Live data from Hacker News

French watchdog fines Google, Amazon for breaching cookies rules

fr.reuters.com

101–110 of 144 posts

Re: French watchdog fines Google, Amazon for breaching cookies rules

#101
post #85
post #22

I can't help but feel that fines by countries of big corps is just so routine that it's probably part of the budget. Sure we see fines, but what happens to the money from the fines! Do they go to the users impacted - nope. Do changes happen as a result - slowly if at all. It's all kinda like some form of taxation upon the user/people as we all know any large fine upon a corporation - who ends up paying for it...the u…

That's how it works and it works well: let's be fair, the law is not always 100% clear. Some companies try to find the line, have the budget for it, and find it when they get slapped. The goal is not to kill the infringing company, it is to force them to adapt their business models. In France, as we see here in the difference in fines between Amazon and Google, the fines are not a flat rate: repeated offenses lead to…

Normally, they should be allowed to rectify the problems without getting a fine. But if you do that you don’t get the free money. It looks like the tech companies are just being treated as cash cows by governments.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#102

> The CNIL rejected the companies’ arguments that it had no right to impose the sanctions because their respective European headquarters are in Ireland and Luxembourg So they are fine with taking French money, but want to be above their laws?

This is actually a really important part of the issue.

One of the things that stops GDPR from being a total clusterfuck is the so-called "one-stop shop mechanism." Each country has its own regulator, so GDPR is enforced by 27 different government agencies. BUT, anyone only ever has to deal with one. For EU residents, the regulator of the country where they reside. For businesses, the regulator of the country of their primary establishment. Regulators are supposed to cooperate in such a way that a company has a single, local point of contact.

(Related: If US companies push for federal privacy regulation, it's because they would rather have 1 law to follow rather than 50 different ones.)

Almost all US companies establish their EU subsidiaries in Ireland for tax reasons. As a result, the Irish regulator is basically in charge of GDPR enforcement against US companies. This is... not ideal. Ireland a conflict of interest, because of the tax stuff.

(I'm not an expert on this. My understanding is that the Irish regulator seems to be operating in good faith, but is under-funded, and is going up against the legal defense teams of Google, Facebook, Amazon, etc., simultaneously, all on its lonesome.)

Several of the larger and more privacy-focused countries, like Germany and France, have been openly critical of Ireland's slow enforcement of US tech giants. In the past, CNIL (France) has said that Google's establishment in Ireland is a legal fiction rather than a legitimate business establishment. But if this gets appealed to an EU court, this is going to be a huge point of contention.

(Possibly the only point of contention, because I don't see any way that Google's actions are in compliance with GDPR/ePrivacy Directive.)

Re: French watchdog fines Google, Amazon for breaching cookies rules

#103
post #27
post #22

I can't help but feel that fines by countries of big corps is just so routine that it's probably part of the budget. Sure we see fines, but what happens to the money from the fines! Do they go to the users impacted - nope. Do changes happen as a result - slowly if at all. It's all kinda like some form of taxation upon the user/people as we all know any large fine upon a corporation - who ends up paying for it...the u…

Right, I feel this is just a new source of income for governments. They seem to be too keen on handing out fines in those areas where it‘s simple to do so, but fail to act in other areas where the consumer is constantly being hurt e.g. right to repair, warranty laws, right to return digital products.

Dieselgate is another area where where the EU completely has completely ignored when it comes to fines, outside a single town in Germany.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#104
post #76

Do these laws apply to browser local storage and all other ways to save info? And once a user says "no" to cookies/tracking how is that saved, in a cookie?

GDPR covers personal information, regardless of when or where it's stored.

The ePrivacy Directive (which is called the "EU Cookie Law," the same way that the ACA is called "Obamacare") covers reading or writing data from a user's terminal device. That will include cookie-equivalents like local storage. In fact, because it covers "reading" separate from "writing," it also includes reading browser settings like user-agent string or location/language headers, and 99% of fingerprinting techniques.

Cookies require consent unless they are essential to the service that was requested by the user. The canonical example is using a cookie to manage a user's shopping cart on an ecommerce site. Shopping is what the user has requested to do, a cookie (or moral equivalent) is basically necessary to do that, no consent required.

