Live data from Hacker News

TikTok hit with consumer law breaches complaints across Europe

reuters.com

141–150 of 177 posts

Re: TikTok hit with consumer law breaches complaints across Europe

#141
post #82
post #29

Earlier quoted context omitted.

> They could simply present you with a yes/no modal once and be done with it Any extra modal, as simple as it might be, leads to a really bad user experience and wasted time.

Then don't place cookies that aren't necessary for the delivery of your service. There, problem solved! If invading your users' privacy is more important than your site's user experience, then the blame is on you, not the legislation.

No, legislators don't get to ignore the unintended consequences of the laws that they implement.

This applies to all laws that are passed. It is a frequent criticism and problem, of laws, is that there are often unintended consequences. And that is the fault of the law, that they did not consider the unintended consequences.

Re: TikTok hit with consumer law breaches complaints across Europe

#142

I have always promised myself that if I become a billionare, I will simply stop providing services to municipalities or countries that create arbitrary laws that make it hard or difficult to do business in. Honestly Google should have just boycotted Europe for a week and seen how well everyone handles not having gmail, google, or anything. California is particularly onerous about all sorts of stuff like labelling eve…

Side note: Can we just not heavily blur post that (maybe) downvoted heavily? I can't even read the post that I quoted atm.

Re: TikTok hit with consumer law breaches complaints across Europe

#143

Earlier quoted context omitted.

Is there no open source effort to make this easy? Or is it one of those instances where people want to do it but don't want to take the legal stands (which is completely understandable). Edit: Also if you are not selling/using this data, why can't you remove everything but session cookies? Please note I'm not a web developer so the answer can just be because it's too much work.

For us, the issue wasn’t a technical one. It was a human one. Our lawyers said we had to appoint a “Data Protection Officer” who’s job it is to respond to requests from EU persons to delete their data. We were a small company and everyone had enough on their plate as it was. Adding more work to keep <1% of revenue wasn’t worth it.

I think I can count on one hand the number of right-to-be-forgotten requests the team I work with has ever received in the last three years (with 15x the users). We've had a couple more subject access requests than that, but we'd already shipped pretty comprehensive self-service tools for retrieving data that met the vast majority of our user's needs. This doesn't seem like an unreasonable thing to expect a service to offer, IMO.

I would argue that the duties of a DPO is not more work than a small company could handle and indeed, it's slightly odd to me that a small company would think that a small handful of data erasure requests or subject access requests are a) somehow difficult to do given 30 days notice and b) somehow consume more time than the profit left over on $24k revenue buys?

Most companies here in the UK just take it in their stride and have no problems complying.

Re: TikTok hit with consumer law breaches complaints across Europe

#144

Earlier quoted context omitted.

> Honestly Google should have just boycotted Europe for a week and seen how well everyone handles not having gmail, google, or anything. I think the EU would have loved that. There are perfectly viable alternatives to pretty much everything that Google offers, some of which created in Europe. They just never gain any traction because it's convenient to just use Google for everything. I still use Gmail and Google Cale…

Out of curiosity, what are the European alternatives to GSuite?

LibreOffice, to some extent. But more pertinently, the Czech search engine Seznam[1], founded in 1996, was the most used search engine in the Czech Republic until Google took over in 2014 due to the influence of Android. Seznam is well diversified and it shouldn't be difficult for it to expand into other markets given the opportunity. It is a major regional player in search, maps, email, news, real estate, jobs, ecommerce, video streaming, advertising, and probably more. Its portfolio, which includes a chromium-based web browser, is quite impressive given that the Czech market consists of some 11 million people.

[1]: https://seznam.cz

Re: TikTok hit with consumer law breaches complaints across Europe

#145
post #143

Earlier quoted context omitted.

For us, the issue wasn’t a technical one. It was a human one. Our lawyers said we had to appoint a “Data Protection Officer” who’s job it is to respond to requests from EU persons to delete their data. We were a small company and everyone had enough on their plate as it was. Adding more work to keep <1% of revenue wasn’t worth it.

I think I can count on one hand the number of right-to-be-forgotten requests the team I work with has ever received in the last three years (with 15x the users). We've had a couple more subject access requests than that, but we'd already shipped pretty comprehensive self-service tools for retrieving data that met the vast majority of our user's needs. This doesn't seem like an unreasonable thing to expect a service t…

Unsure of how you extrapolated the total number of users from my previous statements. We were a B2B SaaS where our customers each served 10,000s of end users, who also had access to our platform with their data stored within. In aggregate we’re talking 25mm+ total users in my case.

At the time, being that the DPO role was new we didn’t know how many requests to expect. And while the law may allow for 30 days, our customers wouldn’t take it well if it took us longer than a couple days (our customer service SLA was 24 hr first resolution time). Their customers would complain to our customer who in turn would complain to us. If we make our customers look bad, we hear about it loudly and clearly.

To each their own, I suppose. From my perspective as an overworked founder, with a small team, growing at >200%/yr, we didn’t see the need to take on additional work just to maintain a very small revenue stream

I don’t fault companies for wanting to remain in the EU market, but for us, it didn’t make much sense at the time as our real growth opportunity lay in the Us/Canada (mostly due to consumer habits in the region).

