Live data from Hacker News

The GDPR blog post

medium.com

31–40 of 144 posts

Re: The GDPR blog post

#31

"To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy, including cookie policy." No Medium, I must NOT agree to your privacy policy and your cookie policy, because to use and share my data you need my FREE consent. AND you can NOT deny me reading an article without giving consent, because then the consent is not FREE, and it is NOT strictly necessary…

I think it's more likely that "to make Medium make money," they engage in tracking for advertising purposes.

Medium works perfectly well for my purposes without that banner being displayed. I can open up developer tools and delete that node.

If I don't click agree, does that mean that this information isn't collected? Because tracking cookies are still placed.

Now what is interesting is that I don't remember being asked for consent for them to place a cookie to log the number of articles I read in a month as part of their sign-up funnel.

Re: The GDPR blog post

#32
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

Isn't that the quid pro quo, though? I don't feel obliged to accept their shitty privacy policy, and in return they are not obliged to serve me their often equally shitty content.

Re: The GDPR blog post

#33
post #6

I got a few dozen gdpr emails today, some from companies I didn't know existed. This law is a fantastic development for end users/consumers.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside. It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

It's a common misconception, but consent is only one of the 6 recognized lawful basis for processing specifically recognized by the GDPR, and a company may contact you when any one is applicable. For example, if you have an existing business relationship via a contract (you bought something), or the business has a legal obligation to inform you of changes, or the nebulous "legitimate interests" basis on behalf of the business.

Those emails which ask you to click to continue to receive marketing are a red flag that those companies did not have any legal basis previously, or they're just cargo-culting other companies even though they already have a perfectly valid basis to keep in touch (like you being a an actual customer). Check out your favorite big-company SaaS signup today (like, Jira), you will still typically not see any explicit consent checkboxes, because due to a customer relationship it is not needed.

Re: The GDPR blog post

#34
post #31

"To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy, including cookie policy." No Medium, I must NOT agree to your privacy policy and your cookie policy, because to use and share my data you need my FREE consent. AND you can NOT deny me reading an article without giving consent, because then the consent is not FREE, and it is NOT strictly necessary…

I think it's more likely that "to make Medium make money," they engage in tracking for advertising purposes. Medium works perfectly well for my purposes without that banner being displayed. I can open up developer tools and delete that node. If I don't click agree, does that mean that this information isn't collected? Because tracking cookies are still placed. Now what is interesting is that I don't remember being as…

> Now what is interesting is that I don't remember being asked for consent for them to place a cookie to log the number of articles I read in a month as part of their sign-up funnel.

They could probably make this compliant by storing the counter in your local storage and never sending it anywhere - just having a piece of JS that essentially does: if(Storage.getItem("visits") > 6) { displaySignnupPopup(); }

Re: The GDPR blog post

#35
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

Isn't that the quid pro quo, though? I don't feel obliged to accept their shitty privacy policy, and in return they are not obliged to serve me their often equally shitty content.

Trading nonessential data sharing for ability to use a service is forbidden under GDPR. I'd be fine with them geoblocking me, but the way it is now, this popup sounds not compliant, and also manipulative.

Re: The GDPR blog post

#36

"To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy, including cookie policy." No Medium, I must NOT agree to your privacy policy and your cookie policy, because to use and share my data you need my FREE consent. AND you can NOT deny me reading an article without giving consent, because then the consent is not FREE, and it is NOT strictly necessary…

> AND you can NOT deny me reading an article without giving consent

They can't, but they can, for example, ask for a fee to read the article. They don't deny you reading it, but they don't have to give it to you for free either.

Either you share your data, so they can make money to operate the site, or you don't, but then the content is not free.

I expect some sites will choose this route.

Re: The GDPR blog post

#37
So, I'm really not trying to start a fight, please read this with curious intent.

I personally don't really feel like keeping my email is a violation of my privacy. If they're not "processing" it (that feels like code for "data mining") is this really required? I mean my email address is literally a public means of contacting me. It's kind of fun that they decided to use a one-way hash, but this story doesn't make me feel like the internet has really been improved.

Re: The GDPR blog post

#38
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

"Processors" need theoretically not be advertising/tracking networks, but could also e.g. be payment processors. That is something that I could imagine classifies as necessary.

Re: The GDPR blog post

#39
post #36

"To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy, including cookie policy." No Medium, I must NOT agree to your privacy policy and your cookie policy, because to use and share my data you need my FREE consent. AND you can NOT deny me reading an article without giving consent, because then the consent is not FREE, and it is NOT strictly necessary…

> AND you can NOT deny me reading an article without giving consent They can't, but they can, for example, ask for a fee to read the article. They don't deny you reading it, but they don't have to give it to you for free either. Either you share your data, so they can make money to operate the site, or you don't, but then the content is not free. I expect some sites will choose this route.

> They can't, but they can, for example, ask for a fee to read the article. They don't deny you reading it, but they don't have to give it to you for free either.

Of course they can charge a fee. They should.

> Either you share your data, so they can make money to operate the site, or you don't, but then the content is not free.

No. My data is not a commodity exchange. The GDPR makes that VERY clear. I can not pay with my data. Full stop. There is money for that.

Re: The GDPR blog post

#40

So, I'm really not trying to start a fight, please read this with curious intent. I personally don't really feel like keeping my email is a violation of my privacy. If they're not "processing" it (that feels like code for "data mining") is this really required? I mean my email address is literally a public means of contacting me. It's kind of fun that they decided to use a one-way hash, but this story doesn't make me…

The problem is identification of physical persons. Your e-mail is public, but it also identifies you as a person. This is important, because it allows for correlating different data sets.

Touch Surgery sounds like a honest company, so for them this was just some extra burden. But the same law prevents ShadyAdtechCo from getting datasets from several companies and joining them on e-mail column to build a profile of you, without your explicit, informed consent in several places.

Post reply on HN