Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

101–110 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#101
post #42
post #11

Quite apropos that this article was cookie-walled with a "We value your privacy. Customize/Agree" modal screen

Which is not compliant with GDPR if those were the only two prominent options. Disagree must be as prominent as Agree.

Wait, are you implying that regulations are hard to comply with, poorly documented, and enforcement is extremely selective to the point where they no longer achieve their intended function?

Big news if true. They should do something about that.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#102
post #29

I think the title is clickbait'y. The EU proposes to simplify the law rather than abolish it, which makes sense to me.

politico is known for its clickbait titles.

They are owned by Axel Springer, whose CEO and part-owner is extreme neo-capitalist Mathias Döpfner, and their news follows his philosophy (or similar ones) as if they are fact, at least at times. The headline depicting privacy regulation as a 'bonfire' is not surprising; I think they were different before the recent corruption of professional journalism by similar people (there is some good journalism remaining!).

Regarding Döpfner, he tried to fire an editor at Business Insider (another Axel Springer publication) because Wall St power player Bill Ackman didn't like their coverage of Ackman's wife. [0] He's taken positions such as, "I am all for climate change"; and ""Free west, fuck the intolerant Muslims and all the other riff-raff." [1]

Politico has published articles saying, "Time to Admit It: Trump Is a Great President. He's Still Trying To Be a Good One.", claiming "The most consequential presidents divided the nation - before “reuniting it on a new level of understanding." (by founding editor and global editor-in-chief John Harris). [2] And another that claimed, as news and not opinion, that disinformation concerns were a "panic" and now outmoded. [3] At least some of their coverage of American politics assumes - again as news fact, not opinion - that anything the left does is ridiculous.

I actually want to know the reality of things, as much as possible, so I will hardly read them anymore.

[0] https://www.semafor.com/article/04/21/2024/axel-springers-tr...

[1] https://www.theguardian.com/world/2023/apr/13/axel-springer-...

[2] https://www.politico.com/news/magazine/2025/01/21/harris-col...

[3] https://www.politico.eu/article/nobody-tricked-vote-donald-t...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#103
post #87
post #67

Earlier quoted context omitted.

Again, the cookie banners have nothing to do with GDPR, where are people getting this misinformation from?! Was there a popular article saying we have those cookie banners because of GDPR, or what? The banners are the result of much earlier directives that predate GDPR by a lot...

It's not misinformation. Yes ePrivacy predates GDPR but it had no teeth. The reason your replies are full of people saying, "Our lawyers told us to implement it for GDPR" is because it was a minimal thing you could do to meet GDPRs emphasis of receiving consent from users for data stored in cookies. Basically the fear of fines from not being GDPR compliant forced companies add them. I agree with you these cookie bann…

Further down on the page they rightly notice that strictly necessary cookies don't require consent. This mirrors the opinion of European Union's Article 29 Working Party back then: https://ec.europa.eu/justice/article-29/documentation/opinio...

gdpr.eu is by the way not an official resource of the European Union but by the Swiss Proton AG. They note down the page that gdpr.eu doesn’t constitute legal advice. Although they are correct in this case and your misunderstanding was in reading for future internet discussions I'd recommend not using private sources.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#104

I think simplifying the law for companies smaller than the 500 person cutt-off makes sense. The Brussels effect is strong. I was just in a company of approximately ~150 people in America and a significant portion of our time went to GDPR/California law takedown requests. User data was everywhere, it was a nightmare. No one thinks of this stuff when everyone is still in sink or swim mode. We got it done though. Maybe…

I spent four years working at a European fintech that serviced millions of end-users, and we had a self-service GDPR portal for users to export or request deletion of the data we had on them. (In some cases we were required to hold onto certain data due to other laws). Any feature that stored new user data had to get integrated into the tool, and then signed off from legal and the team that maintained the tool.

It got very little usage - maybe a few hundred to a thousand requests per year IIRC. I shudder to think what you could have been doing that would attract that volume of requests. Was it Clearview AI?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#105
post #57
post #35

Earlier quoted context omitted.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

The cookie banners don't make companies less "careless" They just introduce a needless bit of friction in the UX. If the EU wanted to prevent digital identity triangulation or cross-domain advertising data gathering, it should have banned it outright. Rather than getting all users to click a stupid banner every time they visit a website.

The EU didn't mandate that annoying UI. That's malicious compliance from businesses who are trying to undermine the law.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#106
post #19

Earlier quoted context omitted.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

auto-accepts? We just go back to square 1 in 2011 in that case.

That's the idea. We didn't have banners all over the place in 2011.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#107
post #28

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. It doesn't help the situation that a…

>Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent.

So if I use telemetry to catch some dirty frontend blob throwing a hissy fit of an exception and that telemetry is tracking sessions rather than individual events (hello ms app insights) -- is that functional or, statistics or etc?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#108
post #32
post #19

Earlier quoted context omitted.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

Can it auto-reject them?

actually, you don't need to actively reject, it's the operator which has to obtain active informed consent, so default option is "no consent given"

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#109
post #18

Cookie consent banners might be one of the most frustrating aspects of modern web browsing. A better solution could have been a thoughtful extension or fork of HTTP, specifically for EU implementations, something that handles consent through HTTP headers instead. That would allow users to easily opt in or out, either globally or per tab, without the clutter. Ideally, technical regulations like these should be designe…

It would have been easy to write in generic wording that the "do not track" header must be respected by websites. I'be been wondering for ages why this wasn't implemented.

From the implementation and enforcement, it seems like GDPR was an attempt to make tracking visitors so expensive and difficult that it would eliminate targeted marketing, without negatively impacting consumer choices. The 'do not track' header would not achieve this goal.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#110
post #42

Earlier quoted context omitted.

Which is not compliant with GDPR if those were the only two prominent options. Disagree must be as prominent as Agree.

Wait, are you implying that regulations are hard to comply with, poorly documented, and enforcement is extremely selective to the point where they no longer achieve their intended function? Big news if true. They should do something about that.

it's not that it's hard to comply, it's fighting malicious compliance which is hard. nevertheless, it's a good damn question why every single operator that has "accept all" and doesn't have "reject all" right there on the consent banner isn't fined on the spot.

I think the commission noted this behavior and malicious compliance is already factored into the DMA act. The "deregulation" of GDPR could as well be retrofitting all the lessons learned into the GPDR v2.

Post reply on HN