Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

1–10 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#2
Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#3
This is amazing news.

I implemented GDPR consent management for some US publishers with EU exposure. As part of this I evaluated vendors and various systems like the IAB framework.

IMHO it was clear it was not compliant. It could never know the potential adtech it was going to load in advance (and therefore could not ask someone to consent), and it still allowed ads/adtech/trackers to load in page before asking for consent.

They ignored anyone who pointed this out.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#4
It was obvious to anyone technical they didn't work as they presented themselves to work, but it takes time for the courts to deal with such things.

They are also totally annoying and I suspect there primary purpose was to annoy users and not actually comply with the GDPR. It was a way for these companies to fight the GDPR with a war of attrition. I'm glad you see with this round hasn't worked... Yet.

I suspect that based on this ruling, things will not get better, as in providing a less annoying user experience and more compliance with the GDPR. Instead I predict another round of pseudo compliance and a more annoying user experience. Eventually they'll start a policy campaign in earnest stating that the GDPR is unworkable.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#5
Finally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok.

I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#6
My favorite part is:

> All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses.

It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them pulling the same shit again.

Edit: loose -> lose

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#8
post #3

This is amazing news. I implemented GDPR consent management for some US publishers with EU exposure. As part of this I evaluated vendors and various systems like the IAB framework. IMHO it was clear it was not compliant. It could never know the potential adtech it was going to load in advance (and therefore could not ask someone to consent), and it still allowed ads/adtech/trackers to load in page before asking for c…

But don't the adtech vendors have to declare what they do with the data? (Purposes and Special Features)?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#9
>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

Post reply on HN