Live data from Hacker News

Study: Google is the biggest beneficiary of the GDPR

cliqz.com

81–90 of 140 posts

Re: Study: Google is the biggest beneficiary of the GDPR

#81

Is Google the biggest "beneficiary" here, or is it more that a lot of shady operations were totally shafting people on their data/privacy and so they've finally had to close down or expose themselves to massive legal risks? The significant drop in trackers on EU sites reported here (and not a huge surge in Google trackers on EU sites) suggests to me that it is other adtech/tracker companies that have lost, rather tha…

You're not looking for a surge from Google though - they're already the 1000lb gorilla, what you're looking for is the limitation in competition, which is what's occurring. As with a lot of EU digital regulations, they're essentially centralising power to organisations who have the legal resources to either go through the process (and find loopholes), or the cash to fight it. A lack of competition in the tracking spa…

The multiple small companies tracking limited pieces of info about you would anyway be happy to sell and share that for money, this is partly how those huge DMP databases are built.

Re: Study: Google is the biggest beneficiary of the GDPR

#82

"WhoTracks.me is a joint initiative of Cliqz and Ghostery. It provides structured information on tracking technologies, market structure and data-sharing on the web and thus creates more transparency. On the WhoTracks.me website, interested parties will find visualized monthly tracker statistics. They are based on the evaluation of around 300 million-page loads and more than half a million websites." Considering IP-a…

I assuming the data was collected through the Ghostery browser extensions, which requires explicit opt-in to share that data.

Re: Study: Google is the biggest beneficiary of the GDPR

#83

The author of this article didn't bother to read even a summary of the GDPR law. It doesn't matter what the user consents to, you cannot use their personal data ad hoc. You need to justify its collection, storage and transfer to the regulator, not the user. This is in contrast to the ill thought out cookie law where websites could get away with it by irritating consent banners. Sort of like, but not exactly the same…

I bet rafting consent forms are still useful in the sense that they discourage most people with trivial-to-moderate injuries from thinking about holding the company liable.

Same as 'Stay Back 500ft, Not responsible for damage' signs on the back of gravel trucks. Youd better bet they are 100% liable for anything that flies out. But it discourages the unmotivated and the uneducated from seeking their entitled legal relief.

Re: Study: Google is the biggest beneficiary of the GDPR

#84

Earlier quoted context omitted.

That's also fine - was their content worth your privacy? If they can't be GDPR compliant we don't want them.

Was their content worth my privacy? I will never know as they will not let me see it. Besides, if they didn’t block me, I can always ensure my privacy to a reasonable degree by using private browsing mode on my browser. That requires very little effort, unlike what I would have to do now — use some VPN provider who quite likely would be monitoring ALL my data not just to that site.

You certainly don't need to use a VPN - much less one that routes all your traffic - to access a site from another place.

I suggest: https://outline.com/

Re: Study: Google is the biggest beneficiary of the GDPR

#85

Is there any evidence of GDPR having the desired effect for which it was put in place? Is citizens' data being protected more than before? The second-order effects that everyone predicted are already happening (big tech companies change nothing significant, many small companies shutting down). The long-term and unforseen second-order effects have yet to bear fruit, as far as I know (please let me know if you've seen…

One effect I haven't seen mentioned yet is that EU data subjects can permanently delete their Facebook accounts, along with all associated data. (Previously you could only indefinitely 'deactivate'.)

Re: Study: Google is the biggest beneficiary of the GDPR

#86
post #59

Earlier quoted context omitted.

That's also fine - was their content worth your privacy? If they can't be GDPR compliant we don't want them.

If you didn't think their content was worth it you didn't have to visit. Now no one can.

You can only make that choice if you're informed about the tradeoff. Getting sites to inform users is the main purpose of the GDPR. It's not the EU's fault that the LA Times would rather block people than do that.

