Live data from Hacker News

CCPA goes into effect January 1, but nobody’s sure how the new rules work

latimes.com

111–120 of 129 posts

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#111
post #74

Earlier quoted context omitted.

GDPR has a lot of burdensome requirements, like hiring a commissar and multi-month government review periods before features launches. Do not bet 21M USD that merely deleting cookies and logs will get you anywhere near compliance.

I'm not sure how serving up a custom page to EU addresses solves that problem either, though, so we come back to equivalence.

The theory is that Article 3 stops the EU from coming after you (however they might try) if you don't offer goods or services to EU data subjects or monitor their behavior. The GDPR is roughly the size of a novel, and proving you're doing everything it requires is a hell of a lot more work than proving you're out of scope entirely.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#112
post #102

Earlier quoted context omitted.

> if you just ask for permission to use cookies (for any reason) and refuse service if the opt-out Is that even true? If I never consent do I get no cookies left on my browser?

It (in theory) should be, but most often if you click "opt-out" they kick you off the site -- hence "refuse service". With GDPR (loosely) that is no longer allowed when it comes to the opt-in nature of data processing disclosures (if you opt-out, they can't refuse you service for not opting-in -- with certain limitations).

Interestingly, a strict reading of GDPR suggests that "consent gating" should not be permitted, but admittedly the wording is quite weak, and it isn't clear cut.

> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

This would suggest consent may not be freely given if it was obtained by conditionally providing a service based on consent bring obtained for processing of extraneous data.

Recital 42 adds:

> Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

I don't think many users have a genuine free choice on many websites, although admittedly it's now mostly the worst offenders to blame here - the average site probably does have an opt-out now that actually works (!)

Recital 32 also appears to deal with the annoying, interrupting, semi modal nature of prompts we see on ad-laden sites:

> If the data subject’s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#113
post #25

Earlier quoted context omitted.

It’s just a passive-aggressive hissy fit. The cost of writing the middleware to write out your angsty nonsense is higher than the cost of writing the middleware to just remove all cookies from every request. The EU detection logic is the same in both cases.

GDPR has a lot of burdensome requirements, like hiring a commissar and multi-month government review periods before features launches. Do not bet 21M USD that merely deleting cookies and logs will get you anywhere near compliance.

> multi-month government review

Can you explain this a bit more?

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#114

Earlier quoted context omitted.

No. Things you need to do to make the site/service function at all such as your login cookies or shopping carts don’t count. Non essential cookies is what it’s about. Sadly, some sites seem to interpret that (incorrectly) as “well out business is to show news paid for by ads so the ad network cookies are essential”. These are the players I wish would be fined out of business.

Just for interest sake, do you ever read news on the internet, and if so how do you pay for it? I personally read a lot of news online, most of it is such utter trash that I would not want to pay for it. I have paid for some specific sites intermittently - currently I pay about $20 USD a month to one specific content creator that produces news content - but that is mostly because it is rather niche news that nobody e…

I pay for a subscription on one news site.

I read dozens of sites, but I’m not going to allow being tracked if I can help it. I also don’t much care whether these sites survive or not, and I absolutely wouldn’t care if they disappeared because people behaved like me (answering no to tracking and/or using ad blockers).

My thinking is that if everyone blocked tracking ads, then money would return to dumb ads (that now aren’t worth anything because of tracking/targeted ads). So I hope that’s the future. If it isn’t then I guess the less optimistic future is that half of all “free” content online disappears while the rest is concentrated in silos like Facebook and YouTube that can ensure eyes on ads. I think both futures are better than the status quo.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#115
post #101

Earlier quoted context omitted.

> Thats an odd thing to say. Websites don't need to allow free access either. I can't comment on any particular revenue model but I imagine many websites chose personalized ads as they provide better revenue returns than non-personalized ads. Another way to get revenue, which doesn't itself transgress against these privacy-focused laws, is to charge directly for providing your service. That's totally legal! Well, but…

Why are people not allowed to choose for themselves? Should we start banning what people can share on social media too for their own protection? Also not everyone can pay for content so you're punishing people who can least afford it by having direct payment be the only way forward. Privacy laws that remove freedom and opportunity aren't very good laws.

