Only 9% of visitors give GDPR consent to be tracked
411–420 of 457 posts
Re: Only 9% of visitors give GDPR consent to be tracked
#412Earlier quoted context omitted.
I work on mobile apps, and I can promise there's no tracking on the apps I've been building if you opt out. The SDKs I've seen seem to do what they promise: no communication to backend when tracking is disabled. Of course, I can only speak for the apps I've been building and SDKs I've used.
Do you have to explicitly opt out to stop tracking? If so, are you sure your apps are GDPR compliant?
Re: Only 9% of visitors give GDPR consent to be tracked
#413If you need a reminder every single freaking time you visit a website, that's your problem not the government's. If you don't want them, turn them off in your browser, install a blocking/auto-wipe extension, use lynx, whatever you want.
Now, I completely agree that websites should clearly state what they are doing with data the user uploads, if it is end-to-end encrypted, etc. The user otherwise has no way of knowing, and it is material to assessing the accuracy of the often-BS "military-grade security"-type marketing and other claims like that. But there is no need for users to "consent" to using a public API of their web browser.
Re: Only 9% of visitors give GDPR consent to be tracked
#414Earlier quoted context omitted.
Some people would rather have products they are interested in rather than products they aren't interested in
Some people would rather have products relevant to the site they are on rather than products irrelevant to the site they are on
Re: Only 9% of visitors give GDPR consent to be tracked
#415Earlier quoted context omitted.
I have the complete opposite view. Companies provably can't be trusted on anything touching privacy, and individuals don't have any power to act on it. Governmental oversight and bureaucracy is the only tool that works for a problem like this. It's a proven, efficient, and universally approved way to already enforce food, fire, travel safety and so on. It's only logical that privacy safety follows the same steps. GDP…
But privacy isn't like food, fire or travel safety. Even assuming absolute cynicism it isn't very exploitable for them to use it for bad purposes. I liken the difference between actors to a housecat and a large dog with a lamb. The cat at worst could give some scratches but at worst would probably just annoy the lamb jumping into its wool and kneading it. The dog ideally would look after tbe lamb but could also infli…
Re: Only 9% of visitors give GDPR consent to be tracked
#416Earlier quoted context omitted.
I don't see how the first option is not GDPR-compliant. If the privacy policy page doesn't process personal data there is no consent needed.
I'm going to quote Article 7.4. of the GPDR here: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract." Preventing you from seeing the page you request if you do not consent seems…
You are correct. However, the prohibition against "a service conditional on consent" can be overcome (inter alia means "among other things") and one of the ways it can be overcome is if the user is given a choice to instead select "a consent-free equivalent service for a reasonable remuneration."[1]
This is the result of a ruling by the Austrian Data Protection Authority (DPA) evaluating an case in which users could access an Austrian newspaper by either (a) consenting to personalized advertising or (b) paying a subscription fee of 6 Euro / month.
The DPA found that these options were not considered a "significant detriment" to users (i.e. it was not considered coercive) and was therefore valid.
It's worth noting that the UK found otherwise, saying that "for the user to have a genuine choice, a consent-free alternative would have to be offered free of charge."[2]
-----
[1] Austrian Data Protection Authority (case no. DSB-D122.931/0003-DSB/2018)
[2] Validity of consent coupled with free online services - Chair of EDPB opens a path https://www.lexology.com/library/detail.aspx?g=5125ca7c-84fa...
Re: Only 9% of visitors give GDPR consent to be tracked
#417Earlier quoted context omitted.
Outside of HN, most content creators, especially professionally, don't have the option to make significant changes to the platform on which their content is published. I agree that an entire publication's site can be trash, but good writers can still write on bad platforms.
They do as much as engineers at Google or Facebook do to change their companies. That is to say, each one cannot make much of an impact, but the responsible thing to do would be to not contribute or at least openly advocate for change from within. If enough people inside shift, then change can happen.
Re: Only 9% of visitors give GDPR consent to be tracked
#418Earlier quoted context omitted.
I don't see how the first option is not GDPR-compliant. If the privacy policy page doesn't process personal data there is no consent needed.
I might not be understanding your point but: - consent requires, among other things, that permission be given freely ;[1] - so, if coercion is involved then consent does not exist;[2] - and, preventing user access to content unless that user agrees to be tracked is likely considered to be coercive. Therefore if a user grants permission to be tracked only in order to gain access to that site's content, that granted pe…
I wanted to add that the freely given requirement can be very granular / fact intensive. This later comment shows one way (renumeration) the above can be accomplished without coercion: https://news.ycombinator.com/item?id=23762945
Re: Only 9% of visitors give GDPR consent to be tracked
#419Earlier quoted context omitted.
I'm going to quote Article 7.4. of the GPDR here: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract." Preventing you from seeing the page you request if you do not consent seems…
>Preventing you from seeing the page you request if you do not consent seems a lot like the provision of a service conditional on consent. You are correct. However, the prohibition against "a service conditional on consent" can be overcome ( inter alia means "among other things") and one of the ways it can be overcome is if the user is given a choice to instead select "a consent-free equivalent service for a reasonab…
Re: Only 9% of visitors give GDPR consent to be tracked
#420What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…
Someone should write the next level of counter measures that just sends a bespoke cookie that contains the do not track info based on patterns similar to ad block - without ever having visited the site beforehand. Or if that's not working for some sites pretend you accept tracking but just forge the tracking ids with random data every visit