Earlier quoted context omitted.
> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it. > Without. Your. Consent. I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data accordi…
Freely given consent, as per the GDPR, must be explicit and optional (even if you have consent to use the data for the service being performed). A line buried in a ToS does not comply.
Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
151–160 of 238 posts
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#152Earlier quoted context omitted.
Did you read, or was even aware of, a ToS of a hotel on use of personal data? This is entering the "local planning department in Alpha Centauri" territory. As a regular person, you should not need to be aware of such things. What GDPR tries to do is to restore some sane defaults into the process, just like customer protection laws do.
Yes, I generally check ToS of whatever services I use, including hotels. And no, it's no "local planning department of Alpha Centauri" territory, it's available on their webpage and in paper form at the reception, usually framed and hanging on the wall. I check it to see what happens if I overstay, but skim through the whole thing. As a regular person, if I want to use a service offered by someone, I should at least…
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#153Earlier quoted context omitted.
Yes, I generally check ToS of whatever services I use, including hotels. And no, it's no "local planning department of Alpha Centauri" territory, it's available on their webpage and in paper form at the reception, usually framed and hanging on the wall. I check it to see what happens if I overstay, but skim through the whole thing. As a regular person, if I want to use a service offered by someone, I should at least…
Fair enough. I do read the regular ToS of the hotel that they frame and hang on the wall; it's usually standard stuff and not once I remember reading anything there about use of my data. It's just the usual "hotel night is from X to Y, please don't do ". So from your comment I assumed that there must be an extra ToS that covers use of personal data. If there is, I've never noticed it.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#154Earlier quoted context omitted.
Freely given consent, as per the GDPR, must be explicit and optional (even if you have consent to use the data for the service being performed). A line buried in a ToS does not comply.
That's today, I replied to a comment talking about the GDPR-less past.
"And then, without your freely given consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it."
And the point still applies.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#155Earlier quoted context omitted.
That's today, I replied to a comment talking about the GDPR-less past.
My point is that you can simply change the previous comment to read: "And then, without your freely given consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it." And the point still applies.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#156Earlier quoted context omitted.
> There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate. You don’t have to do anything to “activate” these rights under GDPR. You can just email the website in question and ask them to send an accessible copy of your data, or remove some or all of it from th…
> You don't have to do anything .... just email the website ... Okay ... let me try this. > TO: cnn.com > SUBJECT: Remove my data Okay, let's send it! > gmail: The address "cnn.com" in the "To" field was not recognized. Please make sure that all addresses are properly formed. Oh. I've been around the block; maybe I can try admin@ or support@ or look at whois data, or browse around their website for a "Contact us" lin…
This is the template they seem to be using for erasure requests: https://github.com/opt-out-eu/opt-out/blob/master/src/email-....
--
[0] - Maybe. I'm not endorsing it, I just found it today. I wish someone (maybe the author) could say something more about the validity of such process, and whether this kind of e-mail is enough in practice.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#157The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#158The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
> The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. At this point I just want those consent forms to be standardized via ARIA tags or whatever so that some extension can click the "yea, sure, whatever" button for me.
Integration of legalese into browsers should have been done a long time ago (another useful thing would be a "ToS" button in the address bar, so you don't have to go hunting for ToS and privacy statements, and read them in whatever painful CSS flavouring the site uses).
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#159The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
Yes that's what is most annoying that many companies by default assume opt-in to their spying activity, despite GDPR regulation saying that all consents should be opt-out by default. As a result, after clicking on 21 pop-up and opting out suddenly I notice that I stop caring... so in this area it seems GDPR is effectively dead regulation.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#160Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…
> The internet was doing fine for decades with minimal involvement from governments - why change things? Things change on their own. The internet used to be accessed by highly sophisticated and technical users. Now it's mainstream. And all mainstream things follow two basic rules: 1. Everything move at the speed of the slowest person. 2. The weakest members of the community need to be protected.