What if I use a cdn that has points of presence in Italy and still pings my server with a head request and the end user ip?
Am I also now breaking Italian law by using google analytics?
71–80 of 614 posts
What if I use a cdn that has points of presence in Italy and still pings my server with a head request and the end user ip?
Am I also now breaking Italian law by using google analytics?
Earlier quoted context omitted.
Congrats. We also chose to do the analytics ourselves. No tracking, no cookie banners, and probably better stats as well. One thing that Google did very cleverly was to only give GA users the search terms that visitors used to end up on their site.
Isn't the search term in the Referer header?
The last time I checked, the Google Analytics' Terms of Service explicitly prohibited its use on web sites involving healthcare companies. That gives you an indication of how invasive it is — that even Google doesn't want to handle the personal information, because it can't be made HIPAA-safe. Naturally, the majority of healthcare web sites use Google Analytics, because nobody ever reads the Terms of Service.
You're missing a key part of the sentence you're remembering:
> If you are (or become) a Covered Entity or Business Associate under HIPAA, you may not use Google Analytics for any purpose or in any manner involving Protected Health Information unless you have received prior written consent to such use from Google.
Healthcare companies can absolutely use GA on their websites as long as the website isn't involving PHI or ePHI.
Good. US citizens should be, at least, disappointed that their government is so bad at protecting their privacy, that US law is so far behind the times. To those companies and people who find these EU decisions baffling or inconvenient: tough. If you had had respect for your users this would not be an issue. You would already not be spying on them. To website visitors: if you see a cookie banner, the site is asking p…
America is the LTS branch of Democracy.
Earlier quoted context omitted.
If you can't beat the free offering, then go home. In the real world of physical goods, there are laws against this. But Google's a tech company, so anything goes.
It's not illegal to give things away for free unless it's dumping.
Which is exactly my point.
"[Dumping] occurs when manufacturers export a product... at a price below the normal price with an injuring effect. The objective of dumping is to increase market share in... by driving out competition and thereby create a monopoly situation"
https://en.wikipedia.org/wiki/Dumping_(pricing_policy)
That's exactly what's happening here.
Google prices Analytics at $0 to prevent any competition from starting up.
While an argument can be made that Google doesn't need to charge money for the product because that cost is made up in other areas, there is no way of knowing that, because those costs are not public. We don't know if it's fully made up by other means, or partially made up by other means, or not at all.
Like you, IANAL, but it's my understanding that legally, it's not about the price, it's about the intent.
Earlier quoted context omitted.
Bizarre idea. Should websites be allowed to opt out of anti-fraud legislation? Anti-money laundering? Human rights protections?
No, just GDPR? I don't see any valid reason a user might want to "opt out" of anti-fraud legislation but I do see a reason why a user might want to access the non-GDPR web.
You can't make exceptions based on what's convenient for some business.
Why should GDPR be opt-in but not the consumer minimum 2-year guarantee against faulty products?
> ? I don't see any valid reason a user might want to "opt out" of anti-fraud legislation
To commit frauds, for example?
Earlier quoted context omitted.
> meaning that Google itself does not violate GDPR, but only the websites that use it. This is so baffling to me. Google has subsidiaries in the EU. The fact that it's ok to give a product to a EU client which can't be used in accordance with the law, and the client is responsible, is just idiotic.
To be compliant, Google can just set up data centers specific to GA in one of those EU subsidiaries, so GA admins can choose to have their visitors' data stored only in an EU data center (and promise to not transfer that data to the US). This wouldn't be that hard to do.
Earlier quoted context omitted.
I don’t find it idiotic. It was the client’s decision to spy on its users. I have no sympathy for companies who make that decision.
> It was the client’s decision to spy on its users. Calling it spying is a little far-fetched I think, when the problem was the transfer ip addresses to US servers, not Analytics itself.
I wish GDPR compliance would have been opt-in. For example, a GDPR compliant website could have sent a custom header indicating compliance, which the browser could have displayed in the address bar (a bit like HTTPS). Consumers would then have been free make the decision to not use websites which aren't GDPR compliant. Consumers who are more concerned about privacy could have set their browser to automatically block…
Bizarre idea. Should websites be allowed to opt out of anti-fraud legislation? Anti-money laundering? Human rights protections?
A parallel anonymous-and-free-for-all-but-with-payments-included, smth. like Tor-but-powered-by-IPFSv9-and-Etherv7, will probably emerge in a couple decades done right after a couple failed iterations. Some techs need hardware to catch up to be cheap enough, and only after a few failed attempts they manage to grow a trend... and it will probably will last until it's used to finance a proper starting of WW3 and by then banning it will be too late.
Anyway, we'll enjoy the hell out of ourselves on the new patreons-but-for-snuff-p03n, so it will all have been worth it :)
Good. US citizens should be, at least, disappointed that their government is so bad at protecting their privacy, that US law is so far behind the times. To those companies and people who find these EU decisions baffling or inconvenient: tough. If you had had respect for your users this would not be an issue. You would already not be spying on them. To website visitors: if you see a cookie banner, the site is asking p…
America is the LTS branch of Democracy.