Live data from Hacker News

Google’s GDPR Workaround

brave.com

51–60 of 629 posts

Re: Google’s GDPR Workaround

#51
post #17
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

> in terms of tracking it seems about as invasive as Debian's popcon.

How do you figure?

Re: Google’s GDPR Workaround

#53
post #23

Earlier quoted context omitted.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

Q4 2018 earnings were around $40 billion. EU will have to try significantly harder.

That's the revenue, not profit.

Re: Google’s GDPR Workaround

#54
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

> "control" over the data after broadcast, albeit legal control via contracts with advertisers Now there's a claim only a court would buy! A court probably would buy it, though. Sigh.

[deleted]

Re: Google’s GDPR Workaround

#55

Earlier quoted context omitted.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

The executives should face jail time. That would certainly light a fire under Google's ass to finally "do no evil".

Sadly mid-level employees would probably be the ones going to jail. The tech lead and/or PM sign off on compliance. I used to joke that one of my responsibilities was to put my freedom at stake.

None of my products violate GDPR in any way I could conceive, but I’d hate to be handed down a mandate to do so. Both not accepting a project and not signing off on it are pretty bold moves.

Re: Google’s GDPR Workaround

#56
post #31
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

The fine is already kinda big for GDPR (4% global rev for big companies) but Google has gotten away with way worse on way more regulated fronts i.e. their antitrust case which slapped them on the wrist. If GDPR wants to be effective they need a ridiculous company-breaking fine for big abusers like COPPA and the like. Something like a per-user fine for violations that means they either can't do business in the EU or t…

>Google has gotten away with way worse on way more regulated fronts i.e. their antitrust case which slapped them on the wrist.

Although I feel that Google has won its position in search, etc by offering a legitimately better product, we need to punish companies that continue to break the law. Success does not put you above the law. If you use your massive profits to absorb fines for breaking the law repeatedly, you should lose your ability to operate as a corporation and be dissolved. We need to reform antitrust laws. It's not just being able to control an entire market anymore, it's about being able to ignore international law because you have so much money.

Re: Google’s GDPR Workaround

#57
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

The real time bidding on ad placements seems like a thing that a user could never give consent to as it's literally feeding your info to a massive ever churning list of companies that get to bid on it.

Aka - you land on a site, it send your IP and whatever identifiers it has to 10,000+ companies who all then figure out if they want to bid on showing you an ad.

Re: Google’s GDPR Workaround

#58

>I was branded as a 'privacy nut' Companies do actually employ shills to go on forums and try to sway public opinion. They call them something like public advocates, doesn't change the idea though.

I get the feeling this is much more prevalent than any of us realize. Would explain why most comments seem ridiculous.

Re: Google’s GDPR Workaround

#59
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

> "control" over the data after broadcast, albeit legal control via contracts with advertisers Now there's a claim only a court would buy! A court probably would buy it, though. Sigh.

That is the GDPR-default though. You're still allowed to give data to third parties, you just need to have contracts with them regarding the handling, deletion etc of that data. Of course, mostly that's for data processors, which I don't think ad networks working with Google would fall under.

Re: Google’s GDPR Workaround

#60
post #47
post #16

Earlier quoted context omitted.

That sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR? A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/

This is being quoted in every comment but if you have enough lawyers anything is possible. Google has come out of antitrust cases relatively unscathed. They've even violated GDPR itself once before explicitly, and got out with a 57MM$ fine. This case won't be any different than all the other times that Google has blatantly violated laws and walked away with a slap on the wrist. I would be very very very shocked if th…

I mean, that's an entirely different class of problem.

If the law literally doesn't work because of reasons, then that's just systemic corruption.

Post reply on HN