Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

221–230 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#221
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

How are they screwing users? By showing them relevant ads?

I think the elephant in the room are political ads, and in some regions personal civil rights.

So the screwing is not done by the advertisers but by the kind of ads and the third party access to data.

Also companies like Google seem to have a very clear stance wrt to both, while companies like FB in the past have been pivotal in political landslides, screwed-over level personalized political influencing...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#222
post #181

Earlier quoted context omitted.

The industry should really get together and set up something like P3PP but good. These settings should be set in the browser, not in the client. Of course the ad and web stalking people don't want that, because that means users can easily opt out. With Google's misguided attempt to force FLOC down everyone's throats we may see them join forces with Apple, Microsoft and Mozilla at some point to develop a consent proto…

How would the browser be able to enforce what the Actual server does with the data? This would work only for those binary track everything/don't track anything scenarios. Those are rare cases. What the the majority of us want and the whole purpose of the GDPR is, is the "informed consent" part. A detailed list of what information is gathered and how it is going to be used. A browser can not really enforce "I give you…

It wouldn't be able to control anything on the backend, but neither can it control the tracker behabvour in the cookie popups. That's where the border between technical and legal issues is crossed.

My idea for consent would be a sort of challenge/response protocol, where the sending party sends a request for consent with all the details they need and the browser approves or denies it. Preferably, this would be done automatically based on the user's settings. It could even be part of the CORS system, leveraging the browser's "firewall" to ensure no data gets leaked to misconfigured trackers and forcing companies to comply.

The thing about consent is that it must be freely given. Therefore, it should always be opt-in. The user can opt into certain stuff from some kind of simple control after reviewing the requests the other party sends, but that stuff should be hidden and denied by default.

A general declarative method would probably lack some finesse. For example, when your user account has a certain country set, a server might load in payment providers on the fly, and the manifest should reflect that. The manifests we have today would get cached way too quickly, I think.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#223
post #142

Earlier quoted context omitted.

People don't care about a lot of things. Mainly because they don't understand them, or don't know about them: climate change, cancerous substances, plastic waste, homeless people, illegal whaling, domestic cats killing singing birds, sewing winter clothing or properly managing their savings. That is why we have subject matter experts providing guidance for people in a world too complex to grasp or even care about eve…

> Advertising companies are ruining the internet for everyone, some people are just too unaware to realise it. Sounds like projection. Though I'd agree that most internet users don't like ads, what's true is that most internet users don't like paying for things. Using YouTube as an example, the most popular site on the internet, the vast majority of people do not pay for YouTube premium even though it's available. At…

If a site offers the choice between either funding via "good" (Non tracking, no malware etc) ads, and a fee, then I'm completely happy with their business model. A lot of sites however, don't do this.

Of course, the reality is that if they _did_ use "good" ads, then the free version wouldn't make enough money (at least not in today's ad market). So either the free version couldn't exist, OR it would need to be subsidized by the paid version being even more expensive.

But this problem could go away if "bad" ads weren't allowed or possible. Because then the price sites get per impression on those ads could go up, as advertisers can't simply pay more for precisely targeted ads.

Now, there are a few risks with this: 1) There is every risk that money on the regular web dries up, as targeting is more effective in apps and other siloed environments. We have already seen this to some extent 2) If online advertising is less efficient because of worse targeting, then traditional advertising will again be relatively more attractive, so some of the money would leave the internet economy that way, returning to traditional advertising.

1 and 2 taken together might mean that a lot of "free" content (and I use scare quotes) will simply disappear. And I think that's a risk we should be willing to take. And not only that: I'd go so far as saying that even if 90% of internet users answered in a survey that "I don't care about tracking ads, I just want free content", that's not something regulators should care about at all.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#224

Earlier quoted context omitted.

The same way ads work in every other industry. Have you ever been to Times Square?

You mean the same ad industry that was easily supplanted by internet ads? So you want a regression, why exactly? If you don’t want to be tracked stop using sites that track you and install ad block.

