Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

91–100 of 195 posts

Re: Statement on 4 Years of GDPR

#91
post #66

In the context of the GDPR, I just want to remind people of this thread where a HN user invokes their rights in order to make Spotify back down on a change that would have locked user playlists into their service for no good reason - https://news.ycombinator.com/item?id=24764371 (can't be 100% sure this is what made Spotify change direction, but it seems likely)

Yikes, what an enlightening demonstration of how bad GDPR and it's users really are. Instead of taking control of their own music by having it on disk this user decided to rely a third party service and then became so upset when the service changed they threatened legal attacks. Services like this should probably block all nation states that support GDPR.

Re: Statement on 4 Years of GDPR

#92
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

Even YouTube now has a REJECT ALL button. Which is quite nice for folks like me, who always clear browsing data upon exit.

If you always clear browsing data on exit, then what difference does having a reject all button make?

Re: Statement on 4 Years of GDPR

#93
post #56

This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

I hear you. These so-called "privacy activists" seem to have no clue how much European corporations are spending on data management, privacy controls, legal due diligence and finally serving the customers' GDPR requests. The last one is the publicly visible part, but it really is just the tip of an iceberg in investment on compliance. This is made even more frustrating by that at least I find GDPR to be not very prec…

If GDPR left you in doubt, that idiocy really showed that these EU bureaucrats are completely out of touch with the reality in the field of technology they want to control.

Honestly, the main thing it revealed is how little value a particular segment of the technology community places on protection of individuals' data. It's actually hard for me to think of any better example of regulation that is designed and written to be in-tune with the technology involved.

Re: Statement on 4 Years of GDPR

#94

This is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate…

That's a very strange argument by the OP, there are massive arguments about whether/how building codes and zoning laws undermine the ability of developers to build new housing.

Re: Statement on 4 Years of GDPR

#95
post #48
post #26

Cookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.

> Does not protect people (99% are just fake. If you reject cookies you keep get them) Fake cookie banners are illegal under the GDPR. Seriously, in what other aspects of life do people respond to terrible enforcement by saying the law is the problem? (Of course there exists a bunch of stupid laws that are also terribly enforced, but here the objective of the GDPR is not stupid – it's merely a matter of terrible enfo…

> in what other aspects of life do people respond to terrible enforcement by saying the law is the problem?

Every other case where the law is widely broken and selectively enforced? From low-level traffic offenses to drug legalization.

Re: Statement on 4 Years of GDPR

#96
post #23

GDPR broke one of my websites that had tens of thousands of happy users. Users loved it and expressed their delight that the website exists on a daily basis. But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody. Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense. So I finally took the plunge a…

With side businesses/projects there's always a matter of balancing the hassle of maintenance with the potential for profit / happy users. GDPR does change this equation somewhat

Re: Statement on 4 Years of GDPR

#97
post #92

Earlier quoted context omitted.

Even YouTube now has a REJECT ALL button. Which is quite nice for folks like me, who always clear browsing data upon exit.

If you always clear browsing data on exit, then what difference does having a reject all button make?

In theory, declining data processing consent means they should not be using other kinds of tracking (that you can’t block/clear client-side) either.

This of course relies on sufficient enforcement of the regulation to act as a deterrent which is currently not the case.

Re: Statement on 4 Years of GDPR

#98

Earlier quoted context omitted.

And if they did that it would also make them GDPR compliant. They chose to put up cookie banners as a way of making to seem like the people making the laws told them to do it. > 99% are just fake. If you reject cookies you keep get them This is silly. The rule is that people are allowed to opt 𝚘̶𝚞̶𝚝̶ in to tracking. Just because some companies use cookies for this doesn't mean that cookies are banned. If you are u…

Opting-in should be a client feature, not a website feature... make browsers block cookies by default, and then add a button next to the title bar to accept cookies for this webpage (for them to remember the login).

GDPR is not just about cookies. In fact cookies are already next-to-useless for tracking because modern browsers have countermeasures against it (which unfortunately does hinder legitimate usage like cross-domain SSO).

The GDPR is about data processing consent as a whole, regardless of how the data was collected. It includes data that you can’t withhold such as your IP address, browser fingerprint, etc.

Re: Statement on 4 Years of GDPR

#99
post #56

This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

I hear you. These so-called "privacy activists" seem to have no clue how much European corporations are spending on data management, privacy controls, legal due diligence and finally serving the customers' GDPR requests. The last one is the publicly visible part, but it really is just the tip of an iceberg in investment on compliance. This is made even more frustrating by that at least I find GDPR to be not very prec…

You're the prime example of what's written in the article: belittling the effort, pretending it's hard to comply with etc. etc.

Re: Statement on 4 Years of GDPR

#100
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

The malicious actors moved everything to "Legitimate Interest", which needs to be toggled off manually for each provider and very well hidden.
Post reply on HN