Live data from Hacker News

Dear Email Industry, We’ve Got a GDPR Problem

jacquescorbytuech.com

151–160 of 215 posts

Re: Dear Email Industry, We’ve Got a GDPR Problem

#151

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

> While spammers may have a problem, people don't. Marketing spammers maybe, but now scammers and malware spammers have the floor instead. Laws only stop the law abiding citizens from doing their thing, it sure doesn't stop the criminals from.... being criminals.

You're right, but this law isn't targeted at scams and malware. It's meant to stop broader commercial tracking, and leaves us better off on that front, while criminals were going to do what they do anyway so we're no worse off there.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#152

Earlier quoted context omitted.

That is a good point. If my browser is sending a do not track header, why is your server even asking me how much tracking I want?

Clearly they are asking because they hope that you click "Yes". Once you click "Yes" they give you a cookie and stop bugging you. It's a nasty trick of the tracking industry. GDPR does not forbid websites to ask or even deteriorate your experience (afaik). Perhaps that should change.

GDPR does forbid providing a lesser experience for people who do not consent to tracking. (Obviously aside from the direct consequences of not having tracking, like getting different adverts.)

Re: Dear Email Industry, We’ve Got a GDPR Problem

#153

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

> While spammers may have a problem, people don't. Marketing spammers maybe, but now scammers and malware spammers have the floor instead. Laws only stop the law abiding citizens from doing their thing, it sure doesn't stop the criminals from.... being criminals.

Actually it does, because if industry stops using tracking pixels, it demotivates email clients from having to support it, and makes it easier to block bad actors. Same with tracking on websites and browser support. Chrome would instantly put in a tracking blocker if Google couldn't do tracking any more. But so far Google's strategy is fighting and working around the law because they think they would lose a huge amount of revenue without tracking.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#154
post #70

Earlier quoted context omitted.

Great, so how do we fix that and stop them doing it?

Wait for a small number of companies practicing the “by using this service you agree to” thing to be fined a large part of their turnover. After that companies will adapt. Now we are in a sort of transition phase where laws are written but companies interpret them themselves (badly) and there are few guiding cases. I look forward to the next phase when the notices will be gone or say “did you know you can enable trac…

My point was that the laws are in place now, but appear to be toothless. I received a marketing email disguised as an order update after an explicit opt out, and reported it to ICO in the UK. ICO told me I had to take it up with the provider, and if they didn't resolve it to get in touch. The provider said sorry and closed my ticket, and I contacted ICO again who just mothballed me.

Laws are only effectivr if they're enforced, and right now the tracking laws of the GDPR don't appear to be enforced, or have any sort of method for reporting, which is really really disappointing

Re: Dear Email Industry, We’ve Got a GDPR Problem

#155
post #70

Earlier quoted context omitted.

Great, so how do we fix that and stop them doing it?

We generally fine them big for breaking it, and may forbid them from doing business at all if they keep breaking it

Who is "we", how do "we" decide who is breaking the laws and how can _I_ tell themof a blatant disregard for the laws?

Re: Dear Email Industry, We’ve Got a GDPR Problem

#156

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

What surprises me more is that tracking pixels even work anymore. What email clients don't bother to filter them out?

I am surprised that Apple's built-in email clients on both macOS and iOS load remote content by default. One of the first things I disable when I set up a new machine.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#157

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

If they send you an email it means that they obviously have your email address, which I believe is considered personal data.

Now, what additional personal data are collected by tracking pixels?

> these are used to uniquely identify individuals

I would say that this isn't the case. It is to check that the email was read.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#158

True that the European user should be able to opt-out just from tracking. Our platform MailUp (ESP) is handling this in the preference center (that can be customized). Here is a sample: https://updates.mailup.com/frontend/preferencecenter/363734/...

The last thing I need is another godforsaken preferences center inside a product I was forced to become a "user" of just because some asshole bought my email address.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#159
post #13
post #8

Earlier quoted context omitted.

It is a problem when you are targeting users from Europe, which you are doing almost certainly.

We already have more than enough cookie popups and "heads up" emails whenever a company changes a comma in their ToS. GDPR is a bureaucratic madness and not something to be imitated. Want to educate users about privacy? do it with extensive educational campaigns, not by ruining everyone's experience on the web

Cookie popups are not caused by GDPR.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#160
post #76

Earlier quoted context omitted.

What surprises me more is that tracking pixels even work anymore. What email clients don't bother to filter them out?

Gmail, among others. Gmail proxies remote content when the email is opened, so the IP address of the user is not disclosed, but the time and number of opens can be tracked. Google could proxy and cache remote content in emails when they are accepted by Gmail servers, and that would render Gmail users untrackable by third-parties.

The decision to not cache was a compromise with email marketers after many years. Originally, gmail would not show embedded images by default at all: https://nakedsecurity.sophos.com/2013/12/16/gmail-takes-imag...
Post reply on HN