Earlier quoted context omitted.
The EU hasn’t shaken off their roots in monarchy. Using the power of the state to go after a single private entity since they have a blood feud with said entity and are now finding all sorts of excuses to hit them economically. I’ve been following the cases with regard to privacy in the EU and it’s a complete joke. You have all these onerous rules against any web technology making it near impossible for startups to f…
> The EU hasn’t shaken off their roots in monarchy. I know, right. I mean obviously the world's most famous royal family (our British one) isn't really a monarchy so that doesn't count. And they certainly don't get previews and vetos on our laws, or given hundreds of millions from the licence fees for offshore wind farms, or own a notable percentage of the land. As for GDPR, compliance is pretty straightforward provi…
Italian watchdog bans use of Google Analytics
561–570 of 614 posts
Re: Italian watchdog bans use of Google Analytics
#562Re: Italian watchdog bans use of Google Analytics
#563Earlier quoted context omitted.
In fact it's not at all onerous, unless you are determined to violate it's provisions. If your business doesn't depend on privacy violations, then the "bureaucracy" that GDPR calls for is trivially easy to implement. There are no licences, and no registration requirements. Provided you aren't playing fast and loose with the personal data of Europeans, you're fine. There's no "personal vendettas" going on; can you sub…
"iTs nOt aT aLl oNeRoUs" said the DPO. lol, what a clown. So all these companies scrambling to hire lawyers to document every single aspect of the "legal basis" or whatever nonsense is in the language are just crazy in your books? And that's just ONE sub clause of a hundred or so. The overhead is both in the arbitrary nature of the requirements (Good Laws are objective, not subjective) and the sheer lack of consisten…
There's a difference between the way French and Germans write laws and the way we write them in the UK; I prefer the UK style, which leaves less room for interpretation.
> basically every small business in the EU is in violation right now
Only if they're handling personal data. Most small businesses don't.
Sure, if your business is collecting personal data, then GDPR is a problem for you; in the same way as the Road Traffic Act is a problem if you're determined to drive uninsured. If you want to sail close to the wind, then it's probably wise to lawyer-up.
And, of course, you don't have to use AWS.
> And it's bureaucratic assholery that keeps this deliberately inconsistent
That's not how I read it. The way I read it, GDPR is astonishingly lenient. Before they prosecute, they'll warn you; provide advice on how to come into compliance; and give you time to do it.
> choosing arbitrary standards
If GA involves depositing personal data in US jurisdiction, then you can't use GA in a GDPR jurisdiction. That's not vague or arbitrary. It may be - um - bold; But this law was flagged up years before it came into force. It's not as if the law came out of nowhere, and suddenly everyone's in violation.
> Its ridiculous and bad for their own economies.
Others have argued that GDPR is an attempt by the EU to steal Silicon Valley's breakfast, implying that it's good for European economies.
Re: Italian watchdog bans use of Google Analytics
#564Earlier quoted context omitted.
> Also if it’s multi-lingual, how are you storing the language prefs? Cookies you require for functionality (ie. login cookies, language settings) require no consent, but do require to be laid out in a cookie policy.
Persistent preferences require consent and is considered tracking. Only auth doesn’t. Go visit any government site and they have cookie banners for their preferences cookies.
Re: Italian watchdog bans use of Google Analytics
#565Earlier quoted context omitted.
> If it’s bad law, it’s bad law. Presumably it's your opinion that it's a bad law. The majority of Europeans think it's a good law - possibly the best regulation the EU has ever promulgated.
Bad law for the reasons above. Ie, onerous toward regular businesses Ie, used to greatly expand bureaucracy and overhead Ie, used by unelected bureaucrats to wage battles of personal vendetta against specific companies instead of doing what laws do, which is set unambiguous standards for all
> unelected bureaucrats
Does the American elect the IRS or the FTC bureaucrat?
Re: Italian watchdog bans use of Google Analytics
#566Earlier quoted context omitted.
Cookies needed to properly provide user authentication, i.e. user session identification, are counted as "technical necessary" cookies and do not need a cookie banner. You only need to ask for cookie consent, if you track visitors with third-party services. And, to counter your unique visitors claim: you don't need cookies, or any third party service, for that. Everything can be done locally without disrespecting use…
> and, to counter your unique visitors claim: you don't need cookies, or any third party service, for that. Everything can be done locally without disrespecting user privacy. how do track unique visitors without cookies, and how is that way less "disrespecting" of user privacy than a cookie?
I wrote "disrespecting" because using GA is exactly this for me. Website owners give a f** about your user privacy just to save them some work, without caring about any of your users' data.
[1]: https://goaccess.io
Re: Italian watchdog bans use of Google Analytics
#567Earlier quoted context omitted.
IIRC, it basically only applies if you're actively doing business in the EU, or courting future business. So, if you have a personal blog that grabs IPs? Not illegal. If you start a merch shop for your blog (or put in ads/sponsored content, etc.), then the whole site needs to be GDPR compliant.
> If you start a merch shop for your blog (or put in ads/sponsored content, etc.), then the whole site needs to be GDPR compliant. And you do business in the EU. If you have a merch shop, but don't serve EU users (no EU shipping, not accepting EUR as a currency, no EU specific languages (German, French...), ...) there is no problem.