Re: Study: Google is the biggest beneficiary of the GDPR

#87

The author of this article didn't bother to read even a summary of the GDPR law. It doesn't matter what the user consents to, you cannot use their personal data ad hoc. You need to justify its collection, storage and transfer to the regulator, not the user. This is in contrast to the ill thought out cookie law where websites could get away with it by irritating consent banners. Sort of like, but not exactly the same…

> It doesn't matter what the user consents to That's not entirely true. If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. Whether the consent banners inform users honestly about the extent of tracking is another question. I think they don't. What's worse is that Google still tracks users by default, even if they never visited an actual Google property, let alone have a Goo…

> If a user really consents to being tracked for advertising purposes, the GDPR allows tracking.

That's not exactly true either. For the consent to be valid, it must be freely given - that is:

1. The user must have a choice to give consent or not give it

2. The service provided should be the same regardless of #1, unless the consent is necessary for the service (e.g. consent to store address for delivery of goods - although in such case this shouldn't really be based on consent)

Unfortunately many sites either do not give opt out at all, or make it hard to find it - in such cases consent can't really be considered to be freely given.

Re: Study: Google is the biggest beneficiary of the GDPR

#88
post #81

Earlier quoted context omitted.

You're not looking for a surge from Google though - they're already the 1000lb gorilla, what you're looking for is the limitation in competition, which is what's occurring. As with a lot of EU digital regulations, they're essentially centralising power to organisations who have the legal resources to either go through the process (and find loopholes), or the cash to fight it. A lack of competition in the tracking spa…

The multiple small companies tracking limited pieces of info about you would anyway be happy to sell and share that for money, this is partly how those huge DMP databases are built.

You can limit that with different legislation though - the data-sharing and processing parts would do this, without the additional level of explicit consent which is the stumbling block (requiring scale).

I'm not advocating in favour of tracking, but the effects of enforcing collecting explicit opt-in consent appears to be centralising power, rather than getting rid of the industry. I'd rather have implicit consent across multiple providers (with processing safeguards and data sharing agreements stating they're only pooling the data amongst their advertisers), than explicit consent with only one behemoth.

Re: Study: Google is the biggest beneficiary of the GDPR

#89
post #43
post #35

Earlier quoted context omitted.

> was their content worth your privacy? What privacy was I losing?

First one that comes to my mind: their advertisers knowing you're on those sites, which page you read, when, for how long, etc. This is mitigated by running an Adblocker and a selective Javascript disabling extension like uMatrix or NoScript, but it would be much better if those sites would let their readers decide if they want to be tracked or not. Anyway, I'm also blocked on those sites but the same news on LA Time…

If you agree to pay $10 a month per paper, then you could have it. But majority of people have proven that they will not pay, hence it does not justify to have a paid subscription system without ads.

When more and more people block ads, there will only be a few large sites remaining on the internet because the rest will not be able to survive in the most likely scenario. You could cry all about your freedom then.

Re: Study: Google is the biggest beneficiary of the GDPR

#90
post #87

Earlier quoted context omitted.

> It doesn't matter what the user consents to That's not entirely true. If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. Whether the consent banners inform users honestly about the extent of tracking is another question. I think they don't. What's worse is that Google still tracks users by default, even if they never visited an actual Google property, let alone have a Goo…

> If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. That's not exactly true either. For the consent to be valid, it must be freely given - that is: 1. The user must have a choice to give consent or not give it 2. The service provided should be the same regardless of #1, unless the consent is necessary for the service (e.g. consent to store address for delivery of goods - a…

That is not true you are confusing single purpose with a “valid” purpose from the users point of view which isn’t actually the case your business needs can be just as a valid reason under the GDPR as anything, you do not have to provide service to users who decline if say it affects your ad revenue the GDPR cannot force you to provide a “free” service to users.

Consent is just one lawful basis for data collection, business justification is another one and ad revenue is a perfectly valid reason in which case you don’t even need consent but just to inform the user.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

You can do what ever you want under “vital interests” as long as you feel comfortable explaining those to the regulator, not the user.

Consent is used often because the current interpretation of most legal experts is that it shifts the liability to the user however this has never been tested.

Post reply on HN