not arguing against consumer protection and asking for consent. I'm arguing against stupidly burdensome regulation that practically makes ads as a monetization scheme impossible.

Re: GDPR will pop the adtech bubble

#146

Earlier quoted context omitted.

Can you flesh that out a bit more? What are those ways?

Customer focus groups. Literally paying customers to spend time with staff to learn their habits and thoughts about the advertising. The big brands have the funds and expertise to directly gather enough data to come up with strong predictors of behavior.

Focus groups are always made with the consent of the participants, though. You can still use tracking cookies if you also get consent.

Re: GDPR will pop the adtech bubble

#147
post #31

Earlier quoted context omitted.

The ICO does not consider IP addresses personal data since more than one person could use a computer in a household.

Currently, or in relation to GDPR? What's your source? https://ico.org.uk/media/for-organisations/data-protection-r... (20th Oct 2017): > Like the DPA, the GDPR applies to ‘personal data’. However, the GDPR’s definition is more detailed and makes it clear that information such as an online identifier – eg an IP address – can be personal data

> What's your source?

The ICO. I've called them up, and they've confirmed their 2011 interpretation of personal data:

https://ico.org.uk/media/for-organisations/documents/1591/pe...

An IP address is "personal data" in the same way that "lifestyle information" or a "location" is. That someone can combine an IP address with other information to personally identify someone is important, but it doesn't prevent me from logging personal data.

Re: GDPR will pop the adtech bubble

#148

Completely oblivious and ignorant here: If a company has no official office in Europe, how does this affect them? All advertisement and business focus is say only in the US, is it business as usual? What if an EU citizen decides to sign up? Are US companies forced to deny customers not par of say an IP block (half assed method I know, but just speaking in general)?

You're right, if a EU resident decides to visit your website and you're tracking them (Google Analytics etc) you have to comply with GDPR when handling his/her data. The IP block has a logic to it because the law applies to people in the EU rather than EU citizens.

Re: GDPR will pop the adtech bubble

#149

Earlier quoted context omitted.

> By and large, it doesn't, very well. I know Twitter isn't known for being the best at advertising, but it was made exceptionally clear to me that online advertising is a massive bunch of lies when I did my GDPR Twitter data export and it included me in a bunch of incorrect, non-sensical and contradictory ad targeting groups. Twitter claims I: * Own a cat, dog and other animal (I don't) * Have between $100k- $999k l…

> I was very disappointed that the Google and Facebook data exports don't contain this data. Facebook has it available, if not in their Download Your Information tool. Go to Settings -> Ads -> Your Information -> Categories.

[deleted]

Re: GDPR will pop the adtech bubble

#150
post #31

Earlier quoted context omitted.

The ICO does not consider IP addresses personal data since more than one person could use a computer in a household.

That's not true; I can only assume you're reading the 2011-era DPA guidance. Under GDPR, an IP address must explicitly be considered as personal data, and any processing of them must be written in the documentation of the data processing activities: https://ico.org.uk/for-organisations/guide-to-the-general-da... As another commenter has mentioned, this is included in the legislation. There isn't much interpretation t…

Yes it's absolutely true, insofar as I do not have to obtain someone's consent to have logs of their IP address (which is what we're talking about[1])

[1]: https://news.ycombinator.com/item?id=17060280

The GDPR requires informing of use, transmitting preference, and protecting rights, of things that can potentially identify an individual, but this is easy to accommodate by simply not being an asshole. You're not under any requirement to actually identify an individual with your IP log.

Post reply on HN