Live data from Hacker News

Google’s GDPR Workaround

brave.com

11–20 of 629 posts

Re: Google’s GDPR Workaround

#11
Snippets from the article:

> The evidence further reveals that Google allowed [...]

> Google has no control over what happens to these data once broadcast [...]

Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)?

Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply with their contract with Google. If that assumption is accurate, perhaps Google's advertisers are in breach of their contract with Google which makes it appear as though Google itself is in breach?

I could be off-base, the details in the article aren't incredibly clear to me.

(For the record, I don't like Google's business model and I don't like Google's pervasive tracking -- I'm playing devil's advocate to better understand the issue)

Re: Google’s GDPR Workaround

#13
What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Re: Google’s GDPR Workaround

#14
post #9
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

Unless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative:

> The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements.

From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties

Re: Google’s GDPR Workaround

#15
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

Re: Google’s GDPR Workaround

#16
post #10
post #4

Earlier quoted context omitted.

From my (admittedly limited) understanding, this is not actually legal under the GDPR. Certainly the alleged (but not demonstrated) behind-the-scenes trading of personal info isn’t, but the shared id is also personally-identifying information, and directly regulated.

It's not legal but there isn't much the EU can really do. It would be shocking if they actually managed to prosecute Google which has so far avoided much hassle in antitrust and the like, taking I think a billion dollar fine which sounds like a lot but is basically a slap on the wrist. That's why, IMO, GDPR sucks for small businesses that can be outed to the ICO for a minor oversight and not so much for big data abus…

That sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR?

A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/

Re: Google’s GDPR Workaround

#17
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues (cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon.

Enabled by default can and should be the default for security-related features.

I tend to agree about the rest of the creepiness, especially anything personally behavioral.

Re: Google’s GDPR Workaround

#18
post #9
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

> Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be.

GDPR penalties are a flat fee or a percentage of revenue, whichever is higher.

If Google is truly willfully violating the GDPR, the maximum penalty by law could be up to 4% of their global turnover. I would not call that pocket change. But more importantly, it is a relative increase in fine based on the law breaking company.

(Will the EU actually fine Google ~6 billion dollars? Perhaps we will find out!)

Re: Google’s GDPR Workaround

#19
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

[deleted]

Re: Google’s GDPR Workaround

#20
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

> If they're able to beat Google's lawyer army and actually prosecute them, then Google will take a whopping fine in the millions of dollars that'll be more than covered by their daily revs.

This is why the 4% of global annual revenue fine option exists. A few of those add up quick.

Post reply on HN