Live data from Hacker News

Facebook’s tracking of non-users ruled illegal again in Europe

techcrunch.com

181–190 of 395 posts

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#181

Earlier quoted context omitted.

It is, if having access to the site is in their interest. The site needs ads to survive, they are a form of payment.

The internet existed before ads, people created content and hosted websites without invasive tracking. And let's be honest, most ads are total garbage.

I remember the 90s internet. It was a neat place but I wouldn't call it very useful by modern standards.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#182
post #136

Earlier quoted context omitted.

I’m looking forward to the GDPR. It seems to target all the failures of the cookie law. The GDPR will not allow blanket consent statements, it will not allow “permission bundling” (eg. allow acces to everything or you can’t use the site). The changes Twitter rolled out in preparation of the GDPR look like a good thing. We’ll see how it turns out, but I think the GDPR will actually force companies to change, beyond co…

> it will not allow “permission bundling” (eg. allow acces to everything or you can’t use the site) This is something I have not been able to come to terms with. I can understand requiring express consent to each item individually, rather than burying everything into a long ToS. But what I cannot understand is forcing me (as a service provider) into a contract with a customer even if the customer rejects some of my t…

Yes, ideally the customers would sent back their modifications of your EULA, and then you would negotiate a new contract to the benefits of both of you or not do business with each other.

In practice, this seems difficult and the relations of power in modern EULAs are fairly asymmetric. For example, in many areas there is only one provider of some needed service. like e.g. an ISP. Partial contracts and a certain emphasis on customer protection seem like a reasonable compromise.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#183
post #114
post #91

Earlier quoted context omitted.

The DPR has been implemented since 1998. GDPR had been announced 2012, implemented fully in 2016. Active enforcement will start May 2018 with again a temporary period to allow companies to correct. Refusal to comply after that can result in penalties up to a maximum of 4% of the companies global revenue. How much courtesy lead time does a company actually need to comply?

Especially when such company is pushing legions of developers reduce their "time to market". "You have 20 seconds to comply" says the robocop :-)

Exactly, someone has to be Kinney, and it better be someone already too big for our own good.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#184
post #136

Earlier quoted context omitted.

> it will not allow “permission bundling” (eg. allow acces to everything or you can’t use the site) This is something I have not been able to come to terms with. I can understand requiring express consent to each item individually, rather than burying everything into a long ToS. But what I cannot understand is forcing me (as a service provider) into a contract with a customer even if the customer rejects some of my t…

> But what I cannot understand is forcing me (as a service provider) into a contract with a customer even if the customer rejects some of my terms. I'm not sure what gives you that impression. If the customer rejects the terms, you are free to walk away.

GDPR requires consent to be freely given. If customer A rejects the terms and you "walk away" and deny the service, then if customer B clicks accept, you still can't interpret it as freely given consent and nothing customer B does will give you the permission to process customer B's data.

The GDPR position is that the privacy rights are not something that customers can "trade away" in a contract, they're not for sale. If the customer genuinely wishes you to do that processing, you're allowed to do so; and if they don't, then that processing shouldn't be done at all.

The way it's written it has some similarities with sexual consent - just as a valid signed contract stating "I'll allow you to violate my arse for $1000000" legally cannot be a binding contract term (even in places where prostitution is legal) doesn't really give you the unconditional permission to violate my arse and that consent can still be withdrawn at any time; in the same manner a contract stating "I'll allow you to violate my privacy for $1000000" cannot be a binding contract term in any consumer contract according to GDPR. Just as many, many other terms in EU consumer contracts (e.g. binding arbitration clauses, voiding of warranties, excessive penalty clauses, unilateral changes in terms, etc) - even if the company puts it into the agreement and the consumer signs, they are considered automatically unfair and unenforceable.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#185

Earlier quoted context omitted.

> A lot of people are keen on industry regulations (which GDPR sort of is) but i think are not aware of (a) how bad the bad ones are and (b) the very dominant corporate/incumbent bias they give a market. I think rather than arguing in general terms that regulation is bad, it is more helpful to address any specific problems you have with GDPR. I've spent a few months looking at it at a small organisation that is havin…

I don't think that I did. Just pointing out some recurring themes, generally. We don't have that many examples and "regulation" is a fairly squishy category. But, I think anyone who's worked in a business where the word "compliance" comes up regularly has a clear idea of what this means. Incumbent friendliness is a real concern. In my experience, it is taken as a given by industries facing potential "regulation".

The other side of that is how much mental energy do you give to the ways companies are allowed to lie or mislead. If you’re renting an apartment is the sticker price what you’ll actually pay or are there admin costs both to starting the contract and every month. The UK has recently started to crack down on excessive charges relating to starting a renting contract, with broad positive support.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#186

Earlier quoted context omitted.

Oth: it's a calibration process. If the regulations are to onerous, we can loosen them again, or companies will spring up that make compliance easy. https://www.chargebee.com/ solves the European VAT nightmare for example, until we have harmonization on that front. Is it inefficient? Depends on your model of the world: I'd rather pay a bit more for my goods/services and know that my privacy and data autonomy are pres…

I don't have too much confidence in calibration. The legislative/regulative systems we have are not great at that. Legislation is principles and inflexible. Flexibility requires a more uprincipled, goal oriented approach. Also, goals (mine, anyway) like openness, cosmopolitanism, low barriers to entry and even playing fields... These are hard to measure. In almost all cases, industry regulation (what this is, more or…

Some regulation only applies to incumbents, monopoly law for example.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#187
post #7
post #4

Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry: * Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service * Opt-in/out separately for every activity (no more "research purposes") * Data dele…

What we are seeing is that the ad providers are considering themselves "controllers" under the GDPR and the tracking of device ad identifiers as critical to their business. Hence, their plan is to inform of the collection via a privacy policy but not to offer users the opportunity to affirmatively consent to allowing their advertising ID to be tracked. It's dispiriting.

I'm pretty sure that this kind of behavior will be shot down by EU or Local courts. The GDPR contains parts where it explains what kind of reasons might lead to overriding of legitimate or critical interests.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#188

Earlier quoted context omitted.

No, you could outlaw degrading functionality, which is what they are doing in the new law.

How do you do this for services where functionality is reliant on tracking etc? E.g. some of Google's services.

You can only degrade when the users denial exactly relates to the function of the service.

I have history turned off in google maps. I can’t name the points I make, it tells me I need to turn history and tracking back on. I hope that becomes an unjustifiable degrade.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#189

Earlier quoted context omitted.

No, you could outlaw degrading functionality, which is what they are doing in the new law.

How do you do this for services where functionality is reliant on tracking etc? E.g. some of Google's services.

You don't do these services without obtaining the user consent first. Simple as that.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#190

Earlier quoted context omitted.

But what's the alternative approach to the cookie law? A yes/no consent page before your site, and if you click no, the user doesn't get to access it? Because that's basically the same thing, but even more annoying.

Which is why there is the "And more importantly you can revoke it (at any point) and the site can't deny or degrade the service (unless the data is strictly necessary for a specific action related to the service)." point - you're not allowed to deny access to a newspaper article if somebody does not consent.

Unless you are charging for the content, I suppose.
Post reply on HN