If I run an export business from my own country, the only law I need to comply with are the export laws of my own country. It's the duty of whoever is buying it on the other end to make sure they are allowed to import and possess the goods.
The EU does not own the right to use languages. I can use German if I choose without ceeding an inch of soverignty to the EU.
The EU does not control what data I collect when running my website. I might be required by my home jurisdiction to collect details on controlled export goods, and I might be required not to tell the user.
The EU controls the Euro currency, but they cannot make it illegal to me to use it, or attach special conditions to its use. They could convince my own government to sanction me, or aid them in sanctioning me, but that would be my own government affecting me, not the EU.
Your countries laws stop at its borders. Stop trying to control other people who have no say or vote in the laws. It's anti-democratic.
Re: Italian watchdog bans use of Google Analytics
#568Earlier quoted context omitted.
Isn't it already against Google Analytics' policy to put PII in the platform to begin with? https://support.google.com/analytics/answer/6366371?hl=en#zi...
Gdpr uses a more expansive definition of personal data, and it includes the IP address and geolocation data, for example.
Re: Italian watchdog bans use of Google Analytics
#569Earlier quoted context omitted.
"iTs nOt aT aLl oNeRoUs" said the DPO. lol, what a clown. So all these companies scrambling to hire lawyers to document every single aspect of the "legal basis" or whatever nonsense is in the language are just crazy in your books? And that's just ONE sub clause of a hundred or so. The overhead is both in the arbitrary nature of the requirements (Good Laws are objective, not subjective) and the sheer lack of consisten…
> Good Laws are objective, not subjective There's a difference between the way French and Germans write laws and the way we write them in the UK; I prefer the UK style, which leaves less room for interpretation. > basically every small business in the EU is in violation right now Only if they're handling personal data. Most small businesses don't. Sure, if your business is collecting personal data, then GDPR is a pro…
Interesting way of saying they are bad laws. If you cannot, as a business have certainty in your prediction of the regulatory environment, you're pretty fucked. I wouldn't expect a piece of the bureaucratic establishment such as yourself to understand the struggles of setting up and running a business. What was your role as DPO again? An ornamental peace offering to the burdens imposed by regulation? Not all businesses have the luxury of throwing money at legal resources.
> Only if they're handling personal data. Most small businesses don't.Sure, if your business is collecting personal data, then GDPR is a problem for you; in the same way as the Road Traffic Act is a problem if you're determined to drive uninsured. If you want to sail close to the wind, then it's probably wise to lawyer-up.
It must take a special kind of asshole to say this. In just another one of your recent comments here you mention that even the mere presence of an IP address that ISNT EVEN STORED would put a business in violation and liable to large fines. So you pretty much agree that all small businesses are in violation if they use AWS in any reasonable way to run their business but you don't want to say it explicitly here since it makes you look bad. Gotcha.
> And, of course, you don't have to use AWS.
And of course, the European people elected you their lord and savior to tell businesses which tech stacks they pick and choose because of your interpretation of arbitrary laws. See the problem here yet?
> That's not how I read it. The way I read it, GDPR is astonishingly lenient.
Is it? So why did other member states of the EU take offense at the decision of the Irish DPA ? The one stop provision clearly stipulates that the onus of enforcement falls to the one stop shop and instead, the arbitrary nature of the law as it stands, other member states and bureaucrats in Brussels seem to deem it necessary to impose their will and personal vendettas against the perceived soft touch approach of an entity fully within their rights to do so.
> If GA involves depositing personal data in US jurisdiction, then you can't use GA in a GDPR jurisdiction
Has there been any warnings against AliCloud for instance? Or all the analytics bundles shipped in Huawei phones?
I can't seem to recall any press release or webpage dedicated to a single company like the CNIL and now Italian authorities have adopted towards Google Analytics?
Is there any oversight to these agencies allowed where these decisions are up to public scrutiny such as the FOIA act in the US to assure the public that these highly paid public officials are not wasting all their time and money chasing personal vendettas as seems to be the case here? Of course fucking not.
Is Google Analytics perfect? Maybe not. But this is the crucial point . . THE LEGISLATURE CANNOT DISCRIMINATE AGAINST A SINGLE ENTITY THIS WAY. While turning a blind eye to practices by Huawei and other companies, it is simply against the rule of law.
> Others have argued that GDPR is an attempt by the EU to steal Silicon Valley's breakfast, implying that it's good for European economies.
A weasel through and through. What else did i expect from someone in your position?
So, illegal abuse of power by Government to target a company is fine by you, Mr. DPO ?
Re: Italian watchdog bans use of Google Analytics
#570Earlier quoted context omitted.
Frankly, as a EU company (based in Germany no less) I'm steering clear of any US SaaS whenever possible. Even if they operate in the EU they're usually a legal headache because privacy compliance is added as an afterthought and they'll often carelessly transfer data to US servers based on assumptions that should have been abandoned when Privacy Shield was torn down in the courts. Out of the big cloud providers only A…
Wait, why would Microsoft have a better reputation ? Because (NSA aside), they have been caught less often transferring private information and "stolen" company secrets to third parties ?