The article ignores that the DNT header already had some regulatory backing, as in court decisions saying it ought to be respected. https://www.datev-magazin.de/nachrichten-steuern-recht/recht... references such a decision against LinkedIn. Instead of using that, this new proposal seems to be exactly the same thing, just with more work for website hosters (having to add nonsensical files to /well_known/) and claims t…
DNT failed because advertising and online stalking companies refused to abide by it when browsers enabled it by default. The GPC spec tries to work around this by having the spec disable the feature by default. This new spec is necessary because American legislation requires opt-out signals not to be the browser default. That means DNT, as browsers used it, is not legally an opt-out signal, because browsers default t…
Implications of Global Privacy Control
21–30 of 50 posts
Re: Implications of Global Privacy Control
#22So, there is no tracking opt-out like DNT had.
Do Not Sell is classic regulatory capture: It allows incumbent players to continue their current bad behavior, and directs revenue streams from smaller players (data brokers) to existing monopolies.
Also, this opt out won’t interfere with Mozilla’s recently acquired ad business, which uses user data to sell ad real estate (invading their privacy with obtrusive ads).
(Sorry for the awkward sentence, but they claim it is a privacy preserving technology that doesn’t gather or sell user data, and there’s no way to be doublespeak compliant without using tortured grammar.)
Re: Implications of Global Privacy Control
#23The main problem with DNT was the lack of legal and regulatory backing it received. Website owners could decide if they'd observe the DNT signal and there were no legal repercussions if they chose not to. This is where GPC is different.
....
What to do when receiving a GPC signal
It's up to the developer/business to decide how to treat the signal, for example, removing the user's details from third-party tracking or marketing, following a similar procedure as to when users opt out of sharing data for marketing purposes. If in CCPA jurisdiction, the signal must be observed to avoid legal repercussions.
So what's the difference? Without regulations, which is the real issue here, all this is meaningless just like DNT was. The system is solely based on trusting the site to comply. CCPA only applies in Europe. None of this would apply to users in the US but the article disingenuously implies it would:
At the time of writing, the Attorney General for California has recommended observation of GPC to comply with CCPA
That is not legally binding in any way. This is just DNT with extra step being sold as something it's not. I fail to see how this will benefit the user while making it harder for users to block trackers and advertisers. A site can't prevent you from blocking it's cookies because cookies are stored locally through the context of the browser. Site's can't prevent users from blocking, deleting or modifying cookies.
But GPC signals are sent via HTTP headers. Sites could prevent users from accessing the site by detecting if GPC is disabled by the user in the browser just by checking the HTTP headers, forcing users into sharing information with the site to be allowed to access the site.
Re: Implications of Global Privacy Control
#24> The main problem with DNT was the lack of legal and regulatory backing it received. Website owners could decide if they'd observe the DNT signal and there were no legal repercussions if they chose not to. This is where GPC is different. This sounds like an attempt to regulate the entire internet.
Re: Implications of Global Privacy Control
#25It seems to me like mozilla appeals to paranoid users who don't pay for software and also don't want to see ads, and in exchange insane demands and revolt is placed upon them.
One thing you learn when providing services is that the demands don't ever stop. The more you provide for free, the more demands you get.
Would not want to be in this space, let's normalize paying for software, then you wouldn't need to worry about alternative monetization schemes.
Re: Implications of Global Privacy Control
#26I'm an absolite outsider to this, I use edge and would use chrome if need be. It seems to me like mozilla appeals to paranoid users who don't pay for software and also don't want to see ads, and in exchange insane demands and revolt is placed upon them. One thing you learn when providing services is that the demands don't ever stop. The more you provide for free, the more demands you get. Would not want to be in this…
Re: Implications of Global Privacy Control
#27> The main problem with DNT was the lack of legal and regulatory backing it received. Website owners could decide if they'd observe the DNT signal and there were no legal repercussions if they chose not to. This is where GPC is different. This sounds like an attempt to regulate the entire internet.
It's just an extension of copyright, which already regulates the entire internet. You should have the copyright over your mouse clicks, plus 100 years after the death of the author.
Re: Implications of Global Privacy Control
#28The article ignores that the DNT header already had some regulatory backing, as in court decisions saying it ought to be respected. https://www.datev-magazin.de/nachrichten-steuern-recht/recht... references such a decision against LinkedIn. Instead of using that, this new proposal seems to be exactly the same thing, just with more work for website hosters (having to add nonsensical files to /well_known/) and claims t…
DNT failed because advertising and online stalking companies refused to abide by it when browsers enabled it by default. The GPC spec tries to work around this by having the spec disable the feature by default. This new spec is necessary because American legislation requires opt-out signals not to be the browser default. That means DNT, as browsers used it, is not legally an opt-out signal, because browsers default t…
Can you site the legislation stating that?
Re: Implications of Global Privacy Control
#29these web frameworks for privacy always give me a chuckle. DnT didnt work, why would this? Advertising is an economy worth more than 7.4 trillion USD. it has evaded most attempts to regulate or restrict it in any meaningful sense in the 21st century. the GDPR serving as a bureaucratic organ to which advertisers must subscribe, or quietly ignore with all but the most modest and encumbered window dressings for the illu…
If the CCPA does indeed interpret this as an opt-out signal, those 7.4 trillion are going to be at risk of a whole lot of (class action) lawsuits. The spec is trying to make itself applicable as an official, regulated signal. DNT couldn't, because Colorado (or more likely, a large donation by those 7.4 trillion dollars) decided that an opt-out cannot be the default. The stupidest thing is that Google actually got in…
A setting left at the default value does not indicate that a person has taken action to express a preference.
It's not a bad thing, or proof of bribery or regulatory capture or whatever, if some jurisdictions decide to formally recognize this reality.
> The stupidest thing is that Google actually got in trouble for trying to restrict third party cookies by default. The UK competition watchdog agreed with advertising companies that Google making such a decision would be abuse of power and bad for competition.
From what I recall, Google was trying to grant themselves a unique privileged position where Google and Google alone would be able to track individuals across sites.
Re: Implications of Global Privacy Control
#30Earlier quoted context omitted.
The point is you’d have one browser setting that would make all the obnoxious cookie consent pops disappear. Making laws is one thing, enforcing them is another, however.
I think cookie consent is a different story. GPC would mean: "Under the GDPR, the intent of the GPC signal is to convey a general request that data controllers limit the sale or sharing of the user's personal data to other data controllers". It doesn't preclude a website from storing cookies, and therefore doesn't relieve it from the obligation (at least in the EU) to show an obnoxious popup
While the law has flaws, it's very frustrating to see people misinterpreted it, instead of reaching the correct conclusion that the vast majority of websites are spyware. And that it's not EU's law to blame, but rather standard internet practices related to analytics and the serving of ads.