Live data from Hacker News

1,741 "informed" consents with one click? GDPR complaint filed

noyb.eu

51–60 of 110 posts

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#51
post #47

Earlier quoted context omitted.

Do you have a better system fix than what EU is trying to do?

There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one accept button for every partner - respect DO NOT TRACK, and force software/hardware providers to enable it by default - making payments for non-tracking illegal - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable…

Respecting Do Not Track is the most important thing here. They absolutely could have forced all browser vendors to implement that feature, and force website owners to honor it. Instead, we got cookie banners.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#53
post #24
post #18

Can someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?

Likely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe". For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might ge…

Oh yeah, that combination of fear and lack of knowledge probably plays a big part. I was once involved with creating a privacy policy for a B2B(!) web application. What a farce. In the end, the process was cut short (counsel too expensive and not nearly familiar enough with tech). The resulting document was at least 50 % stuff the app simply does not do.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#55
post #42

EU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.

The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.

I'm again reminded that a significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic, like yourself, slants towards opposing decent privacy laws.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#56
post #42

Earlier quoted context omitted.

The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.

The whole world would be even happier if websites stoped this nonsense tracking of every single action bloating a single webpage with 20Mb of JS, connecting to 50+ domains, impacting accessibility, data usage & interactivity.

But how will my PM get his fancy overlay of our website with the heatmap of user clicks and dwells to grossly misinterpret?

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#57
post #8

Still wondering how "freely given, informed, specific and unambiguous" is fulfilled by "sure you can opt-out of tracking - by buying a premium subscription. Also, here are our 589 'partners' that all claim legitimate interest" but here we are.

noyb calls these schemes "Pay or Okay"[0] and has filed complaints[1]. However, as far as I can tell no one has been forced by a court to stop.

---

[0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...

[1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#58
post #33
post #7

Earlier quoted context omitted.

The issue is that even if you click "Accept" there is no reasonable way to infer that the user has given informed consent, because becoming informed would likely take days or weeks. As such the conditions for data sharing are not met and it is likely to be illegal.

> becoming informed would likely take days or weeks. Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.

I'm not sure I agree that you couldn't become informed about a single one. I think one is probably reasonable.

Presumably, if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, then such a thing could be done. I imagine a lot of people would click the “I’m not reading all that” button though.

You could even envision a simplified sort of 'tracking declaration' as is done with (for example) insurance products here in Australia, where a sort of statutory precis gives the reader a good, bullet-pointed outline of the policy

I would wager that with a well formatted precis like that, it may even be possible to consent to as many as half a dozen 3rd parties. I doubt many people would though, if it was spelled out that blatantly and clearly what it's all about.

And isn't that the point? Hide what's really happening in so many walls of text nobody could ever conceivably bother with them?

So I think the person filing this suit is correct. The behaviour on show here is an end-run around even the idea of informed consent, and needs to be squashed.

(Edit - instead of all these cold GDPR compliance boxes and walls of text, sites should be honest: letting advertisers track you is how we make money, please click yes and we can get paid for your visit”, but of course it’s much more effective just to confuse people into ignorant acquiescence, or try to get people riled up about “stupid gdpr compliance nonsense”)

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#59

Earlier quoted context omitted.

Europe doesn’t enforce the law. Cookie banners are similarly pointless.

€6.3B cumulative fines says that they’re enforcing the law to at least some extent: https://www.enforcementtracker.com/statistics

Yet the pointless banners and illegal tracking remains. They do, sometimes, but rarely. And having Ireland's utterly toothless DPC handling so many big tech companies makes it even worse.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#60
post #42

EU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.

The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.

You don’t need to put up these banners if you aren’t doing dodgy shit with PII
Post reply on HN