Live data from Hacker News

Flattr now deletes your web browsing history within 3 months

ctrl.blog

11–20 of 98 posts

Re: Flattr now deletes your web browsing history within 3 months

#11

Except its not ‘in practice’ because gdpr does not require such thing. In spirit, maybe [i.e. practically they wouldn't be fined for this]

It might be reasonable to conclude that, in practice, GDPR has caused a number of companies to their re-assess data collection and retention hygiene (even beyond the minimum bounds of the law). In particular, this change seems to be a very charitable or expansive reading of the requirement under the GDPR for companies not to collect more than is necessary -- as the post ends by noting.

I think hygiene was mostly in place, but there was no PR points to score. Before GDPR an information that company stores something for 3 months would be a non-news. GDPR doesn't in any way protect people from data leaks.

Re: Flattr now deletes your web browsing history within 3 months

#13
I love how some of the tech industry is beginning to see data as a liability rather than an asset. It dramatically reduces the ability for government mass surveillance for two reasons:

1. If companies only collect what they need (to reduce their liability), governments can't demand more than that (or even hack in to get the data illegally).

2. If the industry culture is to limit data collection, governments can't just say, "Well every company does it, so why can't we."

There's a wonderful talk, Haunted By Data, that covers a lot of the societal downsides of treating data as an asset. Highly encourage watching/reading.

Text: http://idlewords.com/talks/haunted_by_data.htm

Video: https://www.youtube.com/watch?v=GAXLHM-1Psk

Re: Flattr now deletes your web browsing history within 3 months

#14
post #4

Wtf?! Why is micro payment processor even recording browser history?!

Flattr is an extension/service that monitors your web usage and uses it to direct your payment towards the sites that you use. Recording your browser history is almost the extensions entire purpose

Re: Flattr now deletes your web browsing history within 3 months

#15
post #6
post #4

Wtf?! Why is micro payment processor even recording browser history?!

From the article: "Flattr subscribers make a voluntary payment from 3 USD/month, install the company’s browser extension which collects their browsing history, and then Flattr divides their subscription fee out among the creators and websites they spent the most time on."

That could be done in a totally anonymous way. Add up total number of donations and total number of visits and distribute money accordingly. There is no need for them to ever store personal information for this.

Re: Flattr now deletes your web browsing history within 3 months

#16
post #12

"Ads on this site don’t track or stalk you. Please disable your blocker." According to my blocker those are Google ads so...

Google AdSense on Ctrl blog is configured to only show non-personalized ads to any users with the Do-Not-Track (DNT) setting enabled or European Economic Area (EEA) citizens. AdSense still uses cookies for rate-limiting and fraud prevention, but not ad personalization or tracking. requestNonPersonalizedAds=1 is part of AdSense’s GDPR APIs. https://www.ctrl.blog/entry/adsense-gdpr-consent

You also only see that particular message if your browser sends the DNT header, and an adblocker is detected.

Re: Flattr now deletes your web browsing history within 3 months

#17

Earlier quoted context omitted.

It might be reasonable to conclude that, in practice, GDPR has caused a number of companies to their re-assess data collection and retention hygiene (even beyond the minimum bounds of the law). In particular, this change seems to be a very charitable or expansive reading of the requirement under the GDPR for companies not to collect more than is necessary -- as the post ends by noting.

I think hygiene was mostly in place, but there was no PR points to score. Before GDPR an information that company stores something for 3 months would be a non-news. GDPR doesn't in any way protect people from data leaks.

> GDPR doesn't in any way protect people from data leaks.

If GDPR provides PR reasons for better data hygiene the result is the same: less data retained, less data at risk of being leaked.

Re: Flattr now deletes your web browsing history within 3 months

#18

Except its not ‘in practice’ because gdpr does not require such thing. In spirit, maybe [i.e. practically they wouldn't be fined for this]

Art. 5:

Personal data shall be:

kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed

Recital 39:

The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum.

The GDPR is very explicit on this point. You must delete or thoroughly anonymise personal data as soon as is practically possible.

https://gdpr-info.eu/art-5-gdpr/

https://gdpr-info.eu/recitals/no-39/

Re: Flattr now deletes your web browsing history within 3 months

#19
post #15
post #6

Earlier quoted context omitted.

From the article: "Flattr subscribers make a voluntary payment from 3 USD/month, install the company’s browser extension which collects their browsing history, and then Flattr divides their subscription fee out among the creators and websites they spent the most time on."

That could be done in a totally anonymous way. Add up total number of donations and total number of visits and distribute money accordingly. There is no need for them to ever store personal information for this.

(a) How do you get the total number of visits.

(b) This doesn't correctly distribute funds because there is a correlation between how much someone is willing to give per month and what kind of sites they frequent.

Re: Flattr now deletes your web browsing history within 3 months

#20

Earlier quoted context omitted.

It might be reasonable to conclude that, in practice, GDPR has caused a number of companies to their re-assess data collection and retention hygiene (even beyond the minimum bounds of the law). In particular, this change seems to be a very charitable or expansive reading of the requirement under the GDPR for companies not to collect more than is necessary -- as the post ends by noting.

I think hygiene was mostly in place, but there was no PR points to score. Before GDPR an information that company stores something for 3 months would be a non-news. GDPR doesn't in any way protect people from data leaks.

>GDPR doesn't in any way protect people from data leaks.

Article 32:

Security of processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

(a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

Recital 83:

In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.

GDPR also mitigates the impact of leaks. Art. 5 requires that data is stored for no longer than necessary for the purposes for which it was collected. Art. 33 requires that the supervisory authority must be notified of any data breach within 72 hours. Art. 34 requires that data subjects be notified of any breach without undue delay. All of this is enforceable with heavy fines.

https://gdpr-info.eu/art-32-gdpr/

https://gdpr-info.eu/recitals/no-83/

Post reply on HN