Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

281–290 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#281

Earlier quoted context omitted.

Under GDPR consent can’t be “freely given” when it’s bundled as a condition of service unless the consent they’re asking for is necessary in order to perform the service. To use your example: The grocery store doesn’t need to ask if you consent to paying for an apple because if you didn’t consent there wouldn’t be any transaction to perform. Now if you paid for your apple and the cashier said okay hand over your phon…

> GDPR says they have to ask you first (usually in the form of a giant irritating banner as soon as you walk in the door) and that if you say no they have to let you buy your apple anyway. Can you link to source for this (the part that says you can't deny access)?

Perhaps I’ve oversimplified a bit. GDPR has a paragraph that’s often called the “coupling prohibition” - Article 7(4):

> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

It somehow says a whole lot and not much at the same time. Since every member state and everyone who has to comply needs to interpret what GDPR means there are various “recitals” that offer official guidance. One of those is Recital 42 - Burden of Proof and Requirements for Consent[1] which says:

> Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

So a person must be able to refuse consent “without detriment” and the company is meant to provide an equivalent, but necessarily identical, service to those who do not consent.

What that means exactly is, of course, the subject of much litigation. For example is it a “detriment” to require a subscription fee to those who do not consent to information sharing? So far one ruling (Austria) has said no, provided the fee is reasonable while another (UK) has said yes, the equivalent service must also be free.

As far as how the coupling prohibition should or will apply to a company like facebook - where harvesting user data is the entire business model - I think that is yet to be clearly determined. As are most of the nuances and technicalities in GDPR.

Edit: I should also note that consent is just one avenue to legally allow a company to process user data under GDPR. It’s not the only avenue.

[1]https://gdpr-info.eu/recitals/no-42/

Re: Only 9% of visitors give GDPR consent to be tracked

#282

I hate ads as much as everybody else, and this reads to me like "given the choice only 9% of people would pay for their meal", should we forbid charging for food then? Probably not. As sad as the current ads-powered internet is becoming I haven't seen any promising viable alternative, and sure non-tracking-based ads is not the same thing as having no ads, but it significantly moves the needle in that same direction i…

That metaphor falls apart on multiple levels. Paying for a meal is a transaction that both parties explicitly agree to. Tracking in its current state is mostly done without the consumers awareness/consent. Tracking is also not required for advertising, it only (supposedly) increases the effectiveness of it at the expense of the user. A more apt metaphor would be "restaurants are using cheap toxic chemicals to increas…

I agree with you on the non-transactional nature of advertisement, as far as viewers are concerned, the metaphor is perhaps only effect at illustrating how given the choice most people would prefer to have free stuff at the cost of everything else (e.g. free meals or free content and services).

Tracking is not strictly necessary for having ads, but for having _effective_ ads I would argue at least in some cases it makes all the difference. For example I don't care one bit about cosmetics, if a cosmetics company advertises to me it's going to waste its money, and if the company has an increased chance of wasting its money than the ad space is worth less, meaning the website owner gets paid less, meaning that eventually after some threshold is reached offering the content or services via the ads model becomes unsustainable.

Re: Only 9% of visitors give GDPR consent to be tracked

#283
post #276

If I need to figure out what they’re actually asking I’m out. This article makes it clear the majority of these consent boxes are not really compliant. On a side note if someone says they’re in advertising I automatically hate them, this terrible I know, but they’re usually pompous assholes and that’s how I feel of that industry as a whole.

> if someone says they’re in advertising I automatically hate them

You might enjoy Bill Hicks’ take: https://youtu.be/tHEOGrkhDp0

Re: Only 9% of visitors give GDPR consent to be tracked

#284
post #101
post #93

Earlier quoted context omitted.

Why would anyone consent to be tracked if given a real choice? What are the benefits? The 9% look like an error.

I know people who just automatically click yes. I don't think they ever even cared to read what is says. They just have the habit to click yes to every prompt to "make sure it works"

Decades of bad UI design have trained people to click away these kinds of things without reading them. Even people like you or I who should otherwise know better frequently do it.

Re: Only 9% of visitors give GDPR consent to be tracked

#285

Fundamentally, the browser is the user's agent. Storing cookies, running tracking scripts, etc. should be controlled by the browser. Some browsers may take a strict "block everything" approach, some may be relaxed, and some may harass the user with prompts. Users are free to choose the appropriate browser. Depending on websites to limit tracking by on their own is very difficult, since it is inherently against many w…

Browsers do provide these controls to users. You don't have to switch between them. More fine grained customization is possible with extensions, assuming you can trust extensions authors and the browser you're using supports them.