Is it a regression? I'd argue an ad in Times Square (or a reputable print newspaper) is a major upgrade from the cesspool that is internet advertising. Seeing an ad there signals to me that the brand has enough money to clear the huge barrier to entry (thus is unlikely to be a fly-by-night scam) and doesn't mind being seen by everyone. This gives me more confidence as a consumer to purchase their product.

> If you don’t want to be tracked stop using sites that track you

Can you even tell that before being tracked? The GDPR attempts to make tracking opt-in so that you have a way to consider the downsides before agreeing. There's technically no problem with targeted ads and data collection as long as users are given a clear description of what data they're sharing and how it will be processed.

> install ad block

The same people behind all this illicit data collection would rather not have you do that.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#225
post #63
post #4

It was obvious to anyone technical they didn't work as they presented themselves to work, but it takes time for the courts to deal with such things. They are also totally annoying and I suspect there primary purpose was to annoy users and not actually comply with the GDPR. It was a way for these companies to fight the GDPR with a war of attrition. I'm glad you see with this round hasn't worked... Yet. I suspect that…

> Instead I predict another round of pseudo compliance and a more annoying user experience. Eventually they'll start a policy campaign in earnest stating that the GDPR is unworkable. I predict all of this to fail, at considerable expense for the IAB and its clients. The GDPR is popular amongst us EU residents.

I hope it does fail. Although I'm not in the EU I like the ideas the GDPR puts forward.

My fear is that is legislation works in EU anything like it does in the US is that things that the people like but the corporations do not like... Well, corporate interests win out. I suspect that the whole reason the GDPR was allowed to pass was the corporations figured they could ignore it. Now finding out they can't they will fight in earnest.

I do hope I just being old and cynical and I'm ultimately wrong.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#226
post #138
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

I think you meant to use the word lose not loose. I suspect you mean lose the data as in delete it, not loose as in releasing the data to others.

There is a popular anti-drunk-driving campaign in the US with the slogan "Booze it and Lose It!" ("it" being your license)

My town messed up on one of the billboards, though, and for a while commuters got to see "Booze it and Loose It!", which conveys a somewhat more carefree message.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#227

Earlier quoted context omitted.

Countless articles and media pieces over the years on the plethora of unethical ways our data gets sold, resold and abused and still you ask what's wrong...

Yet No alternative have arrived to ads, people are used to free software how do you circumvent these things ?

Who said this ruling forbids ads? It only forbids user tracking (actually not even that - it just requires meaningful consent to be obtained before tracking users).

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#228
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

> All data collected through the TCF

there is no data collected via TCF:

https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...

CMPs are the popups that save the preferences and thus enable the collection of the data.

IAB only provides a spec.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#229

Earlier quoted context omitted.

Suppose there are two products on the market. One, a children’s toy that sells for $9.99. The other a very similar children’s toy that uses lead paint, instead of a safer paint, but is otherwise very similar. It is not clearly labeled as having lead paint. The lead paint toy sells for $4.99. If people buy the cheaper toy, does that mean people are “choosing” lead paint over the more expensive toy? No! It means people…

You're comparing seeing ads with children consuming lead paint? Lead paint has very obvious, bodily harm to children. Do ads harm children? Perhaps, but even if they did, there's no cost to visit a free-site without ads, or pay for a site without ads.

> You're comparing seeing ads with children consuming lead paint?

No, I’m not. You can tell, because I never made a comparison between the two.

What I did was make a hypothetical that was more extreme, with an analogy of the underlying reasoning, to make my objections to that reasoning more apparent.

But, that’s absolutely not a comparison, so no.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#230

Earlier quoted context omitted.

It seems like that's what's happening here though. The IAB appears to take all the blame while everyone else gets away.

They lose all the data though. They may have avoided some name smearing but it's the data that they really want.

I'd argue that the data has already been integrated into ML models or mixed in such a way that there's no way to even tell where the data originated from. While the logical conclusion would be to just delete any data they can't prove a legitimate origin for, I very much doubt this is going to happen.

Most importantly, tens of billions have already been made using this ill-gotten data.

Post reply on HN