I absolutely think that site owners and visitors should not be allowed to enter an agreement where content is provided based on selling PII of the visitor. The reason is simple: the visitor can’t be properly made aware of what they are actually paying. So it should simply be banned. Yes, at the expense of maybe a majority of content online disappearing. And yes at the expense of people who can’t afford to pay for content in cash being denied it entirely.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#116

Regarding the GDPR: > 95% of users choose to be tracked in exchange for access to websites and services The GDPR explicitly disallows the practice of conditioning access to a site or service on acceptance. Without that it would be rather useless. Once that bit is also enforced (current fines for violation sadly week focused on poor data safety measures and similar) I think the online ad landscape actually may start t…

I dunno, man. As you mentioned, all of the people who implement or enforce GDPR compliance seem to think that "our business model relies on ads" is a sufficient reason to require tracking. Maybe the regulators are just biding their time before pouncing, but I'm not sure why they'd want to do that or what they're waiting for after a year and a half. It seems more likely that GDPR as an ad industry killer was just a pi…

The wording was very clearly made to avoid any doubt about “we need to track people to survive on ads”. As I said I think it’s sad that so far the fines have been for data security and not yet for tracking-ads-without-opt-in.

I really do hope regulators will take a few high profile sites and make an example with a massive fine for blatant violations.

The rule is: if I visit a site then tracking is OFF until I switch it on. Seeing the content can’t be conditioned on accepting, and the default “ok close the popup and show me the article” should always result in the miminum cookies allowed - that is, typically no ad networks at all.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#117

Earlier quoted context omitted.

Why are people not allowed to choose for themselves? Should we start banning what people can share on social media too for their own protection? Also not everyone can pay for content so you're punishing people who can least afford it by having direct payment be the only way forward. Privacy laws that remove freedom and opportunity aren't very good laws.

I absolutely think that site owners and visitors should not be allowed to enter an agreement where content is provided based on selling PII of the visitor. The reason is simple: the visitor can’t be properly made aware of what they are actually paying. So it should simply be banned. Yes, at the expense of maybe a majority of content online disappearing. And yes at the expense of people who can’t afford to pay for con…

No thanks, that sounds absolutely terrible. I, and billions of others on the planet, prefer to make our own choices.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#118
post #102

Earlier quoted context omitted.

> if you just ask for permission to use cookies (for any reason) and refuse service if the opt-out Is that even true? If I never consent do I get no cookies left on my browser?

It (in theory) should be, but most often if you click "opt-out" they kick you off the site -- hence "refuse service". With GDPR (loosely) that is no longer allowed when it comes to the opt-in nature of data processing disclosures (if you opt-out, they can't refuse you service for not opting-in -- with certain limitations).

Most often there is no opt-out button. Just a big banner that you have to ignore, click accept, or block using ublock origin. Pretty sure that they use cookies regardless of your choice.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#119

Earlier quoted context omitted.

> Because browsers make it an all or nothing setting (all, 1st party, none) At least for Firefox this is not the case. Anyway, extensions like uMatrix exist. > the DNT header The DNT header is yet another way for sites to track you. I am glad it failed.

> The DNT header is yet another way for sites to track you. I am glad it failed. And clicking decline on cookie banners or your unique combination on the multiple choice cookie disclaimers wont allow sites to track you?

Certainly it will, but I said already that I am against cookie banners.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#120

Earlier quoted context omitted.

Yeah I'm sure the homeless in New Jersey buy themselves plane tickets to SFO because the weather is better and nobody kicks them off the sidewalk where they would prefer to lay. Blame everyone else for San Francisco problems...

It's not blaming, but it does explain a lot of what is going on. Regardless I looked at enough of your past postings to decide you aren't the kind I'd like to engage with further. Good bye.

I think you have no argument to claim that homeless people actually travel across the country to reach California. That's why the quick goodbye.
Post reply on HN