> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?
GDPR enforcer rules that IAB Europe’s consent popups are unlawful
101–110 of 433 posts
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#102Earlier quoted context omitted.
> how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. They will be pleasant but fi…
How well-versed are they in file systems, database schemas? Will they look at source code? Will they understand it? How will they determine what data came from where?
Also this is not criminal law where someone is innocent until proven otherwise. Companies have to prove themselves that they comply with the law. Like food companies have to log cleaning to show they follow the food regulations, as one example.
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#103My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…
> Which will probably be a nice deterrent against them pulling the same shit again. Unfortunately, there are reasons they want these cookies on there so badly that justify the cost to figure out how to comply with the policy and try again.
I mean, if you take a news website like The Independent, there's not a chance in hell that a competent design and engineering team would sign off on all the bullshit that is dumped on top of the page. It's always added on at runtime.
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#104Earlier quoted context omitted.
I wish my government looked out for me like this.
The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#105Edit: Apparently it's been picked up since last time I looked: https://www.theverge.com/2022/2/1/22911965/yahoo-japan-europ...
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#106>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.
This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…
If you then get a letter from the regulator stating that you were in violation, and have to delete some data, and you answer that you did, and signed it -- then you're likely up to criminal charges if that was a lie.
This is not a line most executives are comfortable with crossing.
If any subsequent GDPR shenanigans come up, and they found you intentionally lied to the regulators, you're in some deep shit.
There might or might not be auditors visiting you after the first letter. If you lie and are found out, your career is over, and you might wind up in prison.
It's not perfect for enforcing privacy, but it's much better than not having such a ruling.
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#107Earlier quoted context omitted.
> Which will probably be a nice deterrent against them pulling the same shit again. Unfortunately, there are reasons they want these cookies on there so badly that justify the cost to figure out how to comply with the policy and try again.
I wonder if it's that or if it's also a case of marketing departments going wild with GTM and Segment and the like, literally throwing the kitchen sink in front of the user's experience in a desperate attempt to measure and drive 'engagement'. I mean, if you take a news website like The Independent, there's not a chance in hell that a competent design and engineering team would sign off on all the bullshit that is du…
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#108Earlier quoted context omitted.
I want one for "If your business model is advertisement, get off my Internet".
Wouldn’t this be easier to implement as a server side header that said “if you don’t like my business model get off my internet”?
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#109> The Belgian Data Protection Authority said IAB Europe “was aware of risks linked to non-compliance” and “was negligent”. It also found that IAB Europe had failed to honour its data protection obligations to maintain records of data processing (Article 30 GDPR), to conduct a data protection impact assessment (DPIA) (Article 35 GDPR), and to appoint a Data Protection Officer (Article 37 GDPR). Even if you were to giv…
Unless you're fresh in the job market and still believe in the good of people, maybe.
Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful
#110On one hand our Data Protection Authority gets that done and on the other hand the European commission is about to start legal action against Belgium for GDPR infringements https://www.brusselstimes.com/news/belgium-all-news/173086/e...
And we just passed a law that permits our IRS to have our bank account's data.
And there is an ongoing project to store and register citizens' health data in one single database, available to insurers and government agencies.
Over the last year there's been drama and real concern around the DPA https://iapp.org/news/a/belgian-dpa-director-resigns/ with director resigning and claiming pressure from the authorities post resignation (as PI rummaging through here trash bins).
We have a guy who single handedly decides if databases projects are OK with GDPR and privacy laws and he's the one providing the software solutions.
Belgian surrealism at its finest.
I know there are people from the north on HN, I wonder what are their view on these matters ?