By extension, denying cookies is a positive action taken by the user directing the site to alter its behavior. If a cookie is needed to perform that task, it's allowed even if cookie consent has otherwise been denied.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#105
Honestly, I'm all for the GDPR but the cookie regulations are pathetic. If I store your language preference in a cookie is that the same as if I store a unique identifier so I can track you where-ever you go on the internet (as long as the site has enabled some silly facebook type button)? Of course not, it's the intent which is wrong not the simple act of offering cookies to your browser.

If they really wanted to make cookies completely optional then they should have pushed the responsibility onto browsers. At least then we'd have a consistent interface rather than some javascript which pops up 10 seconds after the page has loaded.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#106

Honestly, I'm all for the GDPR but the cookie regulations are pathetic. If I store your language preference in a cookie is that the same as if I store a unique identifier so I can track you where-ever you go on the internet (as long as the site has enabled some silly facebook type button)? Of course not, it's the intent which is wrong not the simple act of offering cookies to your browser. If they really wanted to ma…

You should probably get familiar with the actual regulation before writing such a critical comment.

Of course it takes into account the finality of the cookie (or any tracker for that matter).

Re: French watchdog fines Google, Amazon for breaching cookies rules

#107

Honestly, I'm all for the GDPR but the cookie regulations are pathetic. If I store your language preference in a cookie is that the same as if I store a unique identifier so I can track you where-ever you go on the internet (as long as the site has enabled some silly facebook type button)? Of course not, it's the intent which is wrong not the simple act of offering cookies to your browser. If they really wanted to ma…

In the case of GDPR, storing language preferences in a cookie does not need user consent because it's used to make the website work. For example session cookie, storage of what a cart, or preferences on locale storage or cookie are fine.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#108
post #102

> The CNIL rejected the companies’ arguments that it had no right to impose the sanctions because their respective European headquarters are in Ireland and Luxembourg So they are fine with taking French money, but want to be above their laws?

This is actually a really important part of the issue. One of the things that stops GDPR from being a total clusterfuck is the so-called "one-stop shop mechanism." Each country has its own regulator, so GDPR is enforced by 27 different government agencies. BUT, anyone only ever has to deal with one. For EU residents, the regulator of the country where they reside. For businesses, the regulator of the country of their…

> The GDPR does however provide for a potentially significant derogation to the 'one-stop-shop' approach. Specifically, any DPA (irrespective of whether or not they are the lead DPA) is given competency to deal with any complaint lodged against it, or deal with any breaches of the GDPR, if the case relates only to an establishment in its Member State (even if that establishment is not the 'main establishment' of the controller or processor) or substantially affects data subjects in that Member State7. In such cases, the local DPA is required to inform the lead DPA without delay and the lead DPA will have three weeks to decide whether or not the case should be dealt with via the co-operation procedure (discussed below)8.

Taken from: https://www.dataguidance.com/opinion/eu-one-stop-shop-under-...

It could be that Ireland did not react within the one-stop-shop allowed time frame, freeing France to start the procedure.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#109

Honestly, I'm all for the GDPR but the cookie regulations are pathetic. If I store your language preference in a cookie is that the same as if I store a unique identifier so I can track you where-ever you go on the internet (as long as the site has enabled some silly facebook type button)? Of course not, it's the intent which is wrong not the simple act of offering cookies to your browser. If they really wanted to ma…

You should probably get familiar with the actual regulation before writing such a critical comment. Of course it takes into account the finality of the cookie (or any tracker for that matter).

Can you direct me to the part of the regulations you are referring to?

Re: French watchdog fines Google, Amazon for breaching cookies rules

#110
post #102

> The CNIL rejected the companies’ arguments that it had no right to impose the sanctions because their respective European headquarters are in Ireland and Luxembourg So they are fine with taking French money, but want to be above their laws?

This is actually a really important part of the issue. One of the things that stops GDPR from being a total clusterfuck is the so-called "one-stop shop mechanism." Each country has its own regulator, so GDPR is enforced by 27 different government agencies. BUT, anyone only ever has to deal with one. For EU residents, the regulator of the country where they reside. For businesses, the regulator of the country of their…

The reason France could act on his own is that ePrivacy is not subject to the one-stop shop mechanisme. Each country can choose to act independantly. They are not saying that Ireland is not relevant for GDPR-related issues.
Post reply on HN