Live data from Hacker News

Dear Email Industry, We’ve Got a GDPR Problem

jacquescorbytuech.com

141–150 of 215 posts

Re: Dear Email Industry, We’ve Got a GDPR Problem

#141

Earlier quoted context omitted.

> But so much of that tracking isn't really necessary. I've just launched my e-commerce platform and I see 34 unique visitors and no sales. Analytics is key to figure out if something is wrong and I'm not talking about the code. > I'd rather focus on making my product better. How do you make it better? Having numbers without analyzing user engagement is shooting in the dark with a shotgun.

Do you need to know that they were 34 unique visitors or would properly anonymised data be enough? I suspect it would be. The GDPR doesn't say you can't have analytics, but it quite rightly tries to prevent the kind of tracking you're talking about without explicit consent from the user being tracked.

Yes, properly anonymised data would be enough. I'm not talking about anything intrusive. I don't care who they are, I care about how they use my product. That can be done in a GDPR complaint way.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#142
post #51

Earlier quoted context omitted.

> We need a standard for managing these controls on the browser side, which major browsers can then implement. Like the "Do Not Track" header field? https://en.wikipedia.org/wiki/Do_Not_Track Perhaps it will work if introduced as a GDPR header field.

That is a good point. If my browser is sending a do not track header, why is your server even asking me how much tracking I want?

Clearly they are asking because they hope that you click "Yes". Once you click "Yes" they give you a cookie and stop bugging you. It's a nasty trick of the tracking industry.

GDPR does not forbid websites to ask or even deteriorate your experience (afaik). Perhaps that should change.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#143
post #127

I think the GDPR is a good opportunity to reflect how much tracking we really need. Tracking has become so ubiquitous, it's become the default to put Google Analytics on a site, to put a tracking pixel into every email, to personalize every link we send out... But so much of that tracking isn't really necessary. I've stopped tracking website visitors and stopped including tracking pixels in emails a few years ago, an…

> But so much of that tracking isn't really necessary. The problem with Google Analytics and tracking is it's hard to tell what the motive is for putting it onto your site from the visitor's POV. Not everyone who uses GA is using it for evil purposes. They use it because GA makes it easy to gain useful business metrics, such as 100 people visited this page, 30 people filled out the account form, 5 people completed th…

From the POV of someone who's both just a visitor on most sites and used GA himself: GA is often used for evil purposes, and as a tool it's optimized to enable and support evil purposes. Therefore, it's reasonable to assume, in absence of evidence to the contrary, that the site that loads it uses it for evil purposes.

Does it inconvenience honest people who'd like to use those tools for honest purposes? Sure. But think of it this way: it would be much more convenient for me if I could just give a merchant or service provider my on-line banking login and password, so they could take care of billing me directly. Would I ever do this if asked? No fucking way (even ignoring that my bank would consider it a TOS violation).

Problem is, there's no good way to signal honest intentions between parties that aren't already in a long-term relationship (and no, "we only use cookies to improve your experience" doesn't count; in fact, it's an anti-signal; thank marketers for that). So the only option for honest people is to not do the same things evil people would do.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#144

Earlier quoted context omitted.

Not having marketing spammers is still better than having spammers and scammers

There's usually an unsubscribe button for marketing spam, and if there isn't I usually block their email. You can't do that with scammers / illegal spam.

Fuck the unsubscribe button. I never subscribed in the first place.

It’s one disgusting thing when people hide signup behind email confirmation without clearly marked opt-in spam confirmation. It’s another when I get home from a professional event and I have a dozen new “subscriptions” and people “just reaching out” or “following up on our prior conversation” to a single-purpose email address I gave to one place and used a fake name and fake company name.

Email marketing can get fucked.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#145
post #68

Earlier quoted context omitted.

So much this. Every time I see a popup with "We respect your privacy", I think "no you don't" and try to see if it is something I can block in privacy badger to remove the popup. If the site respect users privacy it will not track the users and don't need the warning

More accurate - "We value your privacy". In other words, your privacy has value to them, and they are eager to shaft you that privacy to extract the value.

They value your privacy the same way a mugger values your wallet. They'll often even offer you a degraded experience if you don't consent.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#146
post #99

I think the GDPR is a good opportunity to reflect how much tracking we really need. Tracking has become so ubiquitous, it's become the default to put Google Analytics on a site, to put a tracking pixel into every email, to personalize every link we send out... But so much of that tracking isn't really necessary. I've stopped tracking website visitors and stopped including tracking pixels in emails a few years ago, an…

GDPR wants 0 tracking. That's wrong too, the internet can't work that way, even governments can't work that way. EU wants advertising to go back to the popup / animated gifs & flash / interstitial era to maximize clickthroughs in the off-chance one of them is actually interested in your ads. That's regression

GDPR wants 0 tracking without explicit, informed consent. That's the key thing in this regulation: informed consent. Dealing with people fairly.

> EU wants advertising to go back to the popup / animated gifs & flash / interstitial era to maximize clickthroughs in the off-chance one of them is actually interested in your ads.

Not true, unfortunately. EU wants the ads to not track people without their explicit, informed consent. GDPR isn't an anti-advertising law, it's a data protection law (says so literally in the name).

> That's regression

No. That's remission.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#147
post #55
post #23

Earlier quoted context omitted.

>Browsing the web in Europe is like experiencing the rebirth of the pop-up ads era. Very much so; the pop-ups interrupt and obstruct, breaking immersion. I sincerely hope a browser gets brave enough to start blocking those obstructions by default. It irks me how every "Cookies" banner is an unpaid advertising billboard saying, "Your privacy is valuable to us. Yours faithful, EU". >This too shall pass. For now, uBlock…

> the pop-ups interrupt and obstruct, breaking immersion. Here is a trick for website owners: don't track your users. No need for any popup anymore.

This is incorrect, an EU website must provide notification of cookies if they use cookies at all, even for basic session tracking of authenticated users.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#148
post #108

Earlier quoted context omitted.

Thanks for answering, it's curious enough that I'm now looking into Thunderbird plugins to see if there's one to block (or try to) tracking pixels.

Thunderbird blocks images per default. I never bother to load them.

Just to be clear, it blocks remote images by default. Images embedded in a mail are displayed.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#149
post #95

Earlier quoted context omitted.

If it's from a legitimate company in American jurisdiction they are legally obligated to stop sending emails if you click unsubscribe. I suppose that piece of information has some nonzero value that you are giving up in exchange to not be contacted by that company. If you filter just a single address that address can change. If you filter their domain you might lose legitimate correspondence.

I’ve had several groupings of unsolicited marketing emails over the years where I’ve clicked Unsubscribe and ended up on what’s very clearly a Totally Not That Email List, Honest...but it’s advertising the same things, in the same way, just from a slightly different email and possibly different company name. They have all been American in origin.

You can complain under the CAN-SPAM Act.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#150
post #65

Earlier quoted context omitted.

Just because you associate emails with spam doesn't solve the problem of every charity, business, church, school and group needing to communicate with large numbers of email subscribers. Like anything, bad actors make it worse.

No "industry" is needed for pub/sub news. The GDPR only affects the companies abusing current system for unsoliticed advertising

> GDPR only affects the companies abusing current system for unsoliticed advertising

No. Have you looked at the thing? It affects every organization willing to do business or communicate with the EU.

Post reply on HN