Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

111–120 of 195 posts

Re: Statement on 4 Years of GDPR

#111
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

"Better" would mean not seeing cookie dialogs at all.

Re: Statement on 4 Years of GDPR

#112
post #56

This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

I hear you. These so-called "privacy activists" seem to have no clue how much European corporations are spending on data management, privacy controls, legal due diligence and finally serving the customers' GDPR requests. The last one is the publicly visible part, but it really is just the tip of an iceberg in investment on compliance. This is made even more frustrating by that at least I find GDPR to be not very prec…

I think the GDPR is pretty clear: it is illegal to process personal data if you cannot apply an exception listed in the regulation. Also all data that might be deanonymized by some means is personal data. The message is clear: if you put others at risk, you are at risk to get fined.

Yes, this makes many, sometimes ideotic things, illegal. But not I also cross a red light on foot from time to time and I do not think it should be made legal. Regulations that leave a freedom what to prosecute are not bad by design.

Re: Statement on 4 Years of GDPR

#113
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

This seems to be a very common misconception, but the cookie consent dialogues are not part of GDPR.

Re: Statement on 4 Years of GDPR

#114
post #66

In the context of the GDPR, I just want to remind people of this thread where a HN user invokes their rights in order to make Spotify back down on a change that would have locked user playlists into their service for no good reason - https://news.ycombinator.com/item?id=24764371 (can't be 100% sure this is what made Spotify change direction, but it seems likely)

Yikes, what an enlightening demonstration of how bad GDPR and it's users really are. Instead of taking control of their own music by having it on disk this user decided to rely a third party service and then became so upset when the service changed they threatened legal attacks. Services like this should probably block all nation states that support GDPR.

Gatekeeping music availability is weird. In most places, the idea of having all this music locally on a disk is impossible. How can someone in mongolia get a lossless, flac based discography of their favorite band from the 80s?

The music industry purposelessly makes it harder and harder to get lossless file based music for the first world, save for indie bands on bandcamp and the occasional release by a triple A band/label.And again, this is next to impossible in developing nations.

I don't have hundreds of hours and thousands of dollars to dedicate t getting every song I want to listen to on a whim in the above mentioned format, and I have much less time and money to manage those across my devices in a format that is anything short of maddening.

Re: Statement on 4 Years of GDPR

#115
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

Wasn’t there recently some ruling against the use of dark patterns in cookie banners?

The big players can afford to pay the fine, and the small ones probably won't be taken to court, so it might not have enough impact.

Re: Statement on 4 Years of GDPR

#116
post #40

Earlier quoted context omitted.

Yeah, there's also a reason our polluted rivers used to catch fire and children worked in mines, both those things were cheaper/more profitable to the decision maker too. But have we forced every non abusive advertising platform out of business as a result of tolerating this abuse for so long?

A non abusive advertising platform wouldn't be subjected to GDPR problems, this should make it easier for them to compete and thrive not harder. When it was legal to just collect all data about users from everywhere and sell it etc then it was impossible for good actors to compete. What we see today is that all those bad actors who profited from all those bad actions are complaining and having problems, that is a goo…

[deleted]

Re: Statement on 4 Years of GDPR

#117
post #58
post #26

Cookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.

> 99% are just fake. If you reject cookies you keep get them Note that cookies that are technically required to serve the site don't need a cookie banner. This is something many people get wrong. Other people shift to LocalStorage instead. But the actual legislation does not distinguish between cookies and local storage (and similar techniques). Also, there must be a "reject all" button which should appear visually e…

Another thing that is often ignored is that you have to wait for someone to consent before you give them cookies. Many sites just create the cookies when you open the page, then throw the banner, then whether you accept or reject, it makes no difference. Talk about compliance theater.

Re: Statement on 4 Years of GDPR

#118
post #24

Earlier quoted context omitted.

> The legislation itself is sane On paper yes, great intentions[1], in practice no. E.g. Right to be forgotten. Implement RTBF in context of IPFS. [1] Second order effects like prevent rats/snakes by awarding award for rat/snake heads, lead to rat/snake farms. > if privacy-violating monopolies retract from the market You get Splinternet. Several independent Internets, walled from each other.

I find the right to be forgotten very valuable in a world where everything is permanent, searchable and every little mistake will be used against you in the future. > Implement RTBF in context of IPFS. How does IPFS deal with CSAM being published on it? Not saying it should detect CSAM, but once it is found, how does one go about having it removed? You use the same system to handle RTBF, and if you can't, then maybe…

> You use the same system to handle RTBF, and if you can't, then maybe a platform where it's literally impossible to delete something isn't a good idea (partly because undesirable content will ultimately outnumber legitimate content)?

The impossibility of the assured annihilation of data is true of all protocols for data retrieval so long as client nodes are free and able to copy the data retrieved.

It's why removal of illegal content from the internet has been an abysmal failure.

Re: Statement on 4 Years of GDPR

#119
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

The malicious actors moved everything to "Legitimate Interest", which needs to be toggled off manually for each provider and very well hidden.

That's still not compliant so this problem should be resolved eventually.

Re: Statement on 4 Years of GDPR

#120
post #115

Earlier quoted context omitted.

Wasn’t there recently some ruling against the use of dark patterns in cookie banners?

The big players can afford to pay the fine, and the small ones probably won't be taken to court, so it might not have enough impact.

When a fine is issued they will also need to become compliant so it's not just a matter of paying the fine and then carrying on as usual.

However enforcement is indeed severely lacking as this article describes.

Post reply on HN