Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

291–300 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#291

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

Businesses cooking the books and lying to auditors is a tradition as old as time.

Enforcement isn't the real crux of the issue, it's that for some reason it's uncouth to come out and say: this regulation is targeting known liars that we should expect to ratfuck the system as hard as possible.

If that was the commonly accepted understanding of those conmen, enforcement methodology would get solved quickly. Which is why they work so hard to not be seen as ratfuckers.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#292
post #175
post #61

Coming up next: Full page with mandatory reading (through eye scanning which will require camera access with popup consent for camera access). Followed by a 10 Quizzes to test your understanding for what you consented for. Then an email/ID verification to confirm your identity and consent. This is going to be fun.

But the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.

> then you can decline.

Not if the consent form looks like this:

[Register] [Accept]

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#293

Earlier quoted context omitted.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

GDPR enforcement is completely arbitrary (in both senses of the word). People might cheer for the downfall of the tech giants but it's really just a way for the EU to control US companies, extending their power beyond their jurisdiction.

Or just a way to keep peoples’ data inside EU and not allowing it to leak for-profit companies.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#294

I don't understand the findings. The TCF system doesn't collect personal information. The spec is at [0]. CMPs are the popups responsible for creating the TCF string. The IAB provides a spec for how these should operate, but does not supply one of its own. These can absolutely misbehave, and the IAB has previously notified the adtech industry about known misbehaving CMPs. [0] https://github.com/InteractiveAdvertising…

My understanding so far is that the TCF allows providers to accept 'legitimate interest' (instead of direct user consent) as a valid legal basis to store or process user data. This is commonly used for user tracking and advertisement / profiling, meaning you'll get tracked even if you clicked the 'Reject All' button.

My understanding is that Legitimate Interest is something defined by the GDPR lawmakers, not the IAB. If so, and now it appears that LI is not a valid legal basis, then every business operating in Europe needs to be concerned with this ruling, not just adtech.

For example, HN probably collects my IP address under LI. Now it may be illegal for it to do that.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#295

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

Nobody's going to check that all the collected data has been deleted. But if it turns out that someone has retained data about me (or any other individual) that they claimed to have deleted, then they're in violation of a clear court order, and are eligible to be clobbered with a fine.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#296

Earlier quoted context omitted.

> Collecting and selling digital data is not a legitimate business enterprise. According to who, you? > It’s spyware. How is it spying when the people are freely giving away their data? > If no one wants to pay for your product, the market has spoken. Too bad. Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data? > W…

>According to who, you? Spyware is illegal. So it’s just a matter of defining the data collection practices of internet companies as spyware. >How is it spying when the people are freely giving away their data? It’s not “freely given away” when you need a team of attorneys to understand what you’ve agreed to and you have no audit rights. Point me to the public FB page where they clearly and easily define all points o…

> Spyware is illegal. So it’s just a matter of defining the data collection practices of internet companies as spyware.

I’ve seen this phenomenon before but never so explicitly. When you can’t convince someone that something is bad, you re-define it as something they do consider bad.

Some examples I’ve seen:

- Some speech is so hateful and racist that its opponents wish to define it as “violence”.

- Facebook offers advertisers the ability to target the demographics their ads reach. Some have tried to term this as “selling your data”.

In this case, it’s clear the average person doesn’t hold data collection in such low esteem as yourself, so you must redefine it as “spyware” in order to convince them.

This subtle shift is in interesting to me, but it leaves me unconvinced. Words are not violence. Facebook does not sell data. Data collection is not the same as spyware.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#297
post #257
post #195

Earlier quoted context omitted.

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

It's not possible to discuss legality of something, until a judge said we are allowed to discuss it? What? So I can murder someone, and say "Innocent until proven guilty", and forbid anyone from discussing whether I'm a murderer, until I'm actually judged guilty? But ok, sounds like you're nitpicking on my words, so let me rephrase the comment you're replying to. "Considering that we have dozens of research papers sh…

That's not what I said. I said that it would presumably require a trial to prove that the ML models contain PII, as opposed to the government being able to assume they do and demanding the company prove they don't to some arbitrary standard.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#298

Earlier quoted context omitted.

Do we even need a law, or would another case by Max Schrems suffice? The intent of Do Not Track is quite clear.

DNT compliance is voluntary. I don't think Schrems would have a legal leg to stand on.

DNT compliance is only voluntary in that it can be ignored when there is no law requiring consent to track.

If someone says "Do not track me", it's a bit disingenuous to interrupt them with a dialog asking them all the ways they might want to be tracked. It's either an attempt at coercion (we'll keep wasting your time until you give in) or an attempt to gain fraudulent consent through trickery/mistakes.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#299
post #195

Earlier quoted context omitted.

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

Generally not in administrative law. Executive authorities (e.g. tax office) make some decision and you can appeal to administrative court, but you have to prove why the decision was bad.

OK, that's interesting. Thank you.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#300
post #2

Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

The issue here is larger than using the right language. I'm browsing through the full ruling [0], but C.1. Breaches, pages 115-117 is a good summary.

- "First, the consent of the data subjects is currently not given in a sufficiently specific, informed and granular manner"

- "Second, the legitimate interest of the organisations participating in the TCF is outweighed by the interests of the data subjects, in view of the large-scale processing of the users’ preferences (collected under the TCF) in the context of the OpenRTB protocol and the impact this can have on them."

- "In the absence of systematic and automated monitoring systems of the participating CMPs and adtech vendors by the defendant, the integrity of the TC String is not sufficiently ensured, since it is possible for the CMPs to falsify the signal in order to generate an euconsent-v2 cookie and thus reproduce a "false consent" of the users for all purposes and for all types of partners. As indicated above248, this hypothesis is also specifically foreseen in the terms and conditions of the TCF" - no way to verify consent

- "The Litigation Chamber also finds that the current version of the TCF does not facilitate the exercise of the data subject rights, especially taking into consideration the joint- controllership relation between the publisher, the implemented CMP and the defendant. " - no way to revoke consent, or request your data

As to why the system ran for so long: yes, enforcement is (too) slow.

- Many complaints were made to several European DPAs in 2019.

- Litigation commenced 13 October 2020

- Interim Decision 8 January 2021, amended 23 February 2021

It looks like IAB made a lot of procedural complaints when it became clear their arguments were rejected

[0] https://www.gegevensbeschermingsautoriteit.be/publications/b...

Post reply on HN