Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

241–250 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#241
post #210
post #175

Earlier quoted context omitted.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

Can the site deny your access then?

Not legally. Personal data isn’t transactional.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#242
post #235

Earlier quoted context omitted.

> Most of this content is only there to solicit an ad impression, not enough people would pay money for it. Exactly. There’s no issue. > There's a reason you don't see a Patreon or other way of paying for the vast majority of clickbait content. The vast majority of content, clickbait or not doesn’t have a patreon to begin with. Most patreon have social media presence which includes ads. Sounds like the worst of both…

> > Most of this content is only there to solicit an ad impression, not enough people would pay money for it. > Exactly. There’s no issue. Except all the work and energy wasted on creating trash content only intended for ad impressions? The world would be better off without it.

Nope. Trash content is just your opinion.

Just because you don’t like it doesn’t mean it shouldn’t exist.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#243
post #212
post #83

Earlier quoted context omitted.

> how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. They will be pleasant but fi…

> If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. zero chance of this ever happening.

What happens when, say, a restaurant does not allow inspectors to look at their operations? They get shut down or fined. Same thing.

And, no, it's not different because the tech companies are serving up bits and bytes. Same mechanism.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#244
post #191
post #186

Earlier quoted context omitted.

My understanding is that as long as there is no PII is in the ML model (there’s not) then any existing models do not need to be deleted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

Of course you can’t prove that some data cannot be de-anonymized unless there are duplicate entries. However, GDPR explicitly encourages anonymization, or “pseudonymization”, which therefore suggests that reasonable attempts to keep data generic are considered legal by this particular law. People have already pointed out that GDPR’s language here is too vague and makes bad assumptions about how identifying multiple quasi-identifiers can be.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#245
Good. Now pick a random one of the companies that used this particular product/service and make an example of them.

The problem I think until now has basically been that sites that rely on tracking ads know they are in violation. They don't want to comply, because it would be too costly.

Basically, a meeting at one of these businesses (I'm imagining) has a conversation where people say "Ok what do we do about the cookies? Unless we at least write the X and Y and Z tracking cookies, we can't keep the lights on so we cant't risk users just clicking 'Reject all' and getting dumb ads. What should we do? I think we should use that dark pattern dialog which leaves X Y and Z on for 75% of visitors who just click the biggest button. That at least buys us some time. If regulators complain we can always change it".

A regulation that was scary enough would see sites prefer shutting down over using a dark pattern. For that to happen, the fines not only need to be big enough to be fatal to the business, they have to actually go further and be personal fines to key employees.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#246
post #83

Earlier quoted context omitted.

> how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. They will be pleasant but fi…

How well-versed are they in file systems, database schemas? Will they look at source code? Will they understand it? How will they determine what data came from where?

Ah, I see that you expect a US / Southern European style revolving-door wink-and-a-nudge quid pro quo! Yep. Nope.

These people will be frighteningly competent

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#247
post #235

Earlier quoted context omitted.

> > Most of this content is only there to solicit an ad impression, not enough people would pay money for it. > Exactly. There’s no issue. Except all the work and energy wasted on creating trash content only intended for ad impressions? The world would be better off without it.

Nope. Trash content is just your opinion. Just because you don’t like it doesn’t mean it shouldn’t exist.

The fact that nobody wants to pay their hard-earned dollars for it suggests it's more than just his opinion.

In fact, let's imagine a system where one side provides ads that you can watch to accumulate a monetary balance and the other provides content (including the aforementioned trash).

Do you think people will still watch and choose to pay for said trash content? Or will they choose to spend that money on better content, or even cash it out and buy a meal or drink?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#248

Earlier quoted context omitted.

That's only your opinion. There are billions who disagree. At the end of the day no one is forcing you to use YouTube.

There should be enough people in those billions to sustain a paid alternative.

There are paid alternatives.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#249

Earlier quoted context omitted.

You mean the same ad industry that was easily supplanted by internet ads? So you want a regression, why exactly? If you don’t want to be tracked stop using sites that track you and install ad block.

Is it a regression? I'd argue an ad in Times Square (or a reputable print newspaper) is a major upgrade from the cesspool that is internet advertising. Seeing an ad there signals to me that the brand has enough money to clear the huge barrier to entry (thus is unlikely to be a fly-by-night scam) and doesn't mind being seen by everyone. This gives me more confidence as a consumer to purchase their product. > If you do…

If it’s an upgrade then you should do it and stop trying to force things for others.

I’m really not even sure what your point is. You just want others to do what you want?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#250
post #210
post #175

Earlier quoted context omitted.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

Can the site deny your access then?

afaik no, but you might lose some features
Post reply on HN