Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

261–270 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#261

Earlier quoted context omitted.

Causing you to get angry is all it takes to warrant justification for jail time in your eyes? I am thankful you aren't in charge of any lawmaking.

Jail might be a bit much, but giving them the maximum fine allowed under the GDPR seems quite reasonable to me. I'd even go so far as to try and transfer the debt to the individuals responsible if this causes the company to go bankrupt, as this is clearly malpractice.

> I'd even go so far as to try and transfer the debt to the individuals responsible if this causes the company to go bankrupt

So who's liable in this scenario? Someone in the C suite? The coder monkey who implemented it? Someone in between? All of the above?

Unless I'm mis-remembering, the maximum fine under GDPR is a % of the total revenue of the company, so depending on the size of the company, this could result in bankruptcy of any individuals deemed responsible too.

Re: Only 9% of visitors give GDPR consent to be tracked

#262
post #256

Earlier quoted context omitted.

I don't see how the first option is not GDPR-compliant. If the privacy policy page doesn't process personal data there is no consent needed.

I'm going to quote Article 7.4. of the GPDR here: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract." Preventing you from seeing the page you request if you do not consent seems…

I have read this and (IANAL) view this as a definition for what is "freely given consent". If you force users to give consent in order to use service, it isn't freely given consent. It doesn't say that you must provide the service.

Re: Only 9% of visitors give GDPR consent to be tracked

#263

Earlier quoted context omitted.

Sorry, privacy as a personal responsibility has failed outright. For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). The GDPR is actually sufficiently abstract IMO to make government enfor…

> For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet h…

I'm okay with killing everything currently online (given backups, of course) in exchange for a sensible micropayment/nanopayment architecture.

Ads must die.

Re: Only 9% of visitors give GDPR consent to be tracked

#264

Earlier quoted context omitted.

Jail might be a bit much, but giving them the maximum fine allowed under the GDPR seems quite reasonable to me. I'd even go so far as to try and transfer the debt to the individuals responsible if this causes the company to go bankrupt, as this is clearly malpractice.

> I'd even go so far as to try and transfer the debt to the individuals responsible if this causes the company to go bankrupt So who's liable in this scenario? Someone in the C suite? The coder monkey who implemented it? Someone in between? All of the above? Unless I'm mis-remembering, the maximum fine under GDPR is a % of the total revenue of the company, so depending on the size of the company, this could result in…

I'd say the stock owners.

Re: Only 9% of visitors give GDPR consent to be tracked

#265

I would say of 9% who gave consent the vast majority gave their consent through error, deceit or because they don't know what tracking really means and they wanted the service anyway. Why not outright outlaw opt-out tracking and be done with this silly state of things? There are legitimate uses of tracking and any company would still be able to provide it for the users, but you would have to have legally binding cont…

Tracking already has to be opt-in according the GDPR. The issue is that the GDPR is not enforced so sites get away with non-compliant consent prompts.

The issue here simply seems like enforcement needs to be formalized to be as cost-effective and simple as possible. It starts with fines, ramps up to full investigations if bad faith is shown. Turns out when you write laws they also need to be enforced.

Re: Only 9% of visitors give GDPR consent to be tracked

#266
post #241
post #93

Earlier quoted context omitted.

Why would anyone consent to be tracked if given a real choice? What are the benefits? The 9% look like an error.

I would certainly. Have you seen the kind of ads people can get on Youtube for example? There's some crazy bullshit there. I would regularly go to Google Ads preference page and correct their profile of myself (sadly many time that would means that I keep getting the same 2-3 ads because it then become too specific, but it's much better than the alternative). I also advise it to people that complains about ads on You…

Google (search) had that kicking-ass feature that it would show you some 20 ads relevant to your query clearly marked on the side bar. It was incredibly useful.

Then they decided to track everybody, so the ads stopped being relevant and were just about stuff you were already looking for and for the pages you have already opened. Useless as it became, people stopped clicking and they had to start the dark patterns of mixing the ads with content, and filling the first page with it.

Now you are saying tracking is improving your experience, but you just said the ads are useless. Why is that? Are the original ads harmful? And you are protecting from that by surrendering extra information?

Re: Only 9% of visitors give GDPR consent to be tracked

#267

Earlier quoted context omitted.

Of course they're being tracked through any and all means. The whole adtech biz is one big shady shitshow. You can probably count the ethical, law-abiding adtech firms on one hand.

I work on mobile apps, and I can promise there's no tracking on the apps I've been building if you opt out. The SDKs I've seen seem to do what they promise: no communication to backend when tracking is disabled. Of course, I can only speak for the apps I've been building and SDKs I've used.

Do you have to explicitly opt out to stop tracking? If so, are you sure your apps are GDPR compliant?

Re: Only 9% of visitors give GDPR consent to be tracked

#268

I hate ads as much as everybody else, and this reads to me like "given the choice only 9% of people would pay for their meal", should we forbid charging for food then? Probably not. As sad as the current ads-powered internet is becoming I haven't seen any promising viable alternative, and sure non-tracking-based ads is not the same thing as having no ads, but it significantly moves the needle in that same direction i…

That metaphor falls apart on multiple levels. Paying for a meal is a transaction that both parties explicitly agree to. Tracking in its current state is mostly done without the consumers awareness/consent.

Tracking is also not required for advertising, it only (supposedly) increases the effectiveness of it at the expense of the user. A more apt metaphor would be "restaurants are using cheap toxic chemicals to increase their revenue".

Re: Only 9% of visitors give GDPR consent to be tracked

#269
post #93

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Why would anyone consent to be tracked if given a real choice? What are the benefits? The 9% look like an error.

Consent to cookies? No big deal, my browser will erase them as soon as I close the window (and I don't reuse windows), so I click on what is easier.

They never ask for consent to track on the general sense. So I use extensions to stop that.

Re: Only 9% of visitors give GDPR consent to be tracked

#270

I wonder how much of this is the Lizardman constant. Do people even exist who actually volunteer to be tracked in exchange for nothing?

No, the entire transaction relies on coercion and/or deceit. If companies aren't going to listen, maybe it's easier to just ban any sort of unnecessary tracking across the board in order to cut down on enforcement costs, so it stops becoming a process and more of a draconian whip. We tried the carrot, it's time for the stick!
Post reply on HN