Earlier quoted context omitted.
Reminds me when the EU "Fixed" Cookies and now we have these stupid click-through warnings everywhere that have pretty much ruined the user experience. Root cause: people passing laws they have idea what about.
Nothing about the EU law requires sites to put up cookie warnings and degrade the ux. They choose to do that.
Two years in, GDPR defined by mixed signals, unbalanced enforcement
201–210 of 216 posts
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#202Earlier quoted context omitted.
> users don't care and are happy to click past a banner / trade their privacy for free things. Are we discounting the possibility that users make a rational choice that we happen not to like?
Tough question. For some things, I'd say that informed consent is hard to give - if you consent, you're not informed. I don't believe that the average user is making informed choices. The choices may be rational as long as the users don't understand the consequences. It's perfectly rational to trade in your life savings for a fancy meal if you don't understand what "life savings" means.
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#203Earlier quoted context omitted.
But they all choose to do that, so that's the actual outcome of the legislation. I don't understand why I keep seeing this argument. We all have to deal with cookie dickbars regardless of whether or not your armchair lawyer argument is technically correct. If this is what the law does in practice, and the behavior is generally seen as compliant, then it's a dumb law.
Plenty don't. Hyperbole isn't helpful. Lots of websites seemingly actually break the law, with full page "can't see the page unless you click accept" etc. The problem seems to be under-enforcement, and then we're right back at the point of TFA.
The problem starts when legislators write vague or ill-posed laws because they don't understand the underlying technical issues. If your understanding of the problem is that "cookies are some sort of tracking token and tracking is bad," you will not be able to write effective legislation. You need to have a basic understanding of HTTP, you need to know how cookies fit into HTTP, and you need to be aware of some basic cookie usage patterns. You need to be able to identify that some things that certain companies build using cookies are problematic, and other things are totally benign and are required for basic functionality. You need to be capable of understanding that a user's "allow/deny cookies" preference usually can't even be saved without a cookie.
When the law actually comes out, it's so vague and seemingly self-contradictory that lawyers at these companies are going to say "We have no clue WTF they meant here, or how they intend to enforce this law, or if they even intend to enforce it at all, but just to be safe, let's just do it this way that's obviously stupid, but appears to be what everyone else thinks will pass the sniff test."
Then the law isn't actually enforced, because the enforcers don't understand the law either, so the lawyers are like, "Well, no guidance based on patterns of enforcement, in fact, they don't seem to be enforcing this thing at all, so let's just do whatever we want," which is how you get your laundry list of obviously non-compliant websites.
Legislation needs to be clear, enforcement needs to actually happen, and needs to happen consistently in order to reinforce the clarity of the original law. If you don't have these things, your legislation is going to fail. Cookie law used in this example, but the same thing applies to GDPR. So far, very little enforcement, and enforcement has been extremely inconsistent. It's a really bad start.
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#204I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#205I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.
Prior to GDPR, 9 replies in 10 would be polite but dismissive responses, basically telling me that I'm making an unreasonably burdensome request.
Post GDPR, everyone responds with a message stating they have followed my request in a timely fashion.
Am I disappointing that GDPR has not fined Facebook into oblivion? Yeah. I was hoping for global scale schadenfreude as much as the next person.
However, GDPR has fundamentally normalized the notion that peoples relationships with companies need not be permanent, and that submitting to eternal spam is not the accepted price of buying a flight online. GDPR has established in law that it's totally reasonable for people to not want to give their local gym an iris scan in order to enter the gym and work out, and it is indeed the gym owner who's the arsehole in that situation. This grants leverage against the arsehole.
In that respect, it's been a smashing success. There is much we could improve on, but on the statement "it only benefited the lawyers"...hard disagree.
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#206Earlier quoted context omitted.
Plenty don't. Hyperbole isn't helpful. Lots of websites seemingly actually break the law, with full page "can't see the page unless you click accept" etc. The problem seems to be under-enforcement, and then we're right back at the point of TFA.
I agree that (under) enforcement is part of the equation, but I don't think it's the primary issue. The problem starts when legislators write vague or ill-posed laws because they don't understand the underlying technical issues. If your understanding of the problem is that "cookies are some sort of tracking token and tracking is bad," you will not be able to write effective legislation. You need to have a basic under…
But they did all that. Functional cookies (shopping carts, preferences, etc.) all need no consent. This is not some kind of complicated thing. It only gets complicated if you want to try to trick users into allowing other cookies and/or hope that whenever those things get enforced, they’ll start with bigger fishes than you.
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#207Earlier quoted context omitted.
They could call out the news sites/papers of the opposite side though.
That is something I considered. Many partisan sites love to point out the errors of the other side. I know Fox News loves to call out CNN all the time. However, if every site did it, I fear that would just lead to more confirmation bias. And why report that the other side was right? That hurts your viewpoint. What we need is a non-partisan non-profit to do it. But then there’s the problem of funding (which results in…
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#208Earlier quoted context omitted.
DuckDuckGo does ads without tracking In fact, every advertisement outside of the web works without tracking/stalking the consumer. At most, you get a discount code for "seeing this ad on X place" > Why can't I say: "accept that my site is ad-supported or don't use my site?" Because that's the equivalent of me giving you my address, dob, SSN, etc just for entering your store
> Because that's the equivalent of me giving you my address, dob, SSN, etc just for entering your store So what? If you don't want to give me those things (ad tracking isn't nearly that bad, btw), then don't enter my store. And likewise, if a consenting adult doesn't mind giving out that info in exchange for entering my store, why prevent them from doing so? Don't agree to my terms, don't enter my shop. It's as simpl…
Sounds like you're the type of business the law was created for
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#209Earlier quoted context omitted.
We didn't lose that much because I suspect big business in Europe is largely ignoring the more difficult parts of the GDPR. I work for a large bank that is totally non-compliant with GDPR and does not really even have a strategy for getting there. My impression is that we (the bank) looked at the draconian requirements of the bill, realized that, with the total mess that the IT of the bank is in, implementing GDPR wo…
Which parts are so difficult? Trying to find all the data about a user in the system? I have some sympathy for an giant mash of databases like that. I have no sympathy if someone claims that adding a tracking toggle to a single web site is too hard.
1. Deletion/rectification of all copies (that includes backups!) of personal data on demand. We currently are not sure where (in which systems) we store all that data, not to mention adding features to delete/update all data on request in each of those systems.
2. The requirement to complete description of all processes within the bank which touch personal data. That involves creating a fuckton of documentation, a lot of it for systems where required knowledge is missing (i.e. no one is quite sure how they actually work).
Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement
#210Earlier quoted context omitted.
A business model that fails because you explicitly make them illegal isn't exactly a failed business model. The lawmakers made them fail and they either knew it was going to happen or were incompetent.
> A business model that fails because you explicitly make them illegal isn't exactly a failed business model. It literally is, by definition. Any business success has to happen within the legal context it exists in. > The lawmakers made them fail and they either knew it was going to happen or were incompetent. I could reword this as "the elected representatives of the people decided that certain business models were…
Yes, and they had business success until the rules were changed from under them.
>I could reword this as "the elected representatives of the people decided that certain business models were undesirable and anti-consumer, so legislated against them".
And I could reword this as "lobbying groups have bought our politicians and use them to enact laws to put our competitors out of business".
I'd say my rewording is closer to reality, because of course the two biggest ad networks increased in size while the smaller ones decreased as a result of this regulation.