Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

81–90 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#81
post #20

I think GDPR has its heart in the right place. I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge. And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things. GDPR seems to play out as a strange…

> GDPR has its heart in the right place

I'm not sure we can jump to that conclusion. If the outcome of the GDPR was bewilderingly out of left field, and totally unpredictable, perhaps we could pass this off as being a big-hearted failure.

The thing that I struggle to get past, though, is just how many of us warned of these outcomes _before_ the regulations were implemented.

I fear very few had their heart in the right place. After all, it's pretty evident now, that those of of who saw this as a corporate effort to erect unnatural barriers to entry were correct. The people who designed the GDPR aren't idiots - they knew what they were doing too.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#82

Earlier quoted context omitted.

You are allowed a cookie that tracks their opt in to your other cookies, so long as it is anonymous (or so our lawyer tells us). On our site, we ping whether that cookie is set before we load the rest of the cookies.

Is it acceptable to store a cookie that defaults to "false" provided it is generic? That would solve the problem of not being able to detect if cookies are enabled in the browser until you try to store them. added: person down thread indicated that there's an API for determining if cookies are enabled for the host on your page's origin called navigator.cookieEnabled which I am shocked I've not seen nor heard of even…

We didn't trust using the host cookie settings because most users don't know they exist.

But we were told anonymous cookies were totally fine and within the spirit of the law. If you hit the "Accept" button, you got a cookie that allowed more cookies.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#83

Earlier quoted context omitted.

You can not [1] (though this is definitely the clause that at least in the US, I'm confident would be beaten down in court). And this is why I have such a problem with the rule. Without some dramatic changes, any video streaming site almost surely wouldn't be able to handle the substantially lower ad revenue and still make a profit if everyone actually opted out. Sites like Facebook would probably turn a profit, but…

Is YouTube blocked in the EU? Let’s assume it’s turning a profit there, then start wondering how. The obvious answer is that monetised videos generally have a subject, and advertisements can be tied to that subject.

I don't think Google has ever released the numbers on how many people have opted out, one can assume it's not 100%.

And you are clearly tracked across Google services at least, as anyone who has ever google something shopping related, then viewed a youtube video can tell you.

>The obvious answer is that monetized videos generally have a subject, and advertisements can be tied to that subject.

The obvious answer to me is that not everyone opted out. Businesses generally want to make money, collecting data clearly made them more money, or they wouldn't have done it. Now they make less on those who opted out.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#84
post #36

Earlier quoted context omitted.

Under PECR, a cookie being essential means necessary to provide the requested service , not necessary to stay in business. If the user wants to view a news article, and you can serve the article without using analytics cookies, then PECR doesn't allow the cookie. (The situation for paywalls is complicated.)

Providing the service assumes staying in business, no?

Not for this regulation. Business considerations do not matter, only technical ones.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#85
post #20

I think GDPR has its heart in the right place. I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge. And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things. GDPR seems to play out as a strange…

> users don't care and are happy to click past a banner / trade their privacy for free things.

The GDPR explicitly mandates that consent should be freely given (it should not be more difficult to decline than to accept) and that consent should be informed, so you can't bury the information in 30 pages of ToS or privacy policies.

The problem is that there is currently zero enforcement around those things. I'd argue that this is very bad for the intent of the law because even when enforcement starts happening and declining consent becomes possible users would've already been trained to just click accept to everything.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#86
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

I've seen a lot of people say this, but I'm just not convinced it's actually the law. It's not obvious to me that analytics cookies categorically can't be essential or that "freely given" implies strict UI neutrality between accepting and declining.

Well, essential means that a web service cannot technically work without it. For example, a session cookie.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#87
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

There is a bit deja vu, since at that time we were pointing out similar flaws in the DPD (lack of enforcement, lack of clarity, govt inefficiencies, the inability for proponents to separate intent from reality, etc). Sadly, there is an absolute "for or against" mentality out there. You can't make it clear that the implementation of such a law would be poor enough to not justify it being enacted in the first place les…

There was a popular pushback against American tech in Europe at the time. Criticism of GDPR was conflated with criticism of that pushback.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#88
post #36

Earlier quoted context omitted.

Under PECR, a cookie being essential means necessary to provide the requested service , not necessary to stay in business. If the user wants to view a news article, and you can serve the article without using analytics cookies, then PECR doesn't allow the cookie. (The situation for paywalls is complicated.)

Providing the service assumes staying in business, no?

You'd have a hard time arguing that breaking GDPR is the only way to stay in business. There are enough compliant news websites to undermine that argument.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#89
post #9
post #2

We care about your privacy notices have become the bane of my life.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

> The majority of these aren't actually compliant.

The title of the article is "Two years in, GDPR defined by mixed signals, unbalanced enforcement".

So sure, maybe they're not complaint, but nobody is enforcing anyway.

EDIT: removed unnecessary pejorative statement from last paragraph

Post reply on HN