Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

181–190 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#181
post #104

Earlier quoted context omitted.

"legitimate interest" is a legal term with specific definitions in the GDPR. (And indeed it refers to the interest of the site , not yours) IANAL, but as I understand, it refers to data collection that is inherently needed to perform a service. E.g., a pizza delivery service has a legitimate interest to know the address of the place where it should deliver the pizza to - because, well, otherwise they can't deliver th…

> because, well, otherwise they can't deliver the pizza. This is covered by one of the five other GDPR principles for lawfully processing data ("to fulfil contractual obligations..."), so it wouldn't be considered a legitimate interest. An example of legitimate interest would be the Pizza Place keeping your address on their phone system, so that when you call from the same number on a future date, they can confirm yo…

It can also be for advertising. It's very unclear where the line is: of course Facebook has an interest in tracking you, it legitimately makes them money. Afaik that's what this purpose is for. But it should also be weighed how reasonable versus invasive it is. The data protection authorities are clear on how they see it (namely as mostly a dummy clause that rarely lets you do anything) but it has yet to be seen how this holds up in court.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#183
post #179

Earlier quoted context omitted.

Legitimate Interest has a legal definition as a Legal Basis. It's a list of Purposes and Special Features that a Vendor declares to the IAB that they claim to need [0]. A User absoultely has the right to Object to Consent and Legitimate Interest. Any CMP that does not allow you to opt-out is on shaky GDPR legal ground. [0] https://vendor-list.consensu.org/v2/vendor-list.json (see 'vendors' object)

What's an IAB or CMP?

Internet Advertising Bureau, Consent Management Platform

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#184

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

Guy in IT sec recently: some companies reduced their yearly pentesting budget and spend the money on a GDPR paper trail instead. Compliance on paper more important than actual IT security.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#185
post #131

I am working as a developer for a medium sized publisher in germany. Im pro GDPR and dont like the way the industry treats the users. But they just seem to continue on their course. Reaction on GDPR was very slow. Cookie Banners (before GDPR) where ignored. When GDPR was there we started to implement regular cookie banners - despite the warning from us developers that this would be illegal. The first real reaction on…

>>The first real reaction on GDPR came at that moment Google forced them to. There was a deadline (somewhere in february 2021) where Google would limit ads if no consent-manager is implemented.

The irony is that the Cookie warning you get on all Googles sites are including all the dark patterns and seems to be there only to pretend they follow the law. All is op-out by default and you have to dig through many settings to turn off tracking

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#186
post #184

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

Guy in IT sec recently: some companies reduced their yearly pentesting budget and spend the money on a GDPR paper trail instead. Compliance on paper more important than actual IT security.

This shows that they consider GDPR fine possible, thus making it a more worthwhile risk. There risk of penalties from cyber attack unpreparedness is essentially zero.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#187
post #181

Earlier quoted context omitted.

> because, well, otherwise they can't deliver the pizza. This is covered by one of the five other GDPR principles for lawfully processing data ("to fulfil contractual obligations..."), so it wouldn't be considered a legitimate interest. An example of legitimate interest would be the Pizza Place keeping your address on their phone system, so that when you call from the same number on a future date, they can confirm yo…

It can also be for advertising. It's very unclear where the line is: of course Facebook has an interest in tracking you, it legitimately makes them money. Afaik that's what this purpose is for. But it should also be weighed how reasonable versus invasive it is. The data protection authorities are clear on how they see it (namely as mostly a dummy clause that rarely lets you do anything) but it has yet to be seen how…

The attitude of the UK's ICO seems to be quite lax - it gives as an example "you do not want to give the individual full upfront control (ie consent)" with the implication that if you don't want to ask for consent, it's a legitimate interest.

I expect the first point of divergence between UK GDPR and EU GDPR might be here (since they are now separate), in how 'legitimate interest' is interpreted in the law.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#188

GDPR is a textbook example of how government intetvention in our business never ends in the way the technocrats desire/promise. It simply makes things more convoluted and difficult for everyone including those they claim to be protecting.

You have it backwards, this is big companies doing what they can to protest a law they don't agree with. Much in the same way big tobacco and big oil for years have been combating science

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#189

Earlier quoted context omitted.

I feel like this is a point the HN crowd likes to ignore when it calls for governments to regulate certain aspects of tech. Do regulations like this really protect consumers, or just make their experience worse?

That point has been beaten to death here in case of GDPR, though. The problem isn't with regulation, but enforcement. The fines aren't applied nowhere near enough, so almost no site cares. The consumer experience being worse is, in a large way, purposeful UX degradation done by the sites themselves. The typical consent popup tries to simultaneously walk the line between "illegal under GDPR" and "just scummy" (often c…

Did I have to deal with these popups before GDPR? No. Was I blocked from accessing many US sites before GDPR? No.

If EU cancels GDPR would everything go back to normal? Probably.

As an unhappy consumer, that's all I need to know. The cause and effect is pretty obvious here.

Sure, some people may be happy (I hope?!) with whatever privacy benefits GDPR is supposed to bring about. But blaming websites for responding to EU regulation one way or another, doesn't make me, who doesn't care about these supposed benefits, feel any better. If GDPR people feel like this is a cost worth paying then so be it. I certainly don't believe more enforcement will somehow make companies come up with fewer legal derisking strategies.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#190

For me personally - all these popup banners and modal walls for websites about cookies and stuff just really make the internet a worse place. I suspect that empirically, they don't accomplish what the GDPR intended to - and they make the internet less enjoyable. Thanks GDPR.

Imagine that, an EU regulation resulted in nothing but unintended consequences and close to zero benefit to anyone -- unless you count consulting gigs of course. Who could have possibly foreseen this!

All this talk about how the problem is lack enforcement is an absolute riot. Hey, I've got an idea! Let's write another law to address the lack of enforcement. Uh, even better, a third one to address the dark patterns!

(I'm very sorry for the low value comment but I've apparently got a condition where I am physically unable to resist the urge when the topic is rage inducing enough.)

Post reply on HN