Live data from Hacker News

GDPR will pop the adtech bubble

blogs.harvard.edu

381–390 of 454 posts

Re: GDPR will pop the adtech bubble

#381

Although I like the GDPR and would support similar legislation in my country, I honestly don't see the gloom and doom story. The EU market is a small part of the global story, and while this change clearly makes that market harder to enter, the article doesn't make the case that the EU represents a sufficient share of the adtech market to pop a bubble. In general it's easy to believe negative press about hated entiti…

EU market is something like 25% of all the global market revenue, both for total industry and for the main international players individually. 25% of total revenue is large enough to adapt instead of avoiding the market, and it would be expected that every multinational player will be compliant, and thus also require their suppliers to be compliant - i.e. Google won't be buying data from a random adtech company if it might be "contaminated" with EU data obtained without proper procedures, the potential financial risk is just too great.

Re: GDPR will pop the adtech bubble

#382

Earlier quoted context omitted.

> How is "my business model depends on it" not a bona fide legitimate purpose for information collection? Business models are arbitrary and orthogonal to services provided. > But you don't get to randomly outlaw certain entire classes of business. Why not? Some business models are clearly antisocial and don't deserve to exist. GDPR is only outlawing business models based on large-scale abuse of people's private and i…

> Business models are arbitrary and orthogonal to services provided. That's a very interesting claim. So you're saying it'd be possible to organize fighter jet production as a co-op vegan collective?

Sure it is. How effective this business model is is another story.

Either way, you don't have an inherent right to specific business models and the EU is simply not allowing a business model anymore that has been widely abused. Of course it'll hurt some but I think overall the industry will adapt and change for the better.

Re: GDPR will pop the adtech bubble

#383

Earlier quoted context omitted.

That's a good question, I don't know if it's valid to offer discounts and such in exchange for consent. It goes against the EU principles ("personal information cannot be conceived as a mere economic asset"), but I'm not sure if the law actually prevents it.

One of the criteria for freely given consent is that the customer must be able to revoke it at any time without detriment. If revoking consent causes a detriment, then it's not freely given, and so that "consent" isn't sufficient to grant the data controller a legal permission to use that data. Quoting recital 42 from https://gdpr-info.eu/recitals/no-42/ "[...] Consent should not be regarded as freely given if the da…

I think a minor discount would probably fly (under 15% or so) or atleast defendable to the regulatory bodies.

Bigger discounts would be a problem since that would be more of a detriment.

Re: GDPR will pop the adtech bubble

#384

Earlier quoted context omitted.

>Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? Yes the EU invented a new right for its citizens which is the prerogative of the EU because of their bastardized idea of what constitutes privacy. Privacy is a basic human right, that much is obvious. There is no human right however to…

> The author of a creative work doesn't have the right to force me to delete something from my laptop if I obtained it lawfully. A valid point - the rights only address the USE of the photos. You can use them privately all you want and would not have to delete them (unless ordered by a court for whatever odd legal reason such as if they were stolen not uploaded). The difference with personal info is that the lawmaker…

GDPR is focused a lot on regulating the use of the data. In particular, one of the key aspects is the limitation of processing to a particular use - very often business will have a reasonable GDPR-approved reason to get and have the data, but (since this was often used to circumvent earlier privacy legislation) now they'll be limited to using that data only for that reason.

For example, if I order pizza, the business (obviously) needs to have my delivery address; however, that obvious reason only applies for the actual delivery, and if they want to use that same address also for, say, direct marketing, then that's a separate use that's not covered and would (generally) need additional opt-in consent.

Re: GDPR will pop the adtech bubble

#385
post #370

Earlier quoted context omitted.

Jurisprudence in this area disagrees with you: "online media services provider may collect and use personal data relating to a user of those services, without his consent, only in so far as that [..] that data are necessary to facilitate and charge for the specific use of those services by that user" http://curia.europa.eu/juris/document/document.jsf?text=&doc... This is related to the DPA; but the GDPR doesn't chang…

I'm ignoring German opinions since Art 51-52 suggest only the ICO is going to be involved. > if you're arguing collecting IP addresses is absolutely necessary for you to facilitate the service, no, you don't need consent. But I would not want to have to defend that, since disabling collection is as simple as a webserver reconfig. Using IP addresses for audit and security is best practices; I can use the IP address to…

So, three things. First, the case reference I gave you. That "German opinion" is from the Court of Justice of the European Union. This is the highest court that applies, and the ICO must obey it (until Brexit - and even after then, it's highly unlikely that the UK will interpret the GDPR in a different manner, at least for some time).

Second, I've said before IP addresses might not always be personal data. But the issue is they sometimes are, and if you record them without discrimination then you're recording personal data. The old guidance says "An IP address is only likely to be personal data if relates to a PC or other device that has a single user" - ok, so are you able to not record IP addresses that do relate to a single-user device? No?