Re: Only 9% of visitors give GDPR consent to be tracked

#286

Earlier quoted context omitted.

Incognito basically just means "doesn't show up in my history". There are many, many, ways to track users without needing cookies.

> doesn't show up in my history AND drop all cookies from all domains. > There are many, many, ways There probably are. I haven't ever seen it work though. If I get into incognito, my ads show something different my normal profile. In theory, they can track you from your OS/browser combination (and many more variables), but is there a way to test it?

It isn't theoretical. Google is currently facing a lawsuit (Brown et al v Google LLC et al) for tracking people who assumed Chrome's incognito meant Google would stop tracking them. [0]

[0] https://www.gizmodo.com.au/2020/06/google-facing-us5-7-billi...

Re: Only 9% of visitors give GDPR consent to be tracked

#287

I hate ads as much as everybody else, and this reads to me like "given the choice only 9% of people would pay for their meal", should we forbid charging for food then? Probably not. As sad as the current ads-powered internet is becoming I haven't seen any promising viable alternative, and sure non-tracking-based ads is not the same thing as having no ads, but it significantly moves the needle in that same direction i…

A meal paid for by money is a transaction where both parties understand what’s being exchanged. Not paying for it criminal. A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down?

> A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down?

I'm not sure that'd be viable in general, like what would the economic impact globally if all websites that barely can manage to keep the lights on today because of effective ads just disappeared? Maybe the impact could be even positive, like by disallowing politically very-targeted ads, among all other kinds of targeted ads, maybe we can prevent idiots from being elected, but if I had to guess I'd say I wouldn't like to see those websites disappear.

Like imagine if YouTube disappeared because it can't make enough money to host all that staggering amount of content.

Re: Only 9% of visitors give GDPR consent to be tracked

#288
post #251

Why would one need GDPR consent for blog? Privacy Policy should be enough for server logs (without PII). It would be nice to have standard Privacy Policy though (like we have MIT, BSD licenses).

I run a blog. It has Google Analytics. I could probably host my own analytics solution, but that's not easy. I'll get to it eventually, but content benefits my users more. I need analytics because this blog pays the bills. I need to see what works and what doesn't. When building partnerships, I'm usually expected to share some numbers with them. It also lets me spot issues with the website.

Thank you, I understand convenience for author / inconvenience for reader.

I do not use Google Analytics but it looks like it is possible to disable Cookies [1], anonymize IPs, disable data sharing with google [2]. Effectively making it almost third party server logs analytics (no consent required). Would remaining functionality be sufficient for you?

[1] https://law.stackexchange.com/questions/36105/can-usage-of-g...

[2] https://law.stackexchange.com/questions/35528/is-it-really-p...

Re: Only 9% of visitors give GDPR consent to be tracked

#289
complain complain complain. these threads exist so that people can gripe, together. it's tiring.

instead let's talk about solutions.

safari's cookie and localStorage policy is great and automatic. beyond that, firefox containers are good, albeit effectively limited to isolating a few "top sites" like FB. and then of course, UBO, ABP, ghostery and the like.

it's actually not that hard to take a few small steps (or just do the default things on MacOS) to stop this from affecting you, without impacting your (ahem) user journeys.

first-order fixes are easy. now let's get ahead of these assholes and work on fixing fingerprinting.

TFA is ironically quite interesting in that it itself is SEO content, aka an ad. targeting those that care about not being targeted. i, for one, have bookmarked it.

Re: Only 9% of visitors give GDPR consent to be tracked

#290

I signed up for a new account on a fitness website yesterday. They track health and food and diet you enter. anyway, during the sign up they had a opt out, I chose to do just that, however the opt out process then took over the screen with a modal window, which gave a loading bar and took about thirty seconds to complete... But guess what... There was a big CANCEL button. I couldn't perform any action during sign up…

for apps like this why does anyone sign up with their real name, email, and/or demographic info? get a throwaway email and there you go.

i can't remember the last time i used my real info or email.

although there was a case just last week where a site "needed" my phone number. in 2 seconds flat i decided i didn't need that service.

of course without a legit email you can't, or it's much++ harder for account recovery, but i can live with that.

Post reply on HN