Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

151–160 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#151

Earlier quoted context omitted.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

We didn't lose that much because I suspect big business in Europe is largely ignoring the more difficult parts of the GDPR. I work for a large bank that is totally non-compliant with GDPR and does not really even have a strategy for getting there. My impression is that we (the bank) looked at the draconian requirements of the bill, realized that, with the total mess that the IT of the bank is in, implementing GDPR wo…

Which parts are so difficult? Trying to find all the data about a user in the system?

I have some sympathy for an giant mash of databases like that.

I have no sympathy if someone claims that adding a tracking toggle to a single web site is too hard.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#152
post #2

We care about your privacy notices have become the bane of my life.

Found this Chrome Extension: I don't care about cookies - Remove cookie warnings from almost all websites!

https://chrome.google.com/webstore/detail/i-dont-care-about-...

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#153

Earlier quoted context omitted.

In this case you could say anti-drug-trafficking laws are ill-conceived because they go against the cartels' business models.

You may want to choose another example. US drug law is a case-study in how law divorced from consideration of ramifications to existing businesses and societal norms is a disastrous way to craft law. https://www.aclu.org/other/american-drug-laws-new-jim-crow

Drugs by themselves are indeed a bad example (I am personally in favor of legalizing drugs), but let's substitute them with violence:

Would you say that anti-violence laws are ill-conceived because they go against cartels/mobs' business models of extorting money from people under threat of violence?

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#154

Earlier quoted context omitted.

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

>Nasty social media that makes their money on outrage and exposing people to scam ads?

Last I checked Facebook and friends still exist.

>what did we actually lose?

* Many europeans lost access to various publishing sites (another win for the big guys)

* Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#155
post #146

Earlier quoted context omitted.

For starters, it simply means that if declining consent is harder/more annoying than accepting then it's already in breach, regardless of anything else. If your website takes 1 click to accept tracking but several clicks to deny it then you're already in breach (assuming the law was actually enforced, which it isn't at the moment).

Can you link a reliable source?

This is from the ICO, the UK privacy regulator: https://ico.org.uk/for-organisations/guide-to-data-protectio...

> Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent.

If providing consent requires a single click (accept the pre-ticked options) but declining consent requires multiple clicks (to untick the pre-ticked options) then that is already in breach.

> Be specific and ‘granular’ so that you get separate consent for separate things. Vague or blanket consent is not enough.

A big "accept" button for everything is not good enough either.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#156
post #107

Earlier quoted context omitted.

Yes, they could be making a rational choice that we don't agree with.

Then maybe we shouldn't be making laws to force things "we happen to like" to everyone

It's one of the few ways to negotiate back against contracts of adhesion. Giving that choice would theoretically be nice, but the status quo makes it not really a free choice, and the downside is bigger than the upside.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#157
post #20

I think GDPR has its heart in the right place. I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge. And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things. GDPR seems to play out as a strange…

GDPR is poorly designed. It deliberately uses super vauge and imprecise wording. That is bad enough when operating in a common-law legal system where that is the norm. It is inexcusable in the Civil Law system that much of Europe operates in.

Consider you offer the ability to users to voluntarily submit reviews of restaurants. One reviewer complained that person seated at table next to them was excessively noisy, and that upon asking the waitstaff to do something about it, they did nothing.

It is actually entirely plausible for a company like Facebook to have enough information to be able to determine exactly who that other person is, given that review. For example if say both posted images of their receipts to Instagram. Why would they do that? Beats me, but plenty of people do things like that. Under a wide but not at all implausible reading of the personal information definition in the GDPR, that review qualifies as personal data of the person at the other table. The definition of personal data is "any information relating to an identified or identifiable natural person". And that review does include information about a natural person, and we have shown that the person is theoretically identifiable by Facebook.

This means if that other person asks for all their personal info from the site, technically that review should be included. But most likely even Facebook does not yet have the ability to automatically identify this other individual. However, the regulation does not specify any applicable exception, so if you fail to turn over that data (despite having no way of knowing that review pertains to this specific individual), the supervisory authority could still legally fine you.

Would you ever be fined for that? No of course not. Strictly speaking nothing in the wording of the regulation would prevent them from doing so. But obviously they have so many bigger concerns, and are unlikely to bother interpreting things so widely.

After all, there is not a single large company that operates in Europe that is fully compliant with the GDPR if interpreted widely. There quite simply cannot be, since the costs of actually identifying everything that could count as personal data under a wide interpretation and ensuring the company can always look up 100% of it without ever missing any would bankrupt every such large company.

And that is only touching on one little aspect of the GDPR, and one that is unlikely to actually be a major deal. Much worse is how vague the "legitimate interests" reason for processing is. That is the reason that many companies are relying on for much of their processing, and nobody can say with any certainly what cases are included in that, and what are not.

So obviously the best the companies can due is attempt to follow the spirit of the regulation rather than the letter. But of course, if you do that, you cannot be entirely sure the regulators will agree with you.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#158

Earlier quoted context omitted.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

> Nasty social media that makes their money on outrage and exposing people to scam ads? Last I checked Facebook and friends still exist. > what did we actually lose? * Many europeans lost access to various publishing sites (another win for the big guys) * Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

> Last I checked Facebook and friends still exist.

Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil being advertised or malware on major online ad networks (not an issue anymore thanks to an ad blocker).

> Many europeans lost access to various publishing sites (another win for the big guys)

This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void.

> Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

Somewhat agreed but this seems to be a side-effect of companies trying to lawyer their way out of the law, and the reason this works is because of the lack of enforcement. If it was enforced it would be a clear message that these efforts don't work and should be stopped.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#159
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

Reminds me when the EU "Fixed" Cookies and now we have these stupid click-through warnings everywhere that have pretty much ruined the user experience. Root cause: people passing laws they have idea what about.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#160
post #22

Earlier quoted context omitted.

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

DuckDuckGo does ads without tracking In fact, every advertisement outside of the web works without tracking/stalking the consumer. At most, you get a discount code for "seeing this ad on X place" > Why can't I say: "accept that my site is ad-supported or don't use my site?" Because that's the equivalent of me giving you my address, dob, SSN, etc just for entering your store

> Because that's the equivalent of me giving you my address, dob, SSN, etc just for entering your store

So what? If you don't want to give me those things (ad tracking isn't nearly that bad, btw), then don't enter my store. And likewise, if a consenting adult doesn't mind giving out that info in exchange for entering my store, why prevent them from doing so?

Don't agree to my terms, don't enter my shop. It's as simple as that.

Post reply on HN