Third, the ICO do think IP addresses count. I've given you a GDPR reference already, even their DPA tool treats them as such:

https://ico.org.uk/for-organisations/making-data-protection-...

It genuinely doesn't matter what the ICO might have said in the past. Right now, they say IP addresses are personal data. The courts say that. The law says that. I've given you multiple references for all of this.

Re: GDPR will pop the adtech bubble

#386
From the article, it looks like the big winners in this will be companies which both run ads and have customer accounts. Google and Facebook, basically. Companies which have no relationship with the customer have no way to ask for permission to use customer data. This is a killer for third-party adtech companies which need that permission.

So the middlemen get cut out, and advertisers deal with Google and Facebook directly.

Re: GDPR will pop the adtech bubble

#387
post #273

Earlier quoted context omitted.

Don't worry, I am sure it wont be abused. The whole fearfull effect was created by adtech companies trying to create public outrage and paranoia to pretect their money source. Be sure that there are going to be some nasty penalties for greatest violaters (like online dating sites) I have noticed a lot of them is packaging GDPR into terms and conditions and privacy policy changes and those will have to get a fine, but…

Don't worry, I am sure it wont be abused. It would be the first time in history that such a law has not been abused. The fear is real and fully warranted. I am sure warning will come first There is no mandate written into the GDPR requiring warnings before fines, nor is there anything preventing multimillion-dollar fines for first-time, minor violations.

It's not a law it's a regulation and EU regulation is largely intended to be more of a carrot before the unpack the stick.

See the Smartphone Charger regulation. It requires all smartphones vendors to come up with a standard for charging, everyone picked microUSB (though moving to USB C now). The EU is fine with that and the smartphone vendors know that if they start pulling the "everyone has their own port" shit again that the EU will get out the stick.

Nobody wants the stick. The EU not and the Vendors not. The carrot was the EU Cookie law, which was largely ignored and the consent dialogs poorly implemented (not even asking for consent the majority of the time). So this is them getting out the stick. Now you can pick which one you want.

>There is no mandate written into the GDPR requiring warnings before fines, nor is there anything preventing multimillion-dollar fines for first-time, minor violations.

Art. 83 of the GDPR details this. Art. 78 details what rights you have against them imposing a fine.

Re: GDPR will pop the adtech bubble

#388

Earlier quoted context omitted.

> By and large, it doesn't, very well. I know Twitter isn't known for being the best at advertising, but it was made exceptionally clear to me that online advertising is a massive bunch of lies when I did my GDPR Twitter data export and it included me in a bunch of incorrect, non-sensical and contradictory ad targeting groups. Twitter claims I: * Own a cat, dog and other animal (I don't) * Have between $100k- $999k l…

For the frugal/high spender conflict, I can kind of see how that might happen. I try to buy quality goods because cheap stuff doesn't last. That means spending more up front to spend less in the long run. So frugal, but also maybe high spender? My mom always says: if you're poor, you can't afford to buy cheap.

It is probably because they have to show you the categories/tags but they are not required to show you the exact percentage/probability. So in their db they have it like 80% frugal spender, 15% high spender but when exported you see it as a yes/no which is confusing.

Re: GDPR will pop the adtech bubble

#389

Earlier quoted context omitted.

That is not the case. The "right to be forgotten" is not absolute. There are lawful bases for processing under which the right to be forgotten does not apply. Go read GDPR article 17.3, it's easy to read. A few things for which the right to forgotten does not apply: - exercising the right of freedom of expression and information - for compliance with a legal obligation (e.g. keeping records for tax reporting) - for p…

Yes! The fud keeps increasing every time another gdpr related post pops up here.

I'm 60% sure it's people who read articles from Adtech Corporations about GDPR and not from people in the EU having to deal with it.

The only bad thing that I've noticed about GDPR is that some niche sites that rely on ad revenue are getting fucked over by Google (if you turn off personalized tracking for your visitors you still need the consent to track, there is no difference) so their income might break down.

That's quite sad but on the other hand they're exploring alternative methods of income and I'm certain adtech will adapt.

Re: GDPR will pop the adtech bubble

#390

Earlier quoted context omitted.

> Also, what pii is tracked (by default) by piwiki or ga or access logs? I certainly cannot think of anything. Cookies and other artifacts in the request headers or query parameters that can identify a unique user.

Identify a unique user does not mean that it's pii if I cannot produce the real world identity of the user from the cookie.

Under the GDPR that's PII. IP Addresses too. Personal Data is any data relating to a natural person, if you can uniquely identify them that falls under the monitoring/profiling definition of the regulation.
Post reply on HN