Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

271–280 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#271
post #228
post #92

Earlier quoted context omitted.

It’s almost impressive what these people have created. Now, when I stumble across the rare “Reject All” button on one of those pop ups, I don’t know if they even really mean “all” or if it keeps the trackers under “legitimate interests” enabled because they’re... “legitimate”. So the only safe option ends up being disabling all of them manually, which is absurd when these websites list hundreds and hundreds of tracke…

Also the 'reject all' button is often drawn in a greyed out style to make people assume you can't interact with it. The 'accept the status quo' button is always brightly coloured and may as well have blinking arrows pointing at it... It's honestly absurd the amount of different dark patterns they're using to try to trick users.

I’ve already seen websites which I (cynically) assume exploit this new-found aversion I and many others have to green buttons in cookie pop-ups by using differing colour schemes, e.g. https://hltv.org, whose “Allow all cookies” button is actually blue, whilst “Allow selection” is green.

“TrustArc” is a funny name considering it and its pals have obliterated any trust I had in this stuff.

Re: Grindr to be fined almost €10M over GDPR complaint

#272
post #270

Earlier quoted context omitted.

Yes, so we arrive at “ if I understand this correctly, it is not a problem, or a lesser or different problem ” as I first asked. I find this distinction to be bereft of a proper justification. As I said elsewhere, I cannot think of any salient reason to not cover name and address as a means to identify a person, but do cover far more obscure and unlikely biometric data. It should not be protected in any different way…

This is getting a bit off-topic, but there are good reasons why biometric data is especially sensitive. For example, the GDPR emphasizes the "right to be forgotten". If something bad happened to you, you may not want to be forever defined by that event. A kidnapped person might not want to be forever known as just a crime victim. So they can ask Google to remove mentions of their name, and they can even legally chang…

> So it makes sense to treat certain data as more sensitive.

I cannot change my name so easily as far as the Dutch government is concerned as well as that of many other European countries. I need a reason of significance and a simple “I wish to be forgotten and start a new life.” is not accepted, as it is in many European countries.

If the E.U. cared so much about this, it would mandate that it's member states permit easier name changes.

Simply put, it is easier for me in the Netherlands to have plastic surgery and change my biometric data, than it is for me to change my name so I am holly unconvinced by this argument and it seems ad-hoc to justify what is purely an irrational distinction.

> At the same time, the GDPR doesn't want to go overboard with regulation. Name and address are data that lots of businesses need to process -- eg. every online store needs to collect customer name and address and pass it on to payment providers, shipping companies, etc. It would be really inconvenient if you'd need explicit permission for each use ("Do you consent that I can tell the post office where to deliver your package?").

There are already exceptions in place in the law where data may be collected if it be essential for operations.

As it stands, companies may ask for my name and address when they have no need for it to process anything, this information can surely be used to uniquely triangulate my identity with little effort, far more effort would be required to do so with a picture of my face, or a scan of my retina.

This seems highly arbitrary and ineffective to me. I remain very much unconvinced that this distinction is one that was given any serious thought.

> Sure, someone may find a way to abuse a list of names and addresses, but it's just not as sensitive as other data.

It is far, far more sensitive.

Would you rather that your name and address be placed on H.N., or that your fingerprints or retinal pattern end up here? Would you rather a stalker have the former or the latter?

To triangulate a man's identity from biometric data requires specialized equipment, to do so from name and address is a trivial endeavor a layman can undertake.

> I think the GDPR actually strikes a great balance between protecting people's privacy and not inconveniencing businesses. If you only collect and process data that's absolutely necessary for providing your service, the GDPR won't inconvenience you much.

I do not. I find the distinction made here to be completely arbitrary and undeniable that name and address are far more sensitive and open to abuse than biometric data, the latter requiring specialized equipment to make use of.

Again, would you rather a stalker have your name and address, or your retinal scan?

Re: Grindr to be fined almost €10M over GDPR complaint

#273
post #262
post #90

Earlier quoted context omitted.

> There are also passport checks when you fly to Norway from other EU countries. This is incorrect. And the presence or absence of these checks is not a EU/EEA matter. The passport free movement is a matter of the Schengen agreement. This is why the UK had passport checks with most of continental Europe back when they were EU members (but not Schengen members). Norway is a Schengen member, and an EEA member, but not…

> This is incorrect You are right about Schengen. But I had to show my passport a couple of years ago on a flight from Vienna to Norway, so I thought they weren't part of Schengen. I'm not sure why, but I believe the reason must have been the "temporary border controls" introduced in 2015.

Yes. But that was a temporary, exceptional situation of border checks all over Europe.

Re: Grindr to be fined almost €10M over GDPR complaint

#274
post #270

Earlier quoted context omitted.

Yes, so we arrive at “ if I understand this correctly, it is not a problem, or a lesser or different problem ” as I first asked. I find this distinction to be bereft of a proper justification. As I said elsewhere, I cannot think of any salient reason to not cover name and address as a means to identify a person, but do cover far more obscure and unlikely biometric data. It should not be protected in any different way…

This is getting a bit off-topic, but there are good reasons why biometric data is especially sensitive. For example, the GDPR emphasizes the "right to be forgotten". If something bad happened to you, you may not want to be forever defined by that event. A kidnapped person might not want to be forever known as just a crime victim. So they can ask Google to remove mentions of their name, and they can even legally chang…

As another note on your claim of the necessity of address:

It would be absolutely trivial to implement a system where one might requæst a randomly generated code with the postal service, that can be placed on a letter that maps to one's real address, except of course, that the real address cannot be retrieved from it, which is hidden with the postal service.

