Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

121–130 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#121
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

How are they screwing users? By showing them relevant ads?

Breaching privacy, having a detailed dossier of my online behavior, is itself a harm done onto me.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#122

> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?

Without knowing what country you're in, I suggest that your comment indicates that Europe has more strict laws about tracking than your own country.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#123
To be frank, the practical result of GDPR is that it made my browsing experience worse.

Nearly every website opens with an annoying cookie popup, often blocking the content (or reducing it to a fraction of my screen on mobile).

I've never once clicked "Yes, track everything", except by accident when tricked into it by deceptive UI (eg. a button designed to look more inviting than its less invasive counterpart).

I get that wasn't the intent, and there are less intrusive ways for companies to comply. But the result we ended up with is a mess.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#124
post #20

Earlier quoted context omitted.

All the data they were collecting before that GDPR said they had to stop collecting (without freely given consent).

How much data is that? How do we know? It's not clear to me how the ICCL will know that "all data collected" is deleted. Even if the IAB is sanctioned or you storm their datacenters, the ICCL said that the tracking industry collected data through the IAB. How is the ICCL going to ensure that the tracking industry deletes the collected data?

It doesn't really matter "how much" data. What matters is the type of data and whether or not it's strictly necessary to deliver the content.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#125
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

How are they screwing users? By showing them relevant ads?

By not complying with users' lawful rights under the GDPR.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#126
post #81

Earlier quoted context omitted.

I like the idea, but that protocol is too simple. For example, I don't have too much of a problem with Matomo tracking cookies, but I don't want Google Analytics to follow me around the web. This header doesn't specify any of that, and I'd still need to give some kind of consent through a cookie pop-up to websites that want me to use that stuff. I'd rather see a modern version of P3P ( https://en.wikipedia.org/wiki/P…

I see your point, but one of the main problems of P3P was its complexity. There's more than two decades of privacy-enhancing technology research showing that privacy controls need to be fundamentally simple. I think DNT/GPC can be more fine-grained than you make it out to be. The spec is simple, but there's nothing in there that stops you from developing a browser extension that only sends DNT/GPC signals to a curate…

I agree that P3P was way too complex, but so are the cookie popups that plague us today. P3P was built around legalese and privacy statements rather than simple consent, I think a modern take can do much better.

The extension you propose would be my vision of a modern P3P, but with categories you can set up with defaults. You don't want to force a NoScript/uMatrix style screen onto users, so the browser should simplify a bit, but a header that says "yes for necessary services, yes for analytics, no for tracking, no for advertising" (or something like that) would fit my requirements.

I think websites should also have a way to show _why_ and _how_ they process data, because that's part of the informed consent users give. A simple text field with a maximum size to force short descriptions, maybe with a "more details" button next to the selected purpose could be enough.

I don't think just sending a header would suffice because you'd still get consent popups if there's no other way to get consent. A boolean "sell my data" kust doesn't encompass the consent you're giving websites when you allow/deny.

It's a challenge to keep simple, for sure, but the UI and server-side API can be simpler than the underlying protocol. Consider the browser language list that nobody uses: to the user it's just an ordered list of languages, but in the user agent headers each language gets a numeric weight added to it. Or Firefoxs's "block trackers" button that substitutes Javascript when you enable it and applies all kinds of weird rules and detections to work.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#128
post #20

Earlier quoted context omitted.

All the data they were collecting before that GDPR said they had to stop collecting (without freely given consent).

How much data is that? How do we know? It's not clear to me how the ICCL will know that "all data collected" is deleted. Even if the IAB is sanctioned or you storm their datacenters, the ICCL said that the tracking industry collected data through the IAB. How is the ICCL going to ensure that the tracking industry deletes the collected data?

They will ask the companies to delete the data and take action if there is evidence they didn't, just like how all of GDPR is enforced.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#129

Collecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.

> Collecting and selling digital data is not a legitimate business enterprise. According to who, you? > It’s spyware. How is it spying when the people are freely giving away their data? > If no one wants to pay for your product, the market has spoken. Too bad. Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data? > W…

> Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data?

If a business model depends on spying on users, it's not sustainable, and moreover, it's illegal in the EU. People are not giving their data away freely if they have a) no way of understanding the consequences of clicking a single button, b) get tricked into consenting using dark patterns, and c) their refusal to consent isn't even obeyed (TCF loads tracking scripts before users can consent).

In general, one of the requirements of the GDPR is that all information on usage of provided data has to be written in simple, comprehensible terms. Please tell me how you knew the implications of giving consent on a IAB site, namely your data being shared and sold across thousands of companies. If even techies fail to understand that, how can anyone expect that of ordinary people, our parents, kids?

It should be clear that with a law like the GDPR in effect, the IAB is acting unlawfully.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#130
post #50
post #10

Those popups did teach one good thing: when you see "legitimate interest" you know you're about to get scammed.

I'd love to know how often a 'reject all' button actually objected to all 'legitimate interest' crap too. I expected the answer is site and consent management system dependent, so where I really couldn't avoid one of these sites, I'd manually object to all legitimate interest first before pressing it. Such a PITA and probably pointless ultimately, but hey..

Never, as far as I could tell. That was the whole point of the "reject all" button: to trick you into implicitly "agreeing" to the "legitimate interest" section.
Post reply on HN