Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

191–200 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#191

Earlier quoted context omitted.

> Nasty social media that makes their money on outrage and exposing people to scam ads? Last I checked Facebook and friends still exist. > what did we actually lose? * Many europeans lost access to various publishing sites (another win for the big guys) * Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

My entire point of my facebook comment is that GDPR gave us nothing, and people paid by losing news site and lawyer salaries.

I don't care if you aren't personally affected by this. That isn't the argument you should be trying to make. How did GDPR improve your life? AFAICT Facebook may still have your shadow profile

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#192

Earlier quoted context omitted.

> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.

Do you mean the direct cost of implementing the compliance, or the indirect cost of no longer getting extra ad revenue in an illegal way? In most cases I bet the former isn't all that much. The latter is a harder nut to crack, with everyone trying to toe the line and referencing what other companies are able to get away with. Lack of good faith is a big obstacle.

> I bet the former isn't all that much

One of the fundamental problems with GDPR is it contains a federated complain-investigate enforcement model. So your bet would have to apply to each of the EU’s twenty-eight members, now and in the future.

In that context, throwing up notices and calling a day makes sense. One can argue one tried. But not go so far as to potentially create new liabilities by interpreting these enforcers’ current and future preferences too strongly.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#193
post #79

Earlier quoted context omitted.

No, there's no protection for failed business models, as there should not be.

A business model that fails because you explicitly make them illegal isn't exactly a failed business model. The lawmakers made them fail and they either knew it was going to happen or were incompetent.

A goal of the GDPR was to make these business models illegal, because they are considered bad. It has not been successfull at this, mostly due to lack of enforcement.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#194
post #178

Earlier quoted context omitted.

Reminds me when the EU "Fixed" Cookies and now we have these stupid click-through warnings everywhere that have pretty much ruined the user experience. Root cause: people passing laws they have idea what about.

Nothing about the EU law requires sites to put up cookie warnings and degrade the ux. They choose to do that.

But they all choose to do that, so that's the actual outcome of the legislation.

I don't understand why I keep seeing this argument. We all have to deal with cookie dickbars regardless of whether or not your armchair lawyer argument is technically correct. If this is what the law does in practice, and the behavior is generally seen as compliant, then it's a dumb law.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#195
post #79

Earlier quoted context omitted.

No, there's no protection for failed business models, as there should not be.

The business model of Google isn't a failed business model. What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the fo…

They are a giant and those can be hard to topple in one go, but the fact that a giant can continue a failed business model for a longer time does not make it a not failed model.

Hell, at least around 2017, there were voices from Google that they considered ads to be unsustainable long term and sought to diversificate income streams.

The fun thing is, GDPR didn't actually introduce much change in law. It just gave, for the first time in history, existing laws a real set of teeth, even if they are still baby teeth.

So yeah, all that data companies had been vacuuming for no sensible purpose? It was always illegal

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#196

Earlier quoted context omitted.

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

My entire point of my facebook comment is that GDPR gave us nothing , and people paid by losing news site and lawyer salaries. I don't care if you aren't personally affected by this. That isn't the argument you should be trying to make. How did GDPR improve your life? AFAICT Facebook may still have your shadow profile

> How did GDPR improve your life?

People are more aware of privacy violations and even though companies don't fully comply with the regulation, many are at least trying.

I've personally had success in getting multiple EU-based businesses to delete my data and/or fix issues with their marketing infrastructure sending me spam despite not opting into it.

Facebook still has a shadow profile for me but between Facebook having it or Facebook plus a hundred more bad actors having it too I'd still prefer if it was only Facebook.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#197
post #194
post #178

Earlier quoted context omitted.

Nothing about the EU law requires sites to put up cookie warnings and degrade the ux. They choose to do that.

But they all choose to do that, so that's the actual outcome of the legislation. I don't understand why I keep seeing this argument. We all have to deal with cookie dickbars regardless of whether or not your armchair lawyer argument is technically correct. If this is what the law does in practice, and the behavior is generally seen as compliant, then it's a dumb law.

Plenty don't. Hyperbole isn't helpful.

Lots of websites seemingly actually break the law, with full page "can't see the page unless you click accept" etc. The problem seems to be under-enforcement, and then we're right back at the point of TFA.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#198
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.

> There is insufficient evidence attempting to comply with GDPR is worth the cost.

The number of people working at the respective national privacy regulators is appalling. All of them have an extremely scarce amount of privacy auditors that are qualified to extensively investigate privacy breaches. Even Ireland, which has a huge tech hub with the social media companies especially, has a scarce amount of them.

The Financial Times wrote an article about this awhile back, which tends to have good reporting on tech and privacy issues.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#199
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

Not quite the time scale you're looking for, but "Delayed Gratification" provides retrospective news and analysis from the previous quarter.

I'm in no way affiliated with the magazine other than I accidentally bought a copy once and enjoyed it.

https://www.slow-journalism.com

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#200
post #42

Earlier quoted context omitted.

Because the EU says you have it backwards? Ignoring European users is perfectly fine, but if you want to monetize them, you better play by their rules, unless you are more powerful than the EU. In theory. In practice do whatever you want.

> Ignoring European users is perfectly fine, See this: https://news.ycombinator.com/item?id=23353051

That comment speaks to the option of making access to the site conditional on agreeing to the cookies.

That’s not relevant to the parent’s alternative —- as I understood it —- of unconditionally blocking European users entirely.

Post reply on HN