Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

141–150 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#141
Whilst I don’t like cookie banner, I personally appreciate the EU GDPR simple style of cookie banners which are simply three options:

- accept all - necessary only - reject all

So many websites outside the EU have a mass of dark patterns for which I increasingly reject all or leave the website.

GDPR is really simple.

Only store data that you really need to service the customer’s needs, always permit the customer to correct incorrect data and allow them to delete it unless you have a legal reason to keep it. Report GDPR failures within 72 hours where customer data has been compromised and treat PII carefully.

In the US - fuck the customer.

I know which I prefer.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#142

Earlier quoted context omitted.

it's not that it's hard to comply, it's fighting malicious compliance which is hard. nevertheless, it's a good damn question why every single operator that has "accept all" and doesn't have "reject all" right there on the consent banner isn't fined on the spot. I think the commission noted this behavior and malicious compliance is already factored into the DMA act. The "deregulation" of GDPR could as well be retrofit…

That's cute. Worth noting first that this is not really the GDPR (nobody here has said that it is directly, but in other threads people are making that assumption), this is the ePrivacy Directive (which is probably what the EU should be revising in light of these universally hated popups). The EU hands out arbitrary fines to large companies that range in the hundreds of millions of dollars, and ask companies to compl…

I honestly don't see how your comment makes sense.

Tt's the GDPR (published in 2016) that mandates that consent must be freely given. Using a 2002 directive to justify your point is disingenuous. You could have selected instead the 2020 guidelines [1] that are extremely detailed and address this point explicitly:

[quote]Example 17: A data controller may also obtain explicit consent from a visitor to its website by offering an explicit consent screen that contains Yes and No check boxes, provided that the text clearly indicates the consent, for instance “I, hereby, consent to the processing of my data” […][/]

> You call it malicious compliance; sure, but when this is what everyone else is doing, and you decide that you want to go against "industry norms" for your website, you are painting a giant target on your back.

Non sequitur. Surely refusing to engage in malicious compliance paints _less_ of a target on your back, especially when that "malicious compliance" is actually non-compliant.

[1] https://www.edpb.europa.eu/sites/default/files/files/file1/e...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#143
post #46

Earlier quoted context omitted.

I think cookie banners are a not-so-subtle sabotage of the GDPR. The more annoyance they can associate with GDPR the more the customers will want to water it down. And bonus, it's completely deniable.

And it's largely working. Even on a site like HN where you'd expect people to be educated about this stuff, we have people claiming that GDPR (and not their own data collection practices) forces them to pop up a cookie banner.

On a site like HN you'd expect a significant proportion of people to be willfully ignorant and/or make excuses about this stuff because it helps them sleep at night.

I have been suspecting for a while that the "consent" escape hatch was a concession to get GDPR past the advertising industry's army of lobbyists. Making the problem in-your-face-visible is hopefully only the first step in garnering support from the public. It's much easier for a politician to point to all the obnoxious pop-ups and say "look at this despicable behavior! These companies choose to nag you at every opportunity because abusing your privacy makes them a couple cents. They should just not be allowed to do that."

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#144
post #135

Earlier quoted context omitted.

We live in an Orwellian world: War is peace. Freedom is slavery. Ignorance is strength. Simplification is complication.

"Si vis pacem, para bellum" we have always lived in that world.

Si vis pacem, para bellum - "If you want peace, prepare for war."

https://en.wikipedia.org/wiki/7.65%C3%9721mm_Parabellum

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#145
post #95

Earlier quoted context omitted.

Alternatively: Peace is a lie, there is only passion. Through passion, I gain strength. Through strength, I gain power. Through power, I gain victory. Through victory, my chains are broken. The Force shall free me.

> Peace is a lie, there is only passion. Lie is Truth... sure, sure. > Through passion, I gain strength. Weakness is Strength Sounds like a 1984 sequel from 1939.

Seems to be the Sith Code :)

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#146

As a big GDPR fanboy, one thing I would be happy for them to remove is the portability between providers requirement: it was essentially dead on arrival, is not implemented, and could be done away with. The other EU-level regulation that needs to be either removed or completely rethought (since it will clearly not be enforced in a way that makes sense) is the cookie regulation. It was well-intentioned, badly implemen…

> I would be happy for them to remove is the portability between providers requirement: it was essentially dead on arrival, is not implemented, and could be done away with.

