Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

161–170 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#161
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

There is a bit deja vu, since at that time we were pointing out similar flaws in the DPD (lack of enforcement, lack of clarity, govt inefficiencies, the inability for proponents to separate intent from reality, etc). Sadly, there is an absolute "for or against" mentality out there. You can't make it clear that the implementation of such a law would be poor enough to not justify it being enacted in the first place les…

Do nothing is an untenable position. Software companies have become so brazen and scummy that even a law which is unevenly enforced is absolutely necessary.

The GDPR brought privacy to the front and into the attention of software companies. It gives us individuals at least a chance to control our data.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#162
post #66

Earlier quoted context omitted.

I agree it wouldn't sell very well. But postmortems in the tech world do trend sometimes a news cycle postmortem - someone pitch this in an elevator

It’s a great idea, but I doubt it would succeed. Human nature tends to include not admitting fault. Also, many readers seem to choose their news (at least political news) for confirmation bias (whether intentional or not), so a news site/paper saying they were wrong would defeat that. Not saying that retractions don’t happen, but they seem to be always buried under the headlines.

They could call out the news sites/papers of the opposite side though.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#163

Earlier quoted context omitted.

> Nasty social media that makes their money on outrage and exposing people to scam ads? Last I checked Facebook and friends still exist. > what did we actually lose? * Many europeans lost access to various publishing sites (another win for the big guys) * Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

>This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void.

Access to fewer news sites is access to fewer news. The new site isn't going to replace the old. Also, we're not getting replacements for them in the EU because the business model for these sites doesn't work with GDPR. Making their life financially more difficult just pushes them more into clickbait and yellow journalism.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#164
post #150

Earlier quoted context omitted.

Here's an example of a broken site: https://www.europarl.europa.eu/privacy-policy/en The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and…

That's incredible and just shows how stupid this directive was. In my opinion it destroyed the user privacy and user experience: the average user now clicks "accept" as soon as he visits a site. This made it easy to fool non-technical users to subscribe to push notifications, give access to location and other privacy-invading features. I used the phone of my sister for a few minutes and her notification center was bo…

I agree that the current lack of enforcement is bad for the intent of the law and its long-term impact.

Currently the lack of enforcement allows non-compliant solutions (where accepting is easier than declining) to thrive so people get used to accepting everything.

Down the line, even when enforcement catches up and compliant solutions start appearing, users will still be clicking accept because they've been trained to do so.

This is unfortunately good for adtech/martech not just now but in the future, so all of those currently making your money on stalking users, don't cry, it's all gonna be okay.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#165

Has anyone beyond big tech actually figured out what the rules are yet?

Informally, EU citizens own their personal data, and only ever grant revocable licenses to it.

More precisely, to collect any personally identifiable (PII) of an EU citizen, you need their consent. PII includes things like name and email, but also anything like an IP address that can be used to "unmask" a person. Consent must be freely given and can be withdrawn at any time. If requested by a citizen, you must turn over or delete any PII of the inquirer. You must do your best to keep the PII safe, and follow security best practices - and in case of a data breach you must inform the data authorities and affected citizens. You may only ever hand over data to other companies (sub processors) if you have a contract guaranteeing that they will also abide by the above constraints (nice little GPL-esque twist there).

I hate the barrage of popups from websites trying to weasel out of it in order to continue business as usual with ad-tracking. But at its core, the GDPR is actually a pretty good piece of legislation - we now have a right to be forgotten anywhere.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#166

Earlier quoted context omitted.

We didn't lose that much because I suspect big business in Europe is largely ignoring the more difficult parts of the GDPR. I work for a large bank that is totally non-compliant with GDPR and does not really even have a strategy for getting there. My impression is that we (the bank) looked at the draconian requirements of the bill, realized that, with the total mess that the IT of the bank is in, implementing GDPR wo…

Which parts are so difficult? Trying to find all the data about a user in the system? I have some sympathy for an giant mash of databases like that. I have no sympathy if someone claims that adding a tracking toggle to a single web site is too hard.

Normally it's hard enough to ensure that you have retained an authoritative copy of data, but now it's even harder to ensure that you have destroyed every incidental copy throughout the org on short notice. Then there's the bureaucratic "prior consultation" that will delay launches by months

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#167

Earlier quoted context omitted.

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

> This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void. Access to fewer news sites is access to fewer news. The new site isn't going to replace the old. Also, we're not getting replacements for them in the EU because the business model for these sites doesn't work with GDPR. Making their lif…

> Making their life financially more difficult just pushes them more into clickbait and yellow journalism.

Clickbait is explicitly caused by advertising - it's right there in the name, it's there to drive clicks, the content itself is secondary.

If advertising becomes unsustainable then other business models will take over. At the moment subscribing to news websites is too expensive because 1) we don't have an easy to use micropayment system and 2) they are greedy and charge way more than what they would get in ad revenue.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#168

Earlier quoted context omitted.

It’s a great idea, but I doubt it would succeed. Human nature tends to include not admitting fault. Also, many readers seem to choose their news (at least political news) for confirmation bias (whether intentional or not), so a news site/paper saying they were wrong would defeat that. Not saying that retractions don’t happen, but they seem to be always buried under the headlines.

They could call out the news sites/papers of the opposite side though.

That is something I considered. Many partisan sites love to point out the errors of the other side. I know Fox News loves to call out CNN all the time. However, if every site did it, I fear that would just lead to more confirmation bias. And why report that the other side was right? That hurts your viewpoint.

What we need is a non-partisan non-profit to do it. But then there’s the problem of funding (which results in conspiracy theories).

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#169
The fears about GDPR when it passed, if I remember correctly, were mainly around arbitrary draconian enforcement. This article seems to only be talking about under enforcement. The causes of this under enforcement seem fixable. Ireland, putatively afraid of the big tech companies choosing to put their Europe HQs elsewhere, has been dragging their feet on privacy investigations. But the investigations are happening. Then there are some countries not putting enough money into it. The rest seems to be the various countries not being in alignment. For a sweeping, two-year-old regulation that has spent about an eighth of its life in the time of a major global crisis, this doesn't strike me as all that shocking.

Does anyone have any actual examples of draconian fines being handed out for good-faith misunderstandings of the regulation? Big Tech has professed confusion over how they're supposed to comply, but it seems to me like like they would simply prefer not to.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#170
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

> Turns out... actually yeah.

That might be how you feel. For me, GDPR and the “Cookie Law” have been amazing, as they make it incredibly easy to detect which websites and businesses you should avoid.

I do however wish they’d be a lot more aggressive with the fines.

Post reply on HN