Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

221–230 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#221
post #174

Earlier quoted context omitted.

The UK had those too while being a member.

The UK always got special treatment while they were in the EU. No other country was allowed to come even close. Which made Brexit so much more surprising to the EU.

Perhaps it's not that surprising that the curmudgeon with one foot out of the EU already decided to take the second one out as well.

Re: Grindr to be fined almost €10M over GDPR complaint

#222
post #187

Earlier quoted context omitted.

Yep, that's TrustArc These fake progress spinners are only there to deter you from opting out (hint: if you just accept all, the modal closes instantly). I wish the EU would throw massive fines at these companies, and ban the persons in charge from over working in the business again.

At least in some cases I've seen, the progress seems to be tied to a staggering number of network requests happening in the background. I've heard this explained as being necessary to communicate your opt-out to all the relevant parties, but honestly, that smells like bullshit. More likely it's designed like this on purpose, to have plausible deniability for the dark pattern.

If the default is to be opted-out, why would they even need to communicate at all with third parties? I'd say that it is bullshit.

Re: Grindr to be fined almost €10M over GDPR complaint

#223
post #92
post #16

> Grindr is now relying on a new consent system and alleged "legitimate interest" to use data without user consent. This is in conflict with the decision of the Norwegian DPA, as it explicitly held that "any extensive disclosure ... for marketing purposes should be based on the data subject’s consent". This "legitimate interest" shenanigans is coming up more and more often, where you have a modal with lots of options…

It’s almost impressive what these people have created. Now, when I stumble across the rare “Reject All” button on one of those pop ups, I don’t know if they even really mean “all” or if it keeps the trackers under “legitimate interests” enabled because they’re... “legitimate”. So the only safe option ends up being disabling all of them manually, which is absurd when these websites list hundreds and hundreds of tracke…

I've found the Reject All button _more common_ in the last few months, but due to a lot of sites that have added it also adding a legitimate interests section which is seperate, to the point I'm less trusting of sites that have recently added reject all.

For all the hate that Yahoo gets for theirs (shown above), at least it does have a mostly functional reject all function, even if it requires two button presses (the end of the footer does tell you to go manually opt out of facebook/twitter).

Re: Grindr to be fined almost €10M over GDPR complaint

#224

Earlier quoted context omitted.

No because GDPR has exceptions for state usage. Tax returns are not published but some key figures are available but you need to authenticate to retrieve it and it is logged and the log is available to the searched person.

The point is that comes across as hypocritical and makes the rationales come across as lies. "Consent for data sharing is important - except when we do it!" isn't a very good look even if there are valid reasons for tax return transparency it goes against their own stated principles.

Turns out that states have special rights. States also have a monopoly on violence.

Re: Grindr to be fined almost €10M over GDPR complaint

#225

Earlier quoted context omitted.

I meant that gdpr has no special provisions for LGBT

What do you think would be the chances of having an article 9 provision specifically mentioning 'sexual orientation' if everybody was straight? https://gdpr-info.eu/art-9-gdpr/

What would be the chances of having an article 9 provision specifically mentioning "philosophical beliefs" if everyone had the same philosophical beliefs?

Of course, people don't have the same philosophical beliefs which is a pretty caveat to the whole argument.

Re: Grindr to be fined almost €10M over GDPR complaint

#226
post #135

Earlier quoted context omitted.

TrustArc's doesn't, or at least didn't the last two times I inspected it deeply. It is possible to reproduce this claim by checking the browser inspector Network tab and by debugging trough the source code: it's just a bunch of setTimeouts. Not to mention that if there were any hypothetical API calls those could be made asynchronously after closing the modal. It's purely a dark pattern.

>Not to mention that if there were any hypothetical API calls those could be made asynchronously after closing the modal. If you did that, users wouldn't be able to see whether their opt out was successful.

It should not matter if they're following the law. Failure to access some API doesn't mean the user consented.

Like the sibling poster said, the default should be opt-out.

It's not as if this TrustArc modal is some old product that was repurposed for GDPR. This is all planned and done in bad faith, period. It's a dark pattern.

