Live data from Hacker News

Google’s GDPR Workaround

brave.com

61–70 of 629 posts

Re: Google’s GDPR Workaround

#61
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

> Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be. GDPR penalties are a flat fee or a percentage of revenue, whichever is higher . If Google is truly willfully violating the GDPR, the maximum penalty…

> Will the EU actually fine Google ~6 billion dollars? Perhaps we will find out!)

The EU already fined Google a total of $9 billion over the last two years.

Re: Google’s GDPR Workaround

#62
post #31
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

The fine is already kinda big for GDPR (4% global rev for big companies) but Google has gotten away with way worse on way more regulated fronts i.e. their antitrust case which slapped them on the wrist. If GDPR wants to be effective they need a ridiculous company-breaking fine for big abusers like COPPA and the like. Something like a per-user fine for violations that means they either can't do business in the EU or t…

These are valid points but I still think it's reasonable trade off. Yes, I believe the popups banners etc might be annoying, but all companies share this problem. And I find it hard to believe it really hurts a business with a valid product.

Re: Google’s GDPR Workaround

#64
Targeted ads are already a serious leak of information.

If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me.

Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.

Re: Google’s GDPR Workaround

#65
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

> If they're able to beat Google's lawyer army and actually prosecute them, then Google will take a whopping fine in the millions of dollars that'll be more than covered by their daily revs. This is why the 4% of global annual revenue fine option exists. A few of those add up quick.

Furthermore, if organizations are explicitly accepting penalties to keep on violating the law, that law will be adjusted accordingly. It might take a while, but it will happen. Laws with the intention to change behavior / culture cannot "work" from day one. This is a continuous process steered by politics, courts, governments, and public opinion.

Re: Google’s GDPR Workaround

#66

Earlier quoted context omitted.

> Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be. GDPR penalties are a flat fee or a percentage of revenue, whichever is higher . If Google is truly willfully violating the GDPR, the maximum penalty…

If their whole business model is selling personal data, then 4% is clearly just a cost of running their business.

The GDPR does consider willful violations and a pattern of behavior.

4% the first time might be something you can shrug off, especially for a company the size of Google. But if you continue breaking the law and give the regulators an easy second or third bite at the apple...

I’d expect Google makes no changes and fights the regulators the first few times.

E: I used to have a comment here about Google continuing their current practices against non-EU people but it appears from my reading of the GDPR that may not be so simple

Re: Google’s GDPR Workaround

#67

Earlier quoted context omitted.

Unless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative: > The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements. From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties

In context, "relatively bigger" would mean something like a progressive tax bracket. $20MM up to $500MM rev, 4% up to $1BB rev, 5% up to $2BB rev, 6% up to $5BB rev, etc... A straight 4% would be absolutely bigger, but relatively the same (once beyond $500M).

This

Re: Google’s GDPR Workaround

#68
post #64

Targeted ads are already a serious leak of information. If somebody looks over my shoulder and sees the ads presented to me, they can infer things about me. Also, if a malicious actor targets an ad to a group of people, and some of these people buy the advertised items, then the actor can infer things about those people not necessarily related to the items sold.

if someone looked over your shoulder and saw you browsing HN they could infer things too

Re: Google’s GDPR Workaround

#69
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

> branded as a 'privacy nut'

Only the Paranoid Survive. A book by The President and CEO of Intel.

https://en.m.wikipedia.org/wiki/Andrew_Grove

Re: Google’s GDPR Workaround

#70

Earlier quoted context omitted.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

5 billion is peanuts to google. if the fine is low enough that it can be written off as a cost of business, it's too low. effective fines devastate profit margins rather than merely crimping them.

Doing some quick googling, it looks like their quarterly revenue is in the 6-7 billion range. I don't believe 20%ish of revenue is in the peanuts range.

Edit: doing some more googling, maybe it's in the 10 billion range; getting better for Google, but I still can't see a company deciding that such a fine is irrelevant.

Post reply on HN