Live data from Hacker News

You Know GDPR Is Good Based on Who Hates It

matduggan.com

11–20 of 179 posts

Re: You Know GDPR Is Good Based on Who Hates It

#11
GDPR itself is quite a good law. It's implementation and enforcement are not.

E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.

EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.

Re: You Know GDPR Is Good Based on Who Hates It

#12
As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.

Was it a PITA? Sometimes, yes.

Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.

But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.

Re: You Know GDPR Is Good Based on Who Hates It

#13

I hate the banners, and I am a major privacy advocate. The web has gotten so much uglier as a result of GDPR.

The cookie banner isn't actually specified in gdpr, it was just how everyone else tried to build the solution to the problem at the last minute. I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something" Nope

Browsers already had a way to consent to cookies, since the invention of cookies themselves. But the EU didn't consider that _real_ consent.

Re: You Know GDPR Is Good Based on Who Hates It

#14

US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit! Try to do marketing ad campaign as small eshop owner in EU!

>US companies like Meta or Google __LOVE__ GDPR

If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.

This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.

Re: You Know GDPR Is Good Based on Who Hates It

#15
post #6

Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.

The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

They do come from the ePrivacy directive but;

> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.

Re: You Know GDPR Is Good Based on Who Hates It

#16
post #6

Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.

The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

It was always possible to ask the user for permission when you actually want to store something on their device, ie. go for an opt-in model.

Re: You Know GDPR Is Good Based on Who Hates It

#17
post #6

Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.

The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal.

Because if it is, I also want to do it that way.

Re: You Know GDPR Is Good Based on Who Hates It

#18
post #6

Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.

The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

No you don’t need a cookie banner or consent to store normal data in the user browser.

You do if you want to track your users. Very different thing.

Re: You Know GDPR Is Good Based on Who Hates It

#19

I hate the banners, and I am a major privacy advocate. The web has gotten so much uglier as a result of GDPR.

Shaka, when the walls fell.

I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.

GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.

Re: You Know GDPR Is Good Based on Who Hates It

#20

US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit! Try to do marketing ad campaign as small eshop owner in EU!

As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
Post reply on HN