Re: Grindr to be fined almost €10M over GDPR complaint

#227
post #204

Earlier quoted context omitted.

Probably net zero, as long as everyone follows the same rules. Advertising is a zero-sum game, and changing the height of the playing field shouldn't impact relative revenue all that much.

As an advertiser, not true at all. Promoting products to any niche smaller than "man" or "woman" basically requires targeted advertising to make work.

Couldn't this be done based on content, without looking at personal data? "Here is an article on investment. How about I show an ad of an investment bank."

If only one company does it, they lose. But if everyone is forced to do it, noone will lose.

Re: Grindr to be fined almost €10M over GDPR complaint

#228
post #92
post #16

> Grindr is now relying on a new consent system and alleged "legitimate interest" to use data without user consent. This is in conflict with the decision of the Norwegian DPA, as it explicitly held that "any extensive disclosure ... for marketing purposes should be based on the data subject’s consent". This "legitimate interest" shenanigans is coming up more and more often, where you have a modal with lots of options…

It’s almost impressive what these people have created. Now, when I stumble across the rare “Reject All” button on one of those pop ups, I don’t know if they even really mean “all” or if it keeps the trackers under “legitimate interests” enabled because they’re... “legitimate”. So the only safe option ends up being disabling all of them manually, which is absurd when these websites list hundreds and hundreds of tracke…

Also the 'reject all' button is often drawn in a greyed out style to make people assume you can't interact with it. The 'accept the status quo' button is always brightly coloured and may as well have blinking arrows pointing at it...

It's honestly absurd the amount of different dark patterns they're using to try to trick users.

Re: Grindr to be fined almost €10M over GDPR complaint

#229

Earlier quoted context omitted.

The various dark patterns employed by these consent systems are fairly opaque to anyone who bothers to open them, and are clearly deliberate attempts at maintaining the old status quo of "opt-in by default". Frankly, I am surprised at how few of these fines are flying around, though I am quite happy to hear they _are_ happening. I do get that this type of regulation is very disruptive to many companies, but if they c…

I'm baffled by the number of companies that should not have any need for third-party cookies and still go full-on dark pattern. In particular online shops: I'm already on their site, why would they loudly advertise "we're shady and want to trick you into selecting all cookies"? I've cancelled more than one purchase because I didn't want to bother with this.

One expects it of many companies. But the BBC seemingly have a dark pattern here - if you follow the cookie link it shows all cookies are turned off already, so there's nothing to do, no confirmation, nada. If you don't follow the link they of course have set tracking cookies ... so the cake^w link is a lie.

IMO it would be fine to say "we were tracking you but when you followed the link we deleted those cookies and won't now set them". "Reject all", or default off ("no cookies are set, cock here to enable the committee types you wish") is better.

What's far worse is the admission that they still use ad networks even when those networks are clearly breaking the law (ie they offer no settings to disable tracking). Indeed BBC should be going further and not allowing advertisers on their network to drop cookies if a user has disabled first-party cookies. Instead they say "go to these networks and disable it yourself", good luck with that!

This from an org funded in [minor] part by taxation and whose rausin d'etre is supposed to be serving the public interest.

Re: Grindr to be fined almost €10M over GDPR complaint

#230

The GDPR has always amazed me. It changed the playing field from "you can use our free app as long as you give us data for marketing or not use it" to "you can provide a free service in the EU as long as you dont collect data for marketing or dont provide it" Without making a judgement on the merits of the approach, as a user/individual I appreciate the power this gives to protect my data. As a company/developer the…

> As a company/developer the conplexity of navigating the landmines that this poses makes me understand why a lot non EU companies decide to just block EU users. The only places I've seen actually do this are local newspapers in the US. Are there many other substantial companies doing this? In general, dropping the EU is an expensive game: it's 450 million people, including many rich developed countries. GDPR doesn't…

Also, privacy is an international trend. Many countries are enacting national GDPR equivalent. Even California enacted the Consumer Privacy Act.

I'm not even sure why GDPR is so foreign to the US. Think HIPAA for everyone, not just healthcare providers.

Post reply on HN