I have no issue with the spirit of GDPR, and as a human, I support it personally. But, for my business at that point in time, it didn’t make economic sense to comply, so we left.

Re: TikTok hit with consumer law breaches complaints across Europe

#146
post #17

Earlier quoted context omitted.

As clear as can be yes. Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.

It's also interesting to see how Google has reacted to this. Them being the owner of Chrome, they could have implemented a new API in no time which would allow advertisers to use an alternative to cookies. An API where I as a user can define my preferences regarding targeted advertising, and the site owner can query these preferences. An API where advertisers can also store advertising-ids and more site-specific, tra…

I assume the key aspect here isn't to provide an alternative storage mechanism (since the cookie laws aren't actually about cookies themselves, but rather storage), but rather to provide a mechanism with clear and centralised user control. Users must opt-in, so its good in the eyes of the laws, but the advertisers get the benefit of easy legally-compliant tracking when a user allows it.

Re: TikTok hit with consumer law breaches complaints across Europe

#147
post #111
post #68

Earlier quoted context omitted.

No, the legislators didn't want the pop-ups to be annoying. They didn't even require pop-ups. Who wants the pop-ups to be annoying and riddled with dark patterns are the ones implementing it, exactly to cause this kind of reaction on you so you start hating the law, not the ones who are trying their best to skirt around it, to find the loopholes and abuse them. To make your experience as poor as possible while being…

"No, the legislators didn't want the pop-ups to be annoying. They didn't even require pop-ups." This is the point: the legislators were exceedingly naive, and created a bad outcome. 'National Geographic' is not evil, they are struggling and most of these sites are not giant entities with well-staffed experts. It's a good example of poorly designed legislation. "This is part of their game, make the experience miserabl…

The spirit of the law dictates that:

- The default option of consent is opt-out.

- Opt-in and opt-out should be equally easy and accessible.

Tell me how a company who would be trying to be ethical and follow this spirit would come up with the current pop-ups.

Don't blame the legislation for allowing dark patterns to be used due to loopholes or failure of prediction all possible clever tricks to circumvent the spirit described above.

It hasn't unconditionally failed, the pop-ups are still there and I opt-out of every single one of them.

Except one: schneidersladen.de - they follow exactly the spirit of the law, I put the bar there.

Re: TikTok hit with consumer law breaches complaints across Europe

#148
post #17

Earlier quoted context omitted.

As clear as can be yes. Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.

How so? Almost every single one uses cookies and I press I agree anyway because otherwise I'll be off more than half the internet.

I'm slowly starting to stop using these sites because it turns out that half of the internet is clickbait misinformation trash run by people who do not care about my privacy and who want to suck up as much data about me as possible. Its difficult sometimes, mentally, but I feel like my life is better without these garbage sites anyway. I now spend more time playing guitar, that I used to spend on the internet.

Re: TikTok hit with consumer law breaches complaints across Europe

#149
post #111
post #68

Earlier quoted context omitted.

No, the legislators didn't want the pop-ups to be annoying. They didn't even require pop-ups. Who wants the pop-ups to be annoying and riddled with dark patterns are the ones implementing it, exactly to cause this kind of reaction on you so you start hating the law, not the ones who are trying their best to skirt around it, to find the loopholes and abuse them. To make your experience as poor as possible while being…

"No, the legislators didn't want the pop-ups to be annoying. They didn't even require pop-ups." This is the point: the legislators were exceedingly naive, and created a bad outcome. 'National Geographic' is not evil, they are struggling and most of these sites are not giant entities with well-staffed experts. It's a good example of poorly designed legislation. "This is part of their game, make the experience miserabl…

> 'National Geographic' is not evil, they are struggling and most of these sites are not giant entities with well-staffed experts.

There's a very simple solution: respect my privacy and don't store or sell data about me. If you only use cookies necessary for running the site, then you don't need to do anything.

If you must track me, then do as sibling commenter said. If you store privacy-invading data about me, then you damn well better know the laws and if you don't, then sorry, you can't track me on your website.

Re: TikTok hit with consumer law breaches complaints across Europe

#150
post #17

Earlier quoted context omitted.

As clear as can be yes. Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.

Many sites ruin your experience because they don't know any better. GDPR is perceived as a Sword of Damocles by many smaller and medium sized companies and they will annoy you with elaborate consent solution for which they are paying a ton of money even if they most probably wouldn't need to do it. For the big players it is easy. They often don't annoy you with consent banners because: - they have legal departments t…

> they require your login and therefore have your consent anyway (e.g. Facebook)

Requiring you to login doesn't automatically mean consent. In fact, the laws state that you cannot make consent a requirement for using the service. You can do login without needing any consent, as cookies needed for functioning of the site are exempt, but even if it wasn't the case, opting into some doesn't automatically opt you in to all.

> they can afford to skip Cookies because they have elaborate fingerprinting solutions

The law isn't actually about cookies at all and rather about tracking/storing. Things like localstorage are counted the same as cookies. I'd have to check the exact language, but I wouldn't be surprised if fingerprinting isn't against the cookie law too.

Post reply on HN