Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

111–120 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#111
post #79

Earlier quoted context omitted.

No, there's no protection for failed business models, as there should not be.

The business model of Google isn't a failed business model. What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the fo…

> afford the engineers with the technical expertise to comply with the law while accomplishing their goals

Google is in breach of the GDPR as it stands, so no.

> afford the lawyers to address the issue when they fail at the former

Potentially, though again a clear-cut breach like theirs should result in a fine regardless of how much money they throw at the problem.

As far as building a moat, I'm not sure. Whether it's Google or a one-man shop, neither can accurately track users without being in breach. There is no moat that I can see, you either break the law or you don't.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#112
post #107

Earlier quoted context omitted.

> users don't care and are happy to click past a banner / trade their privacy for free things. Are we discounting the possibility that users make a rational choice that we happen not to like?

Yes, they could be making a rational choice that we don't agree with.

Then maybe we shouldn't be making laws to force things "we happen to like" to everyone

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#113
post #9
post #2

We care about your privacy notices have become the bane of my life.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

Here's an example of a broken site:

https://www.europarl.europa.eu/privacy-policy/en

The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and "atidvisitor" analytics identifiers it has set to identify you).

If that's the result on the EU Parliament's own website, on their privacy policy page, it's safe to say the EU doesn't actually care about privacy.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#114
post #42

Earlier quoted context omitted.

Because the EU says you have it backwards? Ignoring European users is perfectly fine, but if you want to monetize them, you better play by their rules, unless you are more powerful than the EU. In theory. In practice do whatever you want.

> Ignoring European users is perfectly fine, See this: https://news.ycombinator.com/item?id=23353051

Not following a law I'm not subject to is perfectly fine.

I'm free to insult the King of Thailand and drink scotch whisky all night long (as long as I don't die behind the wheel) contrary to the laws of Thailand and Saudi Arabia, respectively.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#115
post #31

Earlier quoted context omitted.

> How else can you even store a consent for cookies/localStorage? You said "the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog" . But if cookies are disabled, then there's no point in asking for consent. There should be no cookie banner in this case.

> But if cookies are disabled, then there's no point in asking for consent. But the only way to determine if cookies are actually disabled in the browser is to attempt to store cookies, which is the thing you're asking consent for.

A cookie storing simply whether the person has accepted, declined or not yet responded to your consent dialog does not require consent.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#116
post #37

Nothing says GDPR is something that can't be improved upon. Better enforcement, refinement of laws, everything is possible. It has to begin somewhere and that beginning is rarely perfect. Every failure is also an opportunity to learn what to do better. As some other people have commented, the intent is right, the execution has to be improved. Edit: Fixed grammar and some words

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#117

Earlier quoted context omitted.

Stalking is collecting any information, that either by itself or combined with other information can be used to identify someone with reasonable probability. IP addresses, browser/device details (fingerprinting, etc), usage patterns can fall into this category.

By that definition, literally everybody in real life is stalking me just by seeing what I look like. That's not a terribly useful or reasonable distinction.

Your analogy would be more accurate if they were logging/taking pictures of what you look like, and that can actually be considered stalking in certain countries.

Seeing the information is one thing. Collecting and storing it is another.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#118
post #22

Earlier quoted context omitted.

The rules are very clear once you look past the fear-mongering. Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline. Don't be careless with user data so you minimize the likelihood of a breach, and if you do get breached then report it to the regulator and cooperate with them. In fact, "big tech" has figured out how to get around the rules by exploiting the lack of…

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

I thought GDPR allowed you to put ads on your site? If you mean you’d prefer that the ads be based on personal user data, and you want collection of that data to be a condition of using your site, that’s a great debate to have, but not when you equate it with the possibility of having ads at all.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#119
post #64

Earlier quoted context omitted.

Your site can be ad-supported, without GDPR popup, as long as you don't track your users to display those ads. You could even have relevant ads by using keywords instead of user data. That's what the NYT has done, and they've seen their revenue grow: https://news.ycombinator.com/item?id=18920079

I just visited NYT's sit. It immediately set 20 cookies before asking for consent. It also loaded stuff from google.com sites. The options that appeared are (a) Accept (b) Manage Trackers Manage trackers leads to this page https://www.nytimes.com/subscription/privacy-policy#/cookie Which seems to list lots of 3rd parties that will track me if I view the site. I'm told I have to go to their sites and opt out.

That is absolutely in breach of the regulation.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#120
post #107

Earlier quoted context omitted.

Yes, they could be making a rational choice that we don't agree with.

Then maybe we shouldn't be making laws to force things "we happen to like" to everyone

I don't think GDPR forces you to choose not to share information. You simply get a a mechanism to make that choice.

IMO it is a flawed and wonky mechanism.

Still I'd prefer a the option, later if nobody cares then maybe remove the choice.

Post reply on HN