Live data from Hacker News

Google’s GDPR Workaround

brave.com

21–30 of 629 posts

Re: Google’s GDPR Workaround

#21
post #7
post #4

Earlier quoted context omitted.

From my (admittedly limited) understanding, this is not actually legal under the GDPR. Certainly the alleged (but not demonstrated) behind-the-scenes trading of personal info isn’t, but the shared id is also personally-identifying information, and directly regulated.

It is very not legal, but I think the parent was saying these regulations are more onerous to small dev shops rather than Google and the fine for this will be minuscule. Hopefully companies will find paths to revenue that do not require selling out there users to this level, maybe by just having ad auctions without any identifying information at all.

The first GDPR fines handed down by the ICO have been hundreds of millions of pounds for negligent breaches - I don't think it would be out of the realm of possibility for breaches by _design_ to result in multi-billion pound fines.

Re: Google’s GDPR Workaround

#22
post #6
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

And I'm very annoyed that your initial reaction to reading this article is to blame the GDPR instead of blaming Google for these shady practices. Boycott that crap, move to other services. This shouldn't be acceptable. I'm very happy that the GDPR exist, if only because it forced all these websites from explicitly giving me a list of the literally hundreds of partners they want to share my data with, along with a way…

- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR was supposed to regulate this and it is clearly failing to do so. And if you want to boycott it you're welcome to but they've built an empire with their cloud, search, email, etc to the point where that would be pretty difficult and annoying to the average consumer. They're effectively too big to be boycotted at this point.

- It doesn't explicitly force them to do that. And most sites aren't explicitly sharing the data either; i.e. almost every site uses Google analytics which doesn't really comply with do not track all too well, and Google will then share their data with everybody else (which is part of their violations in this article). Also saying "no" doesn't do much either as most of these big sites either already stored the cookie or won't do much to delete it. And it's not that they'll try to work around it, they either don't put forth the effort because GDPR is like a pebble for them, or they already worked around it in a way that changes nothing. Their business model is still the exact same.

I think the spirit of this law is fine, but the actual law does nothing and is just privacy theater. Google isn't buying time, almost 4 years later nothing has changed -- they just know they can't be touched.

- They're not going to sink, they'll just grow much slower and thus won't be an alternative to the big data abusers you hate so much. And they're not failing to handle your data, most of the time startups aren't selling you out they're just trying to figure out who their customer is internally. To do this they collect some data that is usually optional and very much with your consent; GDPR just puts a bunch of hoops in front of this so that it's an enormous pain to do so. I run a startup that collects basically no data (literally, we do not have a database for 2 of our products). It was a pain for us to become GDPR compliant because that disables our metrics entirely and requires a bunch of banners and checkboxes everywhere even though we literally store nothing.

I'm all for the spirit of the law. I just think the execution sucks and they definitely didn't think it through enough. I think the evidence for this is clear based on the sheer number of privacy violations we've had since GDPR was enacted alone, and how little enforcement and regulation has actually gone on.

Re: Google’s GDPR Workaround

#23
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

Q4 2018 earnings were around $40 billion. EU will have to try significantly harder.

Re: Google’s GDPR Workaround

#24
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

Unless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative: > The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements. From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties

In context, "relatively bigger" would mean something like a progressive tax bracket. $20MM up to $500MM rev, 4% up to $1BB rev, 5% up to $2BB rev, 6% up to $5BB rev, etc...

A straight 4% would be absolutely bigger, but relatively the same (once beyond $500M).

Re: Google’s GDPR Workaround

#25
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Sure you didn't mean to say that what's actually sad is that the US federal government/DoJ doesn't take real action?

Re: Google’s GDPR Workaround

#26
post #7
post #4

Earlier quoted context omitted.

From my (admittedly limited) understanding, this is not actually legal under the GDPR. Certainly the alleged (but not demonstrated) behind-the-scenes trading of personal info isn’t, but the shared id is also personally-identifying information, and directly regulated.

It is very not legal, but I think the parent was saying these regulations are more onerous to small dev shops rather than Google and the fine for this will be minuscule. Hopefully companies will find paths to revenue that do not require selling out there users to this level, maybe by just having ad auctions without any identifying information at all.

From gdpr.eu:

"The more serious infringements go against the very principles of the right to privacy and the right to be forgotten that are at the heart of the GDPR. These types of infringements could result in a fine of up to €20 million, or 4% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher."

For Google that would be 4% of its worldwide annual revenue, I'd assume. Taking into account that it's not one infringement but multiple that could mean a pretty hefty fine.

Re: Google’s GDPR Workaround

#27
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

5 billion is peanuts to google. if the fine is low enough that it can be written off as a cost of business, it's too low. effective fines devastate profit margins rather than merely crimping them.

Re: Google’s GDPR Workaround

#28
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

[deleted]

Re: Google’s GDPR Workaround

#30
post #23

Earlier quoted context omitted.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

Q4 2018 earnings were around $40 billion. EU will have to try significantly harder.

It will have to be executive jailtime and personal fines or it will never matter.
Post reply on HN