Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

21–30 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#21
post #5

Finally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok. I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.

> Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west.

Yes, the logic is frustrating: the big advertising companies have been trying malicious compliance for political reasons. It’s not like they couldn’t build better systems if they were trying to honor the intention of the law.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#22
post #3

This is amazing news. I implemented GDPR consent management for some US publishers with EU exposure. As part of this I evaluated vendors and various systems like the IAB framework. IMHO it was clear it was not compliant. It could never know the potential adtech it was going to load in advance (and therefore could not ask someone to consent), and it still allowed ads/adtech/trackers to load in page before asking for c…

But don't the adtech vendors have to declare what they do with the data? (Purposes and Special Features)?

IAB europe had a shared list of vendors and their purposes amongst the ad industry, and everyone's popups using the TCF framework just prompted with the same list because they _might_ be in the ads, not because they'd actually be on the page. Many of the vendors claimed every purpose, often as legitimate interest, regardless of what they actually planned to do and if they _did_ count as legitimate interest.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#23

Earlier quoted context omitted.

Well, that's their problem. They must delete the data or face legal consequences. That should act as a deterrent to future "too smart for their own good" ad people.

I agree! I'm just curious how would you do it? Look at when you deployed the popup to production and then delete all data from that timestamp forward? Engineering leaders now have ammo to push back against illegal roadmaps foisted on them.

I guess that if you cant deliminate the unlawful data from the rest, you'll just have to delete all of it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#24
post #12
post #5

Finally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok. I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.

Yep, overall I'm really happy with the GDPR. The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. That way we could finally end this farce of the ad-industry's attempts at weaseling their way around the word of the law (and the latest rulings) by designing dark patte…

In general, I agree that it would be nice. Not sure what the right way to legislate that would be, but I'm sure there are ways.

However, if DNT/GPC (which can signal opt out but not much else) becomes legally binding (as they very well might, with DSA), that'd be a huge win for me personally, because I don't see my self ever consenting, and reading consent dialogs isn't worth my time.

As I understand it, GPC is already legally binding in California thanks to CCPA.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#25
post #13
post #7

Quoted post unavailable.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

Business pepe works just say the minimum is name, email address, etc. is the minimum in that case... And if you don't provide it, the site won't work

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#26
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

> Which will probably be a nice deterrent against them pulling the same shit again.

Unfortunately, there are reasons they want these cookies on there so badly that justify the cost to figure out how to comply with the policy and try again.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#27
post #20

> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. How much data is being collected through these pop-ups?

All the data they were collecting before that GDPR said they had to stop collecting (without freely given consent).

How much data is that? How do we know? It's not clear to me how the ICCL will know that "all data collected" is deleted. Even if the IAB is sanctioned or you storm their datacenters, the ICCL said that the tracking industry collected data through the IAB. How is the ICCL going to ensure that the tracking industry deletes the collected data?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#28

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

If they can not prove that data was not gained by illegal means, the only way would be to delete all data.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#29
post #13
post #7

Quoted post unavailable.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

https://globalprivacycontrol.org/ goes kind of in that direction. It's a rebranded Do Not Track header, but referencing specific privacy rights under GDPR/CCPA. That hopefully makes it enforceable, whereas advertisers could just ignore Do Not Track.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#30
post #13
post #7

Quoted post unavailable.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

I want one for "If your business model is advertisement, get off my Internet".
Post reply on HN