Live data from Hacker News

Dear Email Industry, We’ve Got a GDPR Problem

jacquescorbytuech.com

201–210 of 215 posts

Re: Dear Email Industry, We’ve Got a GDPR Problem

#201

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

> Now, what additional personal data are collected by tracking pixels?

If I read it, when I read it, where I read it from (location, device, etc)

Re: Dear Email Industry, We’ve Got a GDPR Problem

#202
post #181

Earlier quoted context omitted.

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

You can tracking pixels to track per-user engagement. You can also use tracking links to connect the email address to website activity. As you say, it's possible to use these to track in the aggregate, but many platforms allow tracking by individual. You are correct that the email was already personal data. But, GDPR requires that each new use of data be transparently communicated and legally justified (which may or…

I would argue that pixel trackers for the purpose of checking whether the email is read is covered by the consent to receive marketing by email in the same way as what emails were sent to whom and when will likely also be tracked.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#203

Earlier quoted context omitted.

What surprises me more is that tracking pixels even work anymore. What email clients don't bother to filter them out?

I am surprised that Apple's built-in email clients on both macOS and iOS load remote content by default. One of the first things I disable when I set up a new machine.

Do they? I've just loaded a gmail email on my phone, it says "This message contains unloaded emails", with an option to load them.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#204

Earlier quoted context omitted.

Not some, all email marketers do. There's nothing stopping them either, they're entitled to do so, given they obtain consent for that data processing.

Do they? Remember that under the GDPR, a five-page ToS with a "I consent" button at the end is not considered valid. In particular, the user must consent for each use of the PI separately. I don't remember ever seeing a specific consent box for building an engagement profile.

I meant that all marketers are collecting the data, and in the overwhelming number of cases they're doing so without consent.

I'm yet to see a single marketer only do tracking by opt-in, and I work in the industry.

The problem is that we're:

A) Collecting the data without consent

B) In most cases, unable to not collect the data because ESP's do it by default with no option to switch it off

Re: Dear Email Industry, We’ve Got a GDPR Problem

#205

Earlier quoted context omitted.

Clearly they are asking because they hope that you click "Yes". Once you click "Yes" they give you a cookie and stop bugging you. It's a nasty trick of the tracking industry. GDPR does not forbid websites to ask or even deteriorate your experience (afaik). Perhaps that should change.

GDPR does forbid providing a lesser experience for people who do not consent to tracking. (Obviously aside from the direct consequences of not having tracking, like getting different adverts.)

Then the question is: does (needlessly) asking for permission result in a lesser experience?

Re: Dear Email Industry, We’ve Got a GDPR Problem

#206

Earlier quoted context omitted.

GDPR does forbid providing a lesser experience for people who do not consent to tracking. (Obviously aside from the direct consequences of not having tracking, like getting different adverts.)

Then the question is: does (needlessly) asking for permission result in a lesser experience?

I like the way you're thinking there. But sadly I suspect not.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#207

Earlier quoted context omitted.

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

> Now, what additional personal data are collected by tracking pixels? If I read it, when I read it, where I read it from (location, device, etc)

None of these are personal data if not liked to the email address, which they do not have to.

If linked to email address and considered personal data then the argument is what is covered by consent to receive email marketing? IMHO tracking whether the email was opened is covered (in the same way as agreeing to receive phone marketing should imply they can track whether you answered the phone...). They will also obviously keep track of what emails they sent you and when.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#208

Earlier quoted context omitted.

See for example this site, which is the privacy regulator in the UK: https://ico.org.uk/ Note that they provide notification of necessary cookies, and default opt-out of analytics cookies. > You do not need consent for cookies that power basic website functionality or a feature the user is trying to use. This is correct, you do not need consent for necessary cookies. You do, however, have to provide notification that…

You do not actually need to provide notification for necessary cookies. See https://ico.org.uk/for-organisations/guide-to-pecr/guidance-... and the following few sections. Most clearly, this paragraph on the ICO’s recommendations (quite unreasonable, in my opinion—if all you’re storing is a necessary session cookie, notifying the user in a non-actionable way is just being foolishly annoying): > Although the exemption…

I was directed to that ICO cookie banner as an example of what I need to do, by an EU law firm who we're paying to guide our compliance activities.

I'm not a lawyer and I can't give you legal advice. I can just report that the legal advice that was given to me was that any cookie setting activity needs to be notified, even if consent is not required.

One potential discrepancy is that we are being prepared for the e-Privacy Regulation (which is not yet in effect), while it looks like the page you linked to covers the e-Privacy Directive.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#209

Earlier quoted context omitted.

I’ve had several groupings of unsolicited marketing emails over the years where I’ve clicked Unsubscribe and ended up on what’s very clearly a Totally Not That Email List, Honest...but it’s advertising the same things, in the same way, just from a slightly different email and possibly different company name. They have all been American in origin.

You can complain under the CAN-SPAM Act.

It's so asymmetrical though. The amount of effort it takes to spam someone is vastly lower than a complaint.

What would be great is a third-party site where you can somehow document/log unsubscribe requests. Then, if the company still spams you, document that. A few hundred users is pretty good proof, and the company can't just argue a glitch. It'd pay for that.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#210
While conducting a GDPR review I discovered that our email service provider (Campaign Monitor) was logging IP addresses of our list members associated with each email open. My jaw dropped when I noticed that they were doing geo-ip enrichment, so that I could drill into any subscriber, see a history of their opening of our newsletters, and a map of their approximate location. I could see if "Bruce" was in Melborne or Petaluma on April 23rd. That kind of data is straight up dangerous and would be very hard to justify on a Legitimate Interest Assessment. That said, I haven't found a way to disable or purge that data thus far, and have been having a hard time finding an ESP that doesn't log IPs for its open tracking. We legitimately need open tracking, but certainly not with non-hashed IPs exposed. Realistically, just overall open rate reporting would suffice for our use case, not tracking of individual list member's activity.
Post reply on HN