Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

51–60 of 195 posts

Re: Statement on 4 Years of GDPR

#51

Earlier quoted context omitted.

And if they did that it would also make them GDPR compliant. They chose to put up cookie banners as a way of making to seem like the people making the laws told them to do it. > 99% are just fake. If you reject cookies you keep get them This is silly. The rule is that people are allowed to opt 𝚘̶𝚞̶𝚝̶ in to tracking. Just because some companies use cookies for this doesn't mean that cookies are banned. If you are u…

> The rule is that people are allowed to opt out of tracking Sorry to correct you, but the rule is that people are allowed to opt-in to tracking. This fundamental misunderstanding is kinda the problem...

Sorry, yes this is correct.

And even after opting in, you are allowed to opt out.

Re: Statement on 4 Years of GDPR

#52
post #23

GDPR broke one of my websites that had tens of thousands of happy users. Users loved it and expressed their delight that the website exists on a daily basis. But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody. Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense. So I finally took the plunge a…

It sounds like you encountered a small hurdle and chose to give up. Hundreds of thousands (millions?) of websites are GDPR compliant while running ads.

I have thrown quite a lot of work at it.

Reading into it, looking up the legalese, building a solution that shows a cookie banner and prevents ads to load before users agreed to it etc.

I only gave up after all of that failed.

It just became unjustifiable to throw more time at it.

Re: Statement on 4 Years of GDPR

#53
post #23

GDPR broke one of my websites that had tens of thousands of happy users. Users loved it and expressed their delight that the website exists on a daily basis. But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody. Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense. So I finally took the plunge a…

Is there really no way to monitise an audience with ads without collecting their personal info? That seems more of a problem than GDPR exposing that underlying issue. edit: seems like Google have a non-personalised ad option, but it still uses cookies: > A Non-Personalized Ads solution (Ad Manager Help Center, AdSense Help Center) allows you to present EEA and UK users with a choice between personalized ads and non-p…

> Is there really no way to monetise an audience with ads without collecting their personal info?

There sure is: Contextual ads. DuckDuckGo does it, various documentation sites do it (https://www.ethicalads.io/), a dutch broadcaster does it (https://archive.ph/Zk4Pv). It's how newspapers used to work and TV channels still do, as well as YouTube sponsorships (and probably many more).

It improves the UX over personalized ads because

a) you don't have to invade your users' privacy (including asking them for permission to do it, obviously) and

b) the ad is actually relevant to the context the user is thinking about, instead of something completely unrelated from some other part of their life (or, more often than not, something completely random).

Re: Statement on 4 Years of GDPR

#54
post #52

Earlier quoted context omitted.

It sounds like you encountered a small hurdle and chose to give up. Hundreds of thousands (millions?) of websites are GDPR compliant while running ads.

I have thrown quite a lot of work at it. Reading into it, looking up the legalese, building a solution that shows a cookie banner and prevents ads to load before users agreed to it etc. I only gave up after all of that failed. It just became unjustifiable to throw more time at it.

Sounds like about 5 minutes of work to me: https://support.google.com/adsense/answer/7670013?hl=en

Re: Statement on 4 Years of GDPR

#55
post #37
post #14

Earlier quoted context omitted.

In theory yes, but so far they haven't brought the hammer onto anyone of formidable size.

Amazon Europe Core S.à.r.l. Industry and Commerce LUXEMBOURG 746,000,000 euro Non-compliance with general data processing principles 16 Jul 2021 WhatsApp Ireland Ltd. Media, Telecoms and Broadcasting IRELAND 225,000,000 euro Insufficient fulfilment of information obligations 02 Sep 2021 https://www.enforcementtracker.com/?insights

This link gets posted all the time but if you compare the total amount fined across all companies and all countries it's laughable compared to the profits a single big offender (see Google, Facebook, etc) makes in just a year.

Re: Statement on 4 Years of GDPR

#56
This article is excessively negative on the effectiveness of the law.

I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated.

Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

Re: Statement on 4 Years of GDPR

#57
post #31
post #29

Earlier quoted context omitted.

GDPR aside, I had similar shock after getting a few million users for a viral language game, but finding that basically nobody was willing to sponsor it on Patreon, even to a level to cover the basic hosting costs. It was a little hard to process at the time.

What did you ultimately do with it?

it is kill http://greatlanguagegame.com/

Re: Statement on 4 Years of GDPR

#58
post #26

Cookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.

> 99% are just fake. If you reject cookies you keep get them

Note that cookies that are technically required to serve the site don't need a cookie banner. This is something many people get wrong. Other people shift to LocalStorage instead. But the actual legislation does not distinguish between cookies and local storage (and similar techniques).

Also, there must be a "reject all" button which should appear visually equivalent to the "accept all" button. Rejecting all has to be as easy as accepting all. Additional clicks are not legal.

Re: Statement on 4 Years of GDPR

#59

This is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate…

Nah, this type of argument is often brought up once someone (with a lobby) actually has to change their ways to comply. Safety features would make cars 3x as expensive, nobody in the world could feasibly implement such radical emissions standards ...

All the time. It's just important to recognize this type of argument as pointless.

Re: Statement on 4 Years of GDPR

#60
There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.
Post reply on HN