Live data from Hacker News

Dear Email Industry, We’ve Got a GDPR Problem

jacquescorbytuech.com

181–190 of 215 posts

Re: Dear Email Industry, We’ve Got a GDPR Problem

#181

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

You can tracking pixels to track per-user engagement. You can also use tracking links to connect the email address to website activity. As you say, it's possible to use these to track in the aggregate, but many platforms allow tracking by individual.

You are correct that the email was already personal data. But, GDPR requires that each new use of data be transparently communicated and legally justified (which may or may not mean consent), even if it's only using data you already have. The fact that they have already identified the user does not resolve the issue--GDPR still cares when you collect more data about a known user.

Meaning, even though you are justified using the email address to send the newsletter, you may not be in the clear building an engagement profile associated with that email. Which, apparently, some email marketers do.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#182

Earlier quoted context omitted.

My point was that the laws are in place now, but appear to be toothless. I received a marketing email disguised as an order update after an explicit opt out, and reported it to ICO in the UK. ICO told me I had to take it up with the provider, and if they didn't resolve it to get in touch. The provider said sorry and closed my ticket, and I contacted ICO again who just mothballed me. Laws are only effectivr if they're…

> the laws are in place now, but appear to be toothless Currently the country's regulators (such as ICO in the UK) are swamped with GDPR complaints and are prioritising the most egregious cases. I imagine cookies are a way down the list. In terms of reporting, you tell the company itself first, if you don't get satisfaction you report to your own European country's regulator, or that where the company is based.

The agencies responsible are unable to deal with requests, so for all intends and purposes, the laws are toothless until they start cracking down on it, and there's nothing I can do/nobody I can tell about it.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#183

"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address" "The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them" G…

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

> Now, what additional personal data are collected by tracking pixels?

In theory, an IP can be captured, which is considered PII, but most mailbox providers use proxies so this isn't reliable.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#184
post #178

Earlier quoted context omitted.

Somehow all those groups managed to get by without email in the past. I'm sure they would be fine today as well.

Just because you don't want to hear from anyone via email doesn't mean I don't.

That's fair. I'm guessing those groups can all manage to communicate with you without spying on you.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#185
post #181

Earlier quoted context omitted.

If they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.

You can tracking pixels to track per-user engagement. You can also use tracking links to connect the email address to website activity. As you say, it's possible to use these to track in the aggregate, but many platforms allow tracking by individual. You are correct that the email was already personal data. But, GDPR requires that each new use of data be transparently communicated and legally justified (which may or…

Not some, all email marketers do.

There's nothing stopping them either, they're entitled to do so, given they obtain consent for that data processing.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#186
post #99

Earlier quoted context omitted.

GDPR wants 0 tracking. That's wrong too, the internet can't work that way, even governments can't work that way. EU wants advertising to go back to the popup / animated gifs & flash / interstitial era to maximize clickthroughs in the off-chance one of them is actually interested in your ads. That's regression

GDPR wants 0 tracking without explicit, informed consent . That's the key thing in this regulation: informed consent. Dealing with people fairly. > EU wants advertising to go back to the popup / animated gifs & flash / interstitial era to maximize clickthroughs in the off-chance one of them is actually interested in your ads. Not true, unfortunately. EU wants the ads to not track people without their explicit, inform…

- users could always install an adblocker if they dont consent.

- users could consent once for each tracker if thats what the law cared for. Consenting for each tracker x for each website is purposeful obstruction in order to make advertising optional

Re: Dear Email Industry, We’ve Got a GDPR Problem

#187
post #65

Earlier quoted context omitted.

Just because you associate emails with spam doesn't solve the problem of every charity, business, church, school and group needing to communicate with large numbers of email subscribers. Like anything, bad actors make it worse.

Somehow all those groups managed to get by without email in the past. I'm sure they would be fine today as well.

They also got by without electricity or running water.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#188

Earlier quoted context omitted.

Not having marketing spammers is still better than having spammers and scammers

There's usually an unsubscribe button for marketing spam, and if there isn't I usually block their email. You can't do that with scammers / illegal spam.

It's not like legitimat-ish email marketing will suddenly switch to scammers or illegal spam, they would actually get in trouble for violations. Companies that don't rely on scams aren't desperate enough to risk getting fined for such a weak lead (I'd hope).

Not that I'll ever configure my email client to automatically download images, as far as I'm concerned downloaded images is just making your email address more valuable to the spammer by confirming you got it.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#189

Earlier quoted context omitted.

We generally fine them big for breaking it, and may forbid them from doing business at all if they keep breaking it

Who is "we", how do "we" decide who is breaking the laws and how can _I_ tell themof a blatant disregard for the laws?

Every country implements their version of GDPR and it's sanctions. You can tell your authorities or dedicated organization about violations. Not all countries have yet implemented procedures for them however.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#190
post #150

Earlier quoted context omitted.

No "industry" is needed for pub/sub news. The GDPR only affects the companies abusing current system for unsoliticed advertising

> GDPR only affects the companies abusing current system for unsoliticed advertising No. Have you looked at the thing? It affects every organization willing to do business or communicate with the EU.

The rules dictated in GDPR have been the best practices this far, now they're simply being enforced by law.

The only ones that are (negatively) affected are the companies that are not wanted by the EU in the first place.

Post reply on HN