Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

121–130 of 195 posts

Re: Statement on 4 Years of GDPR

#121
post #92

Earlier quoted context omitted.

If you always clear browsing data on exit, then what difference does having a reject all button make?

If you have a /etc/hosts file that redirects 10000 tracker domains to 0.0.0.0 then you don’t even need to clear any browsing data. Plus, you don’t see ads anymore without any browser plugins.

Until the service sends your data to the trackers server-side which is very common nowadays (in fact there are even legitimate reasons for doing it).

Re: Statement on 4 Years of GDPR

#122
post #56

This article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.

I hear you. These so-called "privacy activists" seem to have no clue how much European corporations are spending on data management, privacy controls, legal due diligence and finally serving the customers' GDPR requests. The last one is the publicly visible part, but it really is just the tip of an iceberg in investment on compliance. This is made even more frustrating by that at least I find GDPR to be not very prec…

One option would be to collect less data on users, which should make it easier to manage.

Re: Statement on 4 Years of GDPR

#123
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

This seems to be a very common misconception, but the cookie consent dialogues are not part of GDPR.

https://gdpr.eu/cookies/

Cookie compliance

To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:

Receive users’ consent before you use any cookies except strictly necessary cookies.

Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.

Document and store consent received from users.

Allow users to access your service even if they refuse to allow the use of certain cookies

Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.

Re: Statement on 4 Years of GDPR

#124
I completely reject the premise of this, that one is somehow EU citizens are not personally responsible for the information they themselves put online.

The most hilarious thing is cookies!

For example, cookies exist, and they work a certain way... and despite not liking how they work.. they are here, and not going away, and imposing some kind of contract-law of cookies being accepted or rejected totally ignores that the user has, and always had, the ability to reject cookies at the browser level, unilaterally or with policies, without any contract laws.

Re: Statement on 4 Years of GDPR

#125
post #105

Earlier quoted context omitted.

Just want to point out that this not an issue only between European countries but also a problem e.g. inside Germany. [1]: a major information breach at a car rental company went with literary no consequences, while other cases get fined so high that they can easily fight decisions in court. I understand people if they complain about GDPR because it produces paperwork but in the end nobody cares about it. A central E…

> also a problem e.g. inside Germany. [1]: a major information breach at a car rental company went with literary no consequences, while other cases get fined so high that they can easily fight decisions in court This is the problem of German regulators being too cozy with incumbents. (Also see: Wirecard.) It's related, in that if you're one of the incumbents a regulator is cozy with, you're going to fight to switch f…

Indeed. NOYB's fight with the Irish Data Protection Commission is already legendary:

https://techcrunch.com/2021/12/20/facebook-transfers-impact-...

https://noyb.eu/en/irish-dpc-burns-taxpayer-money-over-delay...

(DPC = the official Irish body who should be responsible for enforcing GDPR… in bed with Facebook instead. Somewhere between shameful and criminal.)

Re: Statement on 4 Years of GDPR

#126
As someone working in ad tech but not rooting for it to win at all costs: the biggest positive I see from GDPR is the fact that many ad tech data vendors have left Europe. I'm talking about vendors that aggregate personal data, track your location and the places you visit, the web sites you visit across multiple devices, etc.

i.e.

https://www.adexchanger.com/data-exchanges/tapad-is-shutting...

Re: Statement on 4 Years of GDPR

#127

Earlier quoted context omitted.

The purpose of GDPR is to help abusers legitimise the data they collect. Before GDPR it was a grey area, because users didn't explicitly consent to anything - GDPR fixes that. Ubiquitous pop ups where you agree for your data to be collected and processed, trained users to consent to anything that comes their way and corporations now have legal basis to use, process and sell that data. It was quite clever - make peopl…

The GDPR has strict regulations on what counts as valid data processing consent. 90% of the consent popups you see out there do not fit that criteria and any "consent" obtained via them doesn't count.

[deleted]

Re: Statement on 4 Years of GDPR

#128
I don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR.

I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests.

They can't fine me, I don't have a physical or business presence in Europe, though I do have European customers.

The only reason I handle requests is to protect my customers, not myself.

Re: Statement on 4 Years of GDPR

#129
post #29
post #23

GDPR broke one of my websites that had tens of thousands of happy users. Users loved it and expressed their delight that the website exists on a daily basis. But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody. Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense. So I finally took the plunge a…

GDPR aside, I had similar shock after getting a few million users for a viral language game, but finding that basically nobody was willing to sponsor it on Patreon, even to a level to cover the basic hosting costs. It was a little hard to process at the time.

Casual games are a tough market, because there's a shitload of competition and a lot of it's free.

I play Wordle most days. I do enjoy it. The amount I'd pay for it is $0, because there are a thousand other free options that would entertain me just as much. Maybe not even word games. Maybe just Microsoft Solitaire. Apple's Texas Hold 'Em. Minesweeper. Nokia Snake Game. Whatever. Despite playing Wordle so much, if you told me I had to pay $1/month for it or else it'd disappear completely, I wouldn't do it. Its competition includes free stuff like watching the clouds go by, or flicking little paper wads at the trash can.

Re: Statement on 4 Years of GDPR

#130
post #26

Cookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.

> Cost money to company (so cost to customers)

You can't necessarily raise prices just because your costs go up.

Post reply on HN