With such a trivial scheme, it would be possible to receive mail without having to leak one's place of residence to the sender, simply give them such a code, which could even be set to expire within a set timeframe, at which point the postal service deletes the connexion to one's real address, for fear their data be leaked.

It's trivial; it's of far greater importance than the sensitivity of biometric data, yet it is not there.

I can only gander it's not, because the E.U. is extremely arbitrary at what points it cares about one's privacy. Name and address are absolutely, as I argued elsewhere, some of the most sensitive data available, and there are trivial measures that could be taken to secure it better, yet these are not implemented, for the E.U. is extremely arbitrary and not rational in it's decisions.

Re: Grindr to be fined almost €10M over GDPR complaint

#275

Question in regards to the user consent pop-ups on websites: On sites that continue to let you browse without making a selection (say the consent banner in on the bottom of the browser window), If I don't make any choice, accept or reject, what happens? Am I giving consent by default?

No, you aren't.

Re: Grindr to be fined almost €10M over GDPR complaint

#276

Earlier quoted context omitted.

I'm baffled by the number of companies that should not have any need for third-party cookies and still go full-on dark pattern. In particular online shops: I'm already on their site, why would they loudly advertise "we're shady and want to trick you into selecting all cookies"? I've cancelled more than one purchase because I didn't want to bother with this.

One expects it of many companies. But the BBC seemingly have a dark pattern here - if you follow the cookie link it shows all cookies are turned off already, so there's nothing to do, no confirmation, nada. If you don't follow the link they of course have set tracking cookies ... so the cake^w link is a lie. IMO it would be fine to say "we were tracking you but when you followed the link we deleted those cookies and…

They use ad networks only outside the UK, so the taxpayers are not tracked by these networks. They're very explicit about it in their cookies explanation: 'Set your cookie preferences for performance cookies. And if you’re outside the UK you can set your preferences for personalised advertising.'

Re: Grindr to be fined almost €10M over GDPR complaint

#277

Earlier quoted context omitted.

A fairly substantial part of the Grindr usrbase is made up of ostensibly straight married family fathers.

Wouldn't that be "bi[-curious] married family fathers", mainly, assuming you're not suggesting they all fathered children against their will. Or, maybe you mean people who never had/never intended to have homosexual sex? Are there published stats you're referencing?

I mean men who have self-internalized being straight due to living in a homophobic society. And I speak from personal experience as a long time Grindr user.

Re: Grindr to be fined almost €10M over GDPR complaint

#278
post #256

Earlier quoted context omitted.

In theory, yes, in reality, no. The strongest, biggest signal of what ads people will click is what kind of ads they clicked in the past. Content based ads have really bad performance comparably.

> biggest signal of what ads people will click is what kind of ads they clicked in the past. Content based ads have really bad performance comparably. Has anyone actually compared this over long stretches of time and compared apples to apples, not apples to oranges? Additionally, most people don't want personalized ads based on tracking: https://www.emarketer.com/content/do-people-actually-want-pe...

No one denies that they don't want it.

I'm sure customers also don't want planned obsolescence. — it is very good for business, however.

Re: Grindr to be fined almost €10M over GDPR complaint

#279

Earlier quoted context omitted.

> biggest signal of what ads people will click is what kind of ads they clicked in the past. Content based ads have really bad performance comparably. Has anyone actually compared this over long stretches of time and compared apples to apples, not apples to oranges? Additionally, most people don't want personalized ads based on tracking: https://www.emarketer.com/content/do-people-actually-want-pe...

No one denies that they don't want it. I'm sure customers also don't want planned obsolescence. — it is very good for business, however.

There's very little planned obsolescence anywhere. It's more about racing to the bottom and building the chepest possible product that will hold for a while.

Re: Grindr to be fined almost €10M over GDPR complaint

#280

Earlier quoted context omitted.

No one denies that they don't want it. I'm sure customers also don't want planned obsolescence. — it is very good for business, however.

There's very little planned obsolescence anywhere. It's more about racing to the bottom and building the chepest possible product that will hold for a while.

Planned obsolescence is a tricky term and has many faces (see e.g. a classification at [0]). A good and widespread example of overt, in-your-face planned obsolescence (surprisingly not mentioned in the article I linked) is "fast fashion", where nobody even tries to hide that clothing is designed to deteriorate quickly, to accommodate a season-long replacement cycle.

I think race to the bottom deserves to be its own type of "planned obsolescence" (again, not mentioned in the Wikipedia classification). While in a highly competitive market, the design process may boil down to "do the same as competitor X, but slightly cheaper" instead of explicitly setting the durability target low, the end result is the same - products that have no business existing enter the market, live very briefly, and forever enter the waste stream. It's a systemic problem, and it's planned in the sense that if you enter such a market, you've already decided to create short-lived trash.

--

[0] - https://en.wikipedia.org/wiki/Planned_obsolescence#Types

Post reply on HN