Well, they actually shouldn't. There are non-EU email providers that show exactly what would happen - customers wouldn't be able to transfer out their email from that service provider. Unlucky if they won't notice that limitation in time.

> The other EU-level regulation that needs to be either removed or completely rethought (since it will clearly not be enforced in a way that makes sense) is the cookie regulation. It was well-intentioned, badly implemented, and the GDPR addresses more of the core problems, it is time to do away with it.

Or simply start handing out fines for malicious compliance.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#147
post #121

Earlier quoted context omitted.

The EU didn't mandate that annoying UI. That's malicious compliance from businesses who are trying to undermine the law.

You're suggesting that companies ruin their own UX to "undermine a law?" That this is all a big conspiracy by nearly every company on the web against our precious overlords in the European Commission?

The core of the system is simple - you list the third parties you send data to, you make accepting and rejecting equally easy.

Consider basically any popup on a popular website which: takes over most of the screen, makes "accept" the highlighted action button, requires going through "customise" to reject, sometimes requires unchecking categories manually, puts "save and exit" and "accept all" that so the same thing next to each other, either hide or not provide "reject all", etc.

There is no conspiracy here. You can either not use third parties, or if you do, your approval system doesn't have to be obnoxious at all, but almost every page makes it a shitty experience to 1. Make you accept out of frustration. 2. Make your angry that this is asked in the first place.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#148

Earlier quoted context omitted.

And it's largely working. Even on a site like HN where you'd expect people to be educated about this stuff, we have people claiming that GDPR (and not their own data collection practices) forces them to pop up a cookie banner.

On a site like HN you'd expect a significant proportion of people to be willfully ignorant and/or make excuses about this stuff because it helps them sleep at night. I have been suspecting for a while that the "consent" escape hatch was a concession to get GDPR past the advertising industry's army of lobbyists. Making the problem in-your-face-visible is hopefully only the first step in garnering support from the publ…

Nah, next step would be to pull the UX noose tighter and tighter, limiting things like number of clicks to reject non-essential cookies, restricting data loss (like if you already filled in some form data, etc.), maybe even limiting how much of the screen they're allowed to take until the user clicks on "read more" or whatever, etc.

I don't think this is necessarily going to happen, but that would be the reasonable next step from where we are now: boiling the advertiser frog slowly and with changes that users would consider uncontroversially positive.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#149
post #109

Earlier quoted context omitted.

It would have been easy to write in generic wording that the "do not track" header must be respected by websites. I'be been wondering for ages why this wasn't implemented.

From the implementation and enforcement, it seems like GDPR was an attempt to make tracking visitors so expensive and difficult that it would eliminate targeted marketing, without negatively impacting consumer choices. The 'do not track' header would not achieve this goal.

It would if "do not track" had to be treated as an automatic "only essential cookies" choice to avoid cookie banners altogether.

At first it would only affect a couple of users, but sooner or later enough "life hack" videos would be out there informing plenty of users about how to get rid of those annoying cookie banners.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#150
post #140

Earlier quoted context omitted.

Ok, let me try to explain once again: > if you have experience with it This must not be an expectation for any regulation that applies to business in general. Let’s say I just graduated from a college where I learned to be a plumber. I registered my firm and now want to acquire customers online, so I hire some local agency to build a website and an order form. You cannot realistically expect that I have any experienc…

> This must not be an expectation for any regulation that applies to business in general Why not? We have that for a bunch of professions already, and for good reasons. You can't just claim to be a doctor, run a hospital or work as a electrician, you need to prove you're able to, before you can do certain things. Engineers should already be data-aware by default, regardless of what regulations, since we do have the e…

> Why not? We have that for a bunch of professions already … > Engineers should already be data-aware by default

Most businesses in this world are not run by software engineers. Engaging with people for whatever reasons via digital channels is not a profession. I don’t really understand your point: as I said already several times, the law can and should be improved. Do you disagree with that? Do you insist that every plumber or relocation business should be an expert in GDPR?

Post reply on HN