Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

101–110 of 195 posts

Re: Statement on 4 Years of GDPR

#101
post #66

In the context of the GDPR, I just want to remind people of this thread where a HN user invokes their rights in order to make Spotify back down on a change that would have locked user playlists into their service for no good reason - https://news.ycombinator.com/item?id=24764371 (can't be 100% sure this is what made Spotify change direction, but it seems likely)

Yikes, what an enlightening demonstration of how bad GDPR and it's users really are. Instead of taking control of their own music by having it on disk this user decided to rely a third party service and then became so upset when the service changed they threatened legal attacks. Services like this should probably block all nation states that support GDPR.

Spotify is based out of Sweden.

Re: Statement on 4 Years of GDPR

#102

Earlier quoted context omitted.

And if they did that it would also make them GDPR compliant. They chose to put up cookie banners as a way of making to seem like the people making the laws told them to do it. > 99% are just fake. If you reject cookies you keep get them This is silly. The rule is that people are allowed to opt 𝚘̶𝚞̶𝚝̶ in to tracking. Just because some companies use cookies for this doesn't mean that cookies are banned. If you are u…

Opting-in should be a client feature, not a website feature... make browsers block cookies by default, and then add a button next to the title bar to accept cookies for this webpage (for them to remember the login).

Other people tracking you has nothing to do with the browser.

They need explicit permission to track you. The browser doing absolutely nothing is what most people want.

The website can set whatever cookies it wants for the activity of the website itself.

Re: Statement on 4 Years of GDPR

#103

This is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate…

That's a very strange argument by the OP, there are massive arguments about whether/how building codes and zoning laws undermine the ability of developers to build new housing.

Arguments yes, but companies still comply at the end of the day. With GDPR, they simply don't, with no punishment.

Re: Statement on 4 Years of GDPR

#104
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

Wasn’t there recently some ruling against the use of dark patterns in cookie banners?

Re: Statement on 4 Years of GDPR

#105
post #56

This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

> the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Wasn't this called out repeatedly over the years and obvious from the start? That a double forum shopping model will produce paperwork and voluntary compliance, in cases where the offender literally didn't know they were misbehaving, but little real action?

Just want to point out that this not an issue only between European countries but also a problem e.g. inside Germany. [1]: a major information breach at a car rental company went with literary no consequences, while other cases get fined so high that they can easily fight decisions in court. I understand people if they complain about GDPR because it produces paperwork but in the end nobody cares about it. A central European regulation might sound nice at first, but if you even can receive not even a symbolic fine for a clear breach because a DPA has pitty with you something is fishy...

[1] https://www.heise.de/news/Kein-Bussgeld-fuer-die-Datenpanne-...

Re: Statement on 4 Years of GDPR

#106
post #92

Earlier quoted context omitted.

Even YouTube now has a REJECT ALL button. Which is quite nice for folks like me, who always clear browsing data upon exit.

If you always clear browsing data on exit, then what difference does having a reject all button make?

If you have a /etc/hosts file that redirects 10000 tracker domains to 0.0.0.0 then you don’t even need to clear any browsing data. Plus, you don’t see ads anymore without any browser plugins.

Re: Statement on 4 Years of GDPR

#107
post #105

Earlier quoted context omitted.

> the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Wasn't this called out repeatedly over the years and obvious from the start? That a double forum shopping model will produce paperwork and voluntary compliance, in cases where the offender literally didn't know they were misbehaving, but little real action?

Just want to point out that this not an issue only between European countries but also a problem e.g. inside Germany. [1]: a major information breach at a car rental company went with literary no consequences, while other cases get fined so high that they can easily fight decisions in court. I understand people if they complain about GDPR because it produces paperwork but in the end nobody cares about it. A central E…

> also a problem e.g. inside Germany. [1]: a major information breach at a car rental company went with literary no consequences, while other cases get fined so high that they can easily fight decisions in court

This is the problem of German regulators being too cozy with incumbents. (Also see: Wirecard.) It's related, in that if you're one of the incumbents a regulator is cozy with, you're going to fight to switch forum to Germany. But it's a different problem with different solutions.

Re: Statement on 4 Years of GDPR

#108

Earlier quoted context omitted.

> Is there really no way to monetise an audience with ads without collecting their personal info? There sure is: Contextual ads. DuckDuckGo does it, various documentation sites do it ( https://www.ethicalads.io/ ), a dutch broadcaster does it ( https://archive.ph/Zk4Pv ). It's how newspapers used to work and TV channels still do, as well as YouTube sponsorships (and probably many more). It improves the UX over person…

Contextual ads have their own set of problems for advertisers though. Think of a blog post writing about someone's traumatic experiences with pregnancy and miscarriages and the algo decides to put an ad for newborn clothes next to it. Ouch...

That can happen with personalized ads. One point of contextual ads is actually letting you control what is shown besides your content/what context you want your ad to be shown in.

Besides ... most current ads are distasteful regardless of context.

Re: Statement on 4 Years of GDPR

#109
post #92

Earlier quoted context omitted.

If you always clear browsing data on exit, then what difference does having a reject all button make?

If you have a /etc/hosts file that redirects 10000 tracker domains to 0.0.0.0 then you don’t even need to clear any browsing data. Plus, you don’t see ads anymore without any browser plugins.

pi-hole is much better and easier to maintain than a per device hosts file

Re: Statement on 4 Years of GDPR

#110
post #66

In the context of the GDPR, I just want to remind people of this thread where a HN user invokes their rights in order to make Spotify back down on a change that would have locked user playlists into their service for no good reason - https://news.ycombinator.com/item?id=24764371 (can't be 100% sure this is what made Spotify change direction, but it seems likely)

Yikes, what an enlightening demonstration of how bad GDPR and it's users really are. Instead of taking control of their own music by having it on disk this user decided to rely a third party service and then became so upset when the service changed they threatened legal attacks. Services like this should probably block all nation states that support GDPR.

They paid a service and expect that service to follow the law.

That’s not bad at all.

Post reply on HN