Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

141–150 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#141
post #22

Earlier quoted context omitted.

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

The argument goes, if the monetization model is unethical, then it shouldn't exist. I'll demonstrate this by taking your post and rewriting it about a different industry. I am NOT saying these are the same situation, because most people have different views on tracking vs child labor. I am demonstrating that the argument makes sense IF you think tracking is similarly immoral. > Ok, that's nice in a fantasy world, but…

The major difference is that the child labor affects someone else negatively, while tracking affects the consumer themselves.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#142
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.

Do you mean the direct cost of implementing the compliance, or the indirect cost of no longer getting extra ad revenue in an illegal way?

In most cases I bet the former isn't all that much. The latter is a harder nut to crack, with everyone trying to toe the line and referencing what other companies are able to get away with. Lack of good faith is a big obstacle.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#143

Earlier quoted context omitted.

Stalking is collecting any information, that either by itself or combined with other information can be used to identify someone with reasonable probability. IP addresses, browser/device details (fingerprinting, etc), usage patterns can fall into this category.

By that definition, literally everybody in real life is stalking me just by seeing what I look like. That's not a terribly useful or reasonable distinction.

If they are collecting and storing that data into neatly labeled folders, any prosecutor worth their salt could make a compelling case for stalking.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#144

Earlier quoted context omitted.

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

We didn't lose that much because I suspect big business in Europe is largely ignoring the more difficult parts of the GDPR. I work for a large bank that is totally non-compliant with GDPR and does not really even have a strategy for getting there. My impression is that we (the bank) looked at the draconian requirements of the bill, realized that, with the total mess that the IT of the bank is in, implementing GDPR would cost billions, and just sort of gave up. It looks like we wait for the regulators to fine us and hope that it won't be a nine figure fine.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#145

Earlier quoted context omitted.

> afford the engineers with the technical expertise to comply with the law while accomplishing their goals Google is in breach of the GDPR as it stands, so no. > afford the lawyers to address the issue when they fail at the former Potentially, though again a clear-cut breach like theirs should result in a fine regardless of how much money they throw at the problem. As far as building a moat, I'm not sure. Whether it'…

> Google is in breach of the GDPR as it stands, so no. I don't believe that is true. What is your source? They were fined in Jan 2019, but are they still out of compliance? If yes, why are they not being continuously fined? > you either break the law or you don't. That's the result on the other side of a trial, sure. Which is why good lawyers are so important.

> They were fined in Jan 2019, but are they still out of compliance?

They were fined on one specific thing and they maybe fixed it (or silently replaced with an equivalent, non-compliant thing once they went out of the spotlight), however they are plenty of other things they do that are in breach and those are not being investigated nor fined which is why we're discussing the lack of enforcement.

> Which is why good lawyers are so important.

True, but a good law should be one that you can't lawyer your way out of and so far the GDPR outcome of that is inconclusive given there is barely any enforcement at all.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#146
post #75

Earlier quoted context omitted.

> Consent should be freely given otherwise it's invalid. I tried to figure out what this actually means but it's very hazy. A naggy news website isn't performing a contract. Are they provisioning a service (assuming you did not buy or order or subscribe to anything)? "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the prov…

For starters, it simply means that if declining consent is harder/more annoying than accepting then it's already in breach, regardless of anything else. If your website takes 1 click to accept tracking but several clicks to deny it then you're already in breach (assuming the law was actually enforced, which it isn't at the moment).

Can you link a reliable source?

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#147
post #66

Earlier quoted context omitted.

That's actually a good idea. It's really frustrating how (in other types of news) a lot of buzz can be generated and then just silence and we forget it all and move on. But it's not really something that would sell well. Not many people care about yesterday's news, people want to know what's coming next and not what came out of some magazine's prediction several years ago.

I agree it wouldn't sell very well. But postmortems in the tech world do trend sometimes a news cycle postmortem - someone pitch this in an elevator

It’s a great idea, but I doubt it would succeed. Human nature tends to include not admitting fault. Also, many readers seem to choose their news (at least political news) for confirmation bias (whether intentional or not), so a news site/paper saying they were wrong would defeat that.

Not saying that retractions don’t happen, but they seem to be always buried under the headlines.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#148

Earlier quoted context omitted.

Letting companies opt-out of a regulation purely because it hurts their business model sounds much more ill-conceived to me.

Good law doesn't "let companies opt-out;" it is crafted with consideration for what is already happening and the consequences of the law. it doesn't appear, 2 years in, GDPR passes that test. If the goal was to minimize "privacy violation" by FB and Google, it's failing. FB and Google are stronger than ever, but their competitors are starved out of the market trying to comply with an onerous suite of policies. It's s…

Did we read the same article? Most fines are tiny. It hasn't fixed everything (yet) but that doesn't mean it's hurting competition.

> Good law doesn't "let companies opt-out;" it is crafted with consideration for what is already happening and the consequences of the law.

And sometimes the outcome of that consideration is "stop doing that".

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#149

Personally I am just annoyed by the cookie warning on every site. Gdpr does not apply to vast portions of the internet.

If you use an AdBlocker, you can add the list called "EasyList Cookie" and it will remove some of the annoying cookie notifications, but even with that list a lot of cookie notifications will be showed.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#150
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

Here's an example of a broken site: https://www.europarl.europa.eu/privacy-policy/en The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and…

That's incredible and just shows how stupid this directive was. In my opinion it destroyed the user privacy and user experience: the average user now clicks "accept" as soon as he visits a site. This made it easy to fool non-technical users to subscribe to push notifications, give access to location and other privacy-invading features. I used the phone of my sister for a few minutes and her notification center was bombarded with random push notifications froms sites he visited and to which she unknowingly subscribed to.
Post reply on HN