Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

281–290 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#281
post #2

Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

> Does this mean it will be a long term of conditions like apple does every time we use a website?

I guess it is the opposite. GDRP requires clear and understandable text in privacy policies.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#282

Earlier quoted context omitted.

> paid search engines, [...], maps Can you find me one? The only one I know about is Kagi which is in beta and invite-only. The problem with the current status-quo is that as long as advertising powered by illicit data collection is possible in practice, it's not viable for a paid service to compete. > Just change it for yourself and then you’re good. It doesn't matter what you do if ad-tech scum will track you anywa…

Try out Neeva in addition to Kagi. If you pay and get your friends to, it’ll compete. > It doesn't matter what you do if ad-tech scum will track you anyway Stay away from sites that use trackers and you won’t be tracked. I recommend turning off JavaScript and sticking to plain text sites.

> Stay away from sites that use trackers and you won’t be tracked.

That's not enough. If your friends give Instagram and the likes access to their contacts to "find friends", then they unintentionally leak your social circle too, and data warehouses sell this info to the highest bidder, lowest bidder, and everyone inbetween, and government agencies also tap into this for mass surveillance. Even the goddamn Mastercard sells transaction histories to Google. Everything's scraped and sold, doesn't matter if you use the internet at all.

Any notion of user consent to this is ridiculous, because barely anyone understands how much is truly collected, shared and linked together from various sources, and then used and abused. That's why Google, Facebook et al fight so furiously against legislation like the GDPR that mandates informed (!) consent.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#283
post #54
post #41

Earlier quoted context omitted.

Also, in loading ads from these vendors, many often included external JS to whatever flavor-of-the-month adtech vendors or trackers they were using. These were often not even listed in the framework. There was little-to-no compliance/auditing that I am aware. It was business as usual for many ad networks.

A former employer in the adtech space did audit that the ads were only including vendors from the list, but I don't know how many of our competitors did the same.

Am glad to hear some folks were doing that properly.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#284
Here is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#285
post #262
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

I don't think it's much of a deterrent, because there's no clawback of the ill gotten gains from the use of that data. That's something done routinely in, say, fraud cases.

Precisely. Until all the profits + substantial deterrent fines occur, nothing will change. This will have been worth it to the violators.

In effect this just encourages them to keep this practise going. This has to be treated like fraud.

Why isn’t anyone going to prison for this? Happens regularly with fraud.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#286

Earlier quoted context omitted.

I'd argue that the data has already been integrated into ML models or mixed in such a way that there's no way to even tell where the data originated from. While the logical conclusion would be to just delete any data they can't prove a legitimate origin for, I very much doubt this is going to happen. Most importantly, tens of billions have already been made using this ill-gotten data.

Or just force all models to be deleted that had any input of that data in the first place. If they don't do that in practice let the whistleblowers do their job in exposing the companies.

Good luck identifying these models. By now what caused what is so muddled, it could get a small army of lawyers to even start detangling

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#287

To be frank, the practical result of GDPR is that it made my browsing experience worse. Nearly every website opens with an annoying cookie popup, often blocking the content (or reducing it to a fraction of my screen on mobile). I've never once clicked "Yes, track everything", except by accident when tricked into it by deceptive UI (eg. a button designed to look more inviting than its less invasive counterpart). I get…

> the practical result of GDPR is that it made my browsing experience worse

Actually it's the website operators that did that. The GDPR doesn't mandate all these cookie popups.

GDPR declared war on trackers. The popups is the trackers fighting back. We are civilians caught in a warzone. I for one hope that GDPR wins; but there's a way to go yet.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#288

Earlier quoted context omitted.

There should be some separate law that would oblige companies to accept "do-not-track" HTTP header. Then we could just set it in our browser settings.

Do we even need a law, or would another case by Max Schrems suffice? The intent of Do Not Track is quite clear.

DNT compliance is voluntary. I don't think Schrems would have a legal leg to stand on.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#289
post #7

Quoted post unavailable.

I wish there was one I could set that just said "Fine, send me your cookies just don't expect them back".

Cookies are already pretty much irrelevant. IP address, user agents and browser fingerprinting is where it's at.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#290
post #2

Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

GDPR enforcement is completely arbitrary (in both senses of the word). People might cheer for the downfall of the tech giants but it's really just a way for the EU to control US companies, extending their power beyond their jurisdiction.
Post reply on HN