Live data from Hacker News

1,741 "informed" consents with one click? GDPR complaint filed

noyb.eu

71–80 of 110 posts

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#71
post #17

My Samsung TV which I bought 8 years ago now suddenly asks me if it's okay they share data with their over 200 partners. They have the nerves to headline this with "protect your privacy". Generally not a big fan of EU policing but I wish somebody sued them over this. > Improving Your Experience and Protecting Your Privacy on Samsung TV Plus > Samsung and our 264 partners use information about you and your device in o…

If I got a dollar for every person suckered into buying Samsung products… But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.

Can a screen/monitor/TV send data back over HDMI through a connected computer or is that a 1 way connection?

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#72

Earlier quoted context omitted.

€6.3B cumulative fines says that they’re enforcing the law to at least some extent: https://www.enforcementtracker.com/statistics

Yet the pointless banners and illegal tracking remains. They do, sometimes, but rarely. And having Ireland's utterly toothless DPC handling so many big tech companies makes it even worse.

Yes, letting companies go regulatory agency shopping should not have been allowed. Legal disputes between companies and the customers need to be decided where the customers are.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#73
post #42

Earlier quoted context omitted.

The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.

And we'd all be even happier with no banners and no tracking.

And even happier with no ads.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#74
post #18

Can someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?

I am one of those.

It generally goes like this:

When we launch a site it is seldom more than perhaps Hotjar, Google Analytics, and two-three other services connected.

And then through the years product managers and other stakeholders gets sold on adding LinkedIn, Instagram, Meta, and so on. So we add those.

Next a specific service ”to better track the sales funnel from in-store salespeople to the web” gets added. Then another ”analyse the data quality versus bounce rate” tracker gets added. And so on.

Before long the developers have streamlined the process of adding new scripts/analytics/trackers that editors can add them on their own, and that is when the floodgates open.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#75
post #12

Every law is made under some assumptions about the scale of things. For example, judiciary procedures were designed assuming certain number of active cases. Citizen services and bureaucracy around them is designed assuming some amount of work and staff size. Look at the US immigration / green card processes. The designers of GDPR would have not expected thousands of partners sharing the data collected in a single cli…

You can't number every limit and corner case. You come with precise terms and give a chance for people to defend their case in court.

We'll now see if "thousands of partners" is considered as a good match for "informed consent". Doesn't mean there is a need for review, unless the legislator is not happy with the interpretation that will be provided.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#76
post #47

Earlier quoted context omitted.

Do you have a better system fix than what EU is trying to do?

There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one accept button for every partner - respect DO NOT TRACK, and force software/hardware providers to enable it by default - making payments for non-tracking illegal - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable…

> making payments for non-tracking illegal

This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#77
post #26

Earlier quoted context omitted.

GDPR is a General Data Protection Regulation. It applies to everything . 10 years . It's been in force for 10 years . The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)

There is the ePrivacy directive as well, which mentions cookies (as a representative example), and I think it requires user consent in cases where GDPR doesn't.

ePrivacy is now mostly about the requirement to notify the user that cookies are set, and what they are used for. But you are correct: https://gdpr.eu/cookies/

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#78
post #47

Earlier quoted context omitted.

There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one accept button for every partner - respect DO NOT TRACK, and force software/hardware providers to enable it by default - making payments for non-tracking illegal - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable…

> making payments for non-tracking illegal This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?

I would have them make money by selling me products, rather than selling me as a product.

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#79
post #47

Earlier quoted context omitted.

Do you have a better system fix than what EU is trying to do?

There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one accept button for every partner - respect DO NOT TRACK, and force software/hardware providers to enable it by default - making payments for non-tracking illegal - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable…

> deny is the default

Article 6 and 7 of the GDPR

> respect DO NOT TRACK, and force software/hardware providers to enable it by default

There is other software and other areas of human activity than just cookies and browsers.

Also, with "deny is default" you shouldn't really nead the DNT. But tell that to the ad/tracking industry

> making payments for non-tracking illegal

Generally derived from GDPR. See e.g. recital 43 https://gdpr-info.eu/recitals/no-43/

> remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything

It's there because actual legitimate activities like security audits or fraud detection would not be possible.

EU expects companies to act as adults, but here we are.

> prohibit any other dark pattern, or at least make it extremely hard to implement

This cannot be properly specified. And existing laws and regulations already cover that.

See the article we're commenting under. And noyb's previous cases: https://noyb.eu/en/where-did-all-reject-buttons-come

Re: 1,741 "informed" consents with one click? GDPR complaint filed

#80
post #47

Earlier quoted context omitted.

There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one accept button for every partner - respect DO NOT TRACK, and force software/hardware providers to enable it by default - making payments for non-tracking illegal - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable…

> making payments for non-tracking illegal This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?

> I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise

Advertising does not require invasive and pervasive tracking. There's no world in which a b2c company needs my precise geo location for 12 years: https://x.com/dmitriid/status/1817122117093056541

Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.

Post reply on HN