Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

201–210 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#201

Earlier quoted context omitted.

How do you propose you track ad spend without "spyware"? Or should the people spending money on ads just "trust" that their ads are actually being displayed to the types of people they want to show them to?

The same way ads work in every other industry. Have you ever been to Times Square?

You mean the same ad industry that was easily supplanted by internet ads?

So you want a regression, why exactly? If you don’t want to be tracked stop using sites that track you and install ad block.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#202

Earlier quoted context omitted.

Transparency. People are overwhelmingly unaware of the volume and types of data that is collected on them. And at this point the free market can’t resolve this. The spyware model has absolutely ruined the internet economy. There is no way to compete against a spyware company with a paid product.

If people are choosing "spyware" over a "paid" product, perhaps they just don't care about data collection that much. Isn't that the logical conclusion? Objectively ads have added more money into the internet economy than ever before. Curious where you're getting your numbers. 20 years ago "YouTuber" wasn't even a profession. The idea some rando with a microphone and a camera could make millions was unheard of. It's…

> If people are choosing "spyware" over a "paid" product, perhaps they just don't care about data collection that much. Isn't that the logical conclusion?

I think the idea that people would be able to even make this decision themselves is too optimistic.

> Objectively ads have added more money into the internet economy than ever before

Is that good though? Is there some actual value being created by this or is it simply that ad money has been flowing out of other places like print and TV, and into online advertising?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#203
post #191
post #186

Earlier quoted context omitted.

My understanding is that as long as there is no PII is in the ML model (there’s not) then any existing models do not need to be deleted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

I suppose the models might theoretically at risk if the learning data can be extracted, but I don’t think this will practically happen because it’s so far different from current GDPR practices. Someone would have to prove their protected information is inside of a model before they might have a chance. After that, I am not a lawyer.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#204

Earlier quoted context omitted.

IAB Europe is the entity being fined, not their participating partners. The linked PDF says their fine is 250k euros, which is "proportionate to the infringment" and less than the maximum.

Seems like the IAB is essentially volunteering to be the scapegoat to shield everyone else. 250k is peanuts compared to how much the industry has made breaching the GDPR over the last 4 years.

IAB's business model is broken at this point. The EU's point is that you can't rules-lawyer your way around GDPR violations by outsourcing the lawbreaking to a paid scapegoat company: having ruled the practices to be essentially illegal, this is going to end up being kicked up a level to the big advertising corporations themselves (by which I mean: Google, Amazon, Microsoft).

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#205
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

It's also extremely important that companies can't insulate themselves from consequences by outsourcing compliance functions to a "designated villain".

It seems like that's what's happening here though. The IAB appears to take all the blame while everyone else gets away.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#206
post #195
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

They have just been found guilty, that's what the ruling is, and the outcome of the ruling is they should delete data derived from the related data. The ML models took the data as input, I think it's fair to say that if they want to argue the ML models do not derive from it despite that, they should maintain the burden of proof.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#207

Some crazy figures here: The maximum fine for such a breach is 4% of the company's global revenue. Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96. Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of da…

> making them liable for a fine of up to $32.3Bn per year

> their fine is 250k euros

massive disconnect between reality and imaginary worlds.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#208

Earlier quoted context omitted.

How are they screwing users? By showing them relevant ads?

Countless articles and media pieces over the years on the plethora of unethical ways our data gets sold, resold and abused and still you ask what's wrong...

Yet No alternative have arrived to ads, people are used to free software how do you circumvent these things ?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#209

Earlier quoted context omitted.

> Advertising companies are ruining the internet for everyone, some people are just too unaware to realise it. Sounds like projection. Though I'd agree that most internet users don't like ads, what's true is that most internet users don't like paying for things. Using YouTube as an example, the most popular site on the internet, the vast majority of people do not pay for YouTube premium even though it's available. At…

>Though I'd agree that most internet users don't like ads, what's true is that most internet users don't like paying for things. Using YouTube as an example, the most popular site on the internet, the vast majority of people do not pay for YouTube premium even though it's available. This is a bit circular. People would rather use a free service than a paid service. So long as free services exist it will be hard or im…

> This is a bit circular. People would rather use a free service than a paid service. So long as free services exist it will be hard or impossible for paid services to exist or thrive.

Of course. If a paid product wants to thrive it needs to be better. People do use paid search engines, email, maps, etc. most people don’t because most people don’t value it that much.

> There's no reason that we should have to make this choice. We don't have to live in a spyware dystopia so that we can have cheaper internet services. This spyware economy is less than 20 years old, and we should throw it out.

I don’t think there’s a dystopia. If you want to regress you can do so alone. We have irc and bbs that won’t track you. I’m sure there are also some plain text sites you can peruse.

Not really understanding why you want to change things for others. Just change it for yourself and then you’re good.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#210
post #175
post #61

Coming up next: Full page with mandatory reading (through eye scanning which will require camera access with popup consent for camera access). Followed by a 10 Quizzes to test your understanding for what you consented for. Then an email/ID verification to confirm your identity and consent. This is going to be fun.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

Can the site deny your access then?
Post reply on HN