Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

271–280 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#271
post #105

I can't find any English language news about it, but Yahoo Japan are going to withdraw a bunch of services from Europe in April including webmail and news. They're citing GDPR costs. Edit: Apparently it's been picked up since last time I looked: https://www.theverge.com/2022/2/1/22911965/yahoo-japan-europ...

What does Yahoo Japan have to do with Europe?

Not sure exactly what your question means but I'll attempt an answer: They currently offer services in the EEA and UK, such as webmail and news alerts (all in Japanese) and they will withdraw those services (presumably by geoblocking) in April.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#272
post #244
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

Of course you can’t prove that some data cannot be de-anonymized unless there are duplicate entries. However, GDPR explicitly encourages anonymization, or “pseudonymization”, which therefore suggests that reasonable attempts to keep data generic are considered legal by this particular law. People have already pointed out that GDPR’s language here is too vague and makes bad assumptions about how identifying multiple q…

GDPR encourages pseudonymization as a best practice, but also draws a sharp distinction between anonymous and pseudonymous data. Pseudonymous data is still personal data and subject to all other obligations under GDPR. Any data that's pseudonymous would still be subject to the deletion order.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#273
post #210
post #175

Earlier quoted context omitted.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

Can the site deny your access then?

No. They consider that "coercion". So there really is no point in even asking, as the only correct answer is to decline. Anyone who accepts can be presumed to have been tricked into falsely thinking they would get something in exchange for granting permission.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#274

Earlier quoted context omitted.

They will ask the companies to delete the data and take action if there is evidence they didn't, just like how all of GDPR is enforced.

How would they know if they did or didn't, though?

Yes, it's possible for companies to act in secret to deliberately not comply with the law.

There have been highly public cases of that blowing up spectacularly for those companies; cases where it becomes public and nothing really happens; and - I'm sure - many many more where nobody outside the company ever found out.

Is there some aspect of this situation in particular where you're trying to ask something more specific than that?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#275
These GDPR banners have made the internet a worse place for most users IMO, there needs to be an easy way to consent to all tracking and skip the banners across all sites. I'm fine with this being opt in, but it should be easy to do on a "normal" browser (like chrome or edge including mobile) without the need for an extension. Forcing everyone to deal with these things is bad.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#276

These GDPR banners have made the internet a worse place for most users IMO, there needs to be an easy way to consent to all tracking and skip the banners across all sites. I'm fine with this being opt in, but it should be easy to do on a "normal" browser (like chrome or edge including mobile) without the need for an extension. Forcing everyone to deal with these things is bad.

You could just, not track. That's always the option and it's what the final intention of these rules are.

Just browsing a website shouldn't be grounds to start tracking users.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#277
post #109

> The Belgian Data Protection Authority said IAB Europe “was aware of risks linked to non-compliance” and “was negligent”. It also found that IAB Europe had failed to honour its data protection obligations to maintain records of data processing (Article 30 GDPR), to conduct a data protection impact assessment (DPIA) (Article 35 GDPR), and to appoint a Data Protection Officer (Article 37 GDPR). Even if you were to giv…

Even with good salary, who in their right mind would possibly accept the DPO job at IAB? That's pretty much guaranteed legal trouble, because IAB will always try to point their finger at you. Unless you're fresh in the job market and still believe in the good of people, maybe.

Arguably, in a company where the primary purpose is legal there'd be teams of legal experts (lawyers, attorneys, etc) that would be the ones deciding features and wording, not the devs themselves (assuming you mean, "who" as in "what developers", since we are in HN)

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#278
post #210
post #175

Earlier quoted context omitted.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

Can the site deny your access then?

They cannot coerce you to sign away your fundamental rights in exchange for service. If they cannot offer service without violating your rights, then the service is illegal in Europe.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#279
post #195
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

Generally not in administrative law. Executive authorities (e.g. tax office) make some decision and you can appeal to administrative court, but you have to prove why the decision was bad.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#280

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

> We designers must [...]

This isn't something that's inflicted on us by web developers (on the whole); it's done by accountants. So fines are the most appropriate remedy.

No judge wants to impose a fine that bankrupts a company; but fines that start gently, but double after each offence, are much more likely to cause the accountants to smell the coffee.

Post reply on HN