Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

141–150 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#141

Earlier quoted context omitted.

Transparency. People are overwhelmingly unaware of the volume and types of data that is collected on them. And at this point the free market can’t resolve this. The spyware model has absolutely ruined the internet economy. There is no way to compete against a spyware company with a paid product.

If people are choosing "spyware" over a "paid" product, perhaps they just don't care about data collection that much. Isn't that the logical conclusion? Objectively ads have added more money into the internet economy than ever before. Curious where you're getting your numbers. 20 years ago "YouTuber" wasn't even a profession. The idea some rando with a microphone and a camera could make millions was unheard of. It's…

People are rarely, if ever, given that choice.

Because it spells out the nature of the non-paying option as spyware.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#142

Earlier quoted context omitted.

Transparency. People are overwhelmingly unaware of the volume and types of data that is collected on them. And at this point the free market can’t resolve this. The spyware model has absolutely ruined the internet economy. There is no way to compete against a spyware company with a paid product.

If people are choosing "spyware" over a "paid" product, perhaps they just don't care about data collection that much. Isn't that the logical conclusion? Objectively ads have added more money into the internet economy than ever before. Curious where you're getting your numbers. 20 years ago "YouTuber" wasn't even a profession. The idea some rando with a microphone and a camera could make millions was unheard of. It's…

People don't care about a lot of things. Mainly because they don't understand them, or don't know about them: climate change, cancerous substances, plastic waste, homeless people, illegal whaling, domestic cats killing singing birds, sewing winter clothing or properly managing their savings.

That is why we have subject matter experts providing guidance for people in a world too complex to grasp or even care about everything they have to deal with. People _shouldn't have to care_, as long as they can trust on those experts to do the right things. We're the experts. Advertising companies are ruining the internet for everyone, some people are just too unaware to realise it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#143
Some crazy figures here:

The maximum fine for such a breach is 4% of the company's global revenue.

Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96.

Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of damage limitation).

The EU general budget in 2019 was only €148.2Bn. So such a fine would actually cover nearly 20% of the running cost of a 27 member multilateral trading entity with a population larger than the United States.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#145

Earlier quoted context omitted.

They don't know. But if evidence comes up showing a company didn't then they will take legal action against that company, in which case intent to break the law from the would be crystal clear so they would get maximum fines which are huge for GDPR. It isn't like laws prevents all crimes, the goal is to reduce illegit data usage, there is nobody who thinks it can ever get completely stamped out.

I'm asking what kind of evidence can exist that proves a negative? Without knowing what was collected how can they prove it was deleted? Doesn't make any sense.

> Without knowing what was collected how can they prove it was deleted?

They don't need to know what data was collected. GDPR requires you to track all data and mark where you got it from, so the companies are legally required to track this for you, they should already have a switch where they can delete this data at the notice of the user, so they should have no problems honouring such a request from the government.

The government don't know if the data was deleted, but a user will know if a company has data the user didn't agree to give to the company, in which case that company is violating GDPR regardless how they got that data. That wont always come up, but if it does the government will go after those companies.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#146
post #142

Earlier quoted context omitted.

If people are choosing "spyware" over a "paid" product, perhaps they just don't care about data collection that much. Isn't that the logical conclusion? Objectively ads have added more money into the internet economy than ever before. Curious where you're getting your numbers. 20 years ago "YouTuber" wasn't even a profession. The idea some rando with a microphone and a camera could make millions was unheard of. It's…

People don't care about a lot of things. Mainly because they don't understand them, or don't know about them: climate change, cancerous substances, plastic waste, homeless people, illegal whaling, domestic cats killing singing birds, sewing winter clothing or properly managing their savings. That is why we have subject matter experts providing guidance for people in a world too complex to grasp or even care about eve…

> Advertising companies are ruining the internet for everyone, some people are just too unaware to realise it.

Sounds like projection. Though I'd agree that most internet users don't like ads, what's true is that most internet users don't like paying for things. Using YouTube as an example, the most popular site on the internet, the vast majority of people do not pay for YouTube premium even though it's available.

At the end of the day no one is stopping you from going back to circa-2000s internet, using IRC, going on plain text websites, using BBS, etc.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#147

> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?

If you live in the US as I do: yes, they are. I traveled to Germany and Belgium shortly before COVID, and the pop-ups were everywhere, even on sites that I know didn't have them back home.

Anyway, I'd prefer if we had privacy laws like this in the US too.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#148

Some crazy figures here: The maximum fine for such a breach is 4% of the company's global revenue. Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96. Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of da…

[deleted]

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#149

Earlier quoted context omitted.

I'm asking what kind of evidence can exist that proves a negative? Without knowing what was collected how can they prove it was deleted? Doesn't make any sense.

> Without knowing what was collected how can they prove it was deleted? They don't need to know what data was collected. GDPR requires you to track all data and mark where you got it from, so the companies are legally required to track this for you, they should already have a switch where they can delete this data at the notice of the user, so they should have no problems honouring such a request from the government.…

What you're saying is literally illogical in the case of IAB acting as an intermediary... Not sure you know what you're talking about in this case. The entire point of the original article is that the user's data is being fed through via IAB to tracking companies. This isn't a normal GDPR situation where the user's data directly is being stored in a way that's accessible to the user as well. Obviously in that scenario the user themselves could just request their data be deleted as that's what GDPR allows. IAB in this case has been acting as an intermediary, allowing tracking companies to collect metadata on users through them. Even if IAB deletes their data, the question is how will the Council know if the end-tracking companies deleted their data?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#150
post #138
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

I think you meant to use the word lose not loose. I suspect you mean lose the data as in delete it, not loose as in releasing the data to others.

thanks
Post reply on HN