Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

191–200 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#191
post #156

Earlier quoted context omitted.

With that they win the public's opinion. I make an effort to always explain to people I hear complaining about those pop-ups why they've been made to be annoying. Usually it helps to turn their opinion against GDPR towards the companies employing the dark patterns. No one likes to be blatantly manipulated.

I think that's a long lost battle and they know it. They're going for attrition. People don't want to be tracked, and clicking all the don't track buttons 78 times a day is annoying, so eventually they say fuck it and just start clicking Accept All. There need to be fines for this. They're clearly violating the spirit of the law, if not the exact letter (and I think much of Europe has legal systems that follow the sp…

They're often violating the letter too.

I'm in favor of a lot more fines, and substantial fines. Few companies need to be made example of. The current situation does further damage to how EU citizens perceive GDPR and EU itself - companies do their best to make the consent control experience as bad and tiresome as possible, and then they tell people to blame GDPR for how web browsing just got more annoying.

Re: Grindr to be fined almost €10M over GDPR complaint

#192

So presumably the Norwegian government will be fined for publishing everyone's tax returns then :-)

No because GDPR has exceptions for state usage. Tax returns are not published but some key figures are available but you need to authenticate to retrieve it and it is logged and the log is available to the searched person.

The point is that comes across as hypocritical and makes the rationales come across as lies. "Consent for data sharing is important - except when we do it!" isn't a very good look even if there are valid reasons for tax return transparency it goes against their own stated principles.

Re: Grindr to be fined almost €10M over GDPR complaint

#193

Earlier quoted context omitted.

Well, now the GDPR gives you 10% of your revenue as a reason for not using SDKs that will not give you control of data collection. You always had "respect the privacy of users" as a reason not to use them before, but we all know how well that worked.

The problem here is that if you want to implement Facebook login in your app, you have to include the SDK. It is against ToS to do it any other way.

Well, if that SDK contains tracking stuff, the question then becomes whether the SDK has an opt-out option. If yes, it's on the consumer of the SDK. If not, then whether the TOS is enforceable in Europe.

Re: Grindr to be fined almost €10M over GDPR complaint

#194
post #16

> Grindr is now relying on a new consent system and alleged "legitimate interest" to use data without user consent. This is in conflict with the decision of the Norwegian DPA, as it explicitly held that "any extensive disclosure ... for marketing purposes should be based on the data subject’s consent". This "legitimate interest" shenanigans is coming up more and more often, where you have a modal with lots of options…

Most of these data consent forms are purposefully complicated so that many opt in to all to save time. The “advanced options” menu even loads suspiciously slowly at times. It should be required by law that there be a simple to access “opt out to everything” option that should be as easy to access as an “opt in to everything” option. Also, I would not be opposed if some browser standard were developed under government…

> It should be required by law that there be a simple to access “opt out to everything” option that should be as easy to access as an “opt in to everything” option.

It arguably is already required with the language of article 7.2 and recital 32, especially this part

> If the data subject’s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

But we will see how it gets interpreted as more cases works their way through the system.

Re: Grindr to be fined almost €10M over GDPR complaint

#195
post #187
post #123

Earlier quoted context omitted.

On some websites I get a tracking / cookie consent popup which, if I choose not to consent to everything, leaves me hanging for a _very_ long time while "saving my settings". I am talking about 30-60 seconds here. That must be deliberate to keep you from denying consent. I forgot which company it was but I immediately recognize those popups.

Yep, that's TrustArc These fake progress spinners are only there to deter you from opting out (hint: if you just accept all, the modal closes instantly). I wish the EU would throw massive fines at these companies, and ban the persons in charge from over working in the business again.

At least in some cases I've seen, the progress seems to be tied to a staggering number of network requests happening in the background. I've heard this explained as being necessary to communicate your opt-out to all the relevant parties, but honestly, that smells like bullshit. More likely it's designed like this on purpose, to have plausible deniability for the dark pattern.

Re: Grindr to be fined almost €10M over GDPR complaint

#197

Earlier quoted context omitted.

Well, now the GDPR gives you 10% of your revenue as a reason for not using SDKs that will not give you control of data collection. You always had "respect the privacy of users" as a reason not to use them before, but we all know how well that worked.

The problem here is that if you want to implement Facebook login in your app, you have to include the SDK. It is against ToS to do it any other way.

Seems like the specific problem there is Facebook enticing you to break the law. You could try filing a complain with some appropriate data protection agency.

Re: Grindr to be fined almost €10M over GDPR complaint

#198
post #168

Earlier quoted context omitted.

Doesn't GDPR require opt-in for tracking? So as long as you didn't interact with the banner, _every_ page load should take ~60s?

Of course they have to track that they aren’t tracking you, or else you would get the consent banner repeatedly on every page load.

The actual way this should be implemented, if they wanted to be morally irreproachable, would be this: a consent popup always available, tucked down somewhere in the corner of the site. It defaults to opt-out from everything, you can click on it to expand it if you want to opt into something.

An acceptable option is to pop up a consent form as needed, and set a cookie recording whether user made a consent decision. That can be classified as essential cookie to fulfill a legal obligation.

Re: Grindr to be fined almost €10M over GDPR complaint

#199

Earlier quoted context omitted.

Most of these data consent forms are purposefully complicated so that many opt in to all to save time. The “advanced options” menu even loads suspiciously slowly at times. It should be required by law that there be a simple to access “opt out to everything” option that should be as easy to access as an “opt in to everything” option. Also, I would not be opposed if some browser standard were developed under government…

> It should be required by law that there be a simple to access “opt out to everything” option that should be as easy to access as an “opt in to everything” option. It arguably is already required with the language of article 7.2 and recital 32, especially this part > If the data subject’s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disrupti…

Yes, that is very arguable.

The phrasing “The-opt-out-to-everything option must be as easily accessible as the opt-in-to-everything option.” is far less arguable and hiding one behind a further menu, but one not, is a clear violation of this rule.

Re: Grindr to be fined almost €10M over GDPR complaint

#200

Earlier quoted context omitted.

You can advertise without bulk collection of personal data.

What kind of financial losses are we realistically talking about from being denied such tracking? what kind of percentages of lesser revenue?

Probably net zero, as long as everyone follows the same rules. Advertising is a zero-sum game, and changing the height of the playing field shouldn't impact relative revenue all that much.
Post reply on HN