Live data from Hacker News

Google’s GDPR Workaround

brave.com

31–40 of 629 posts

Re: Google’s GDPR Workaround

#31
post #9
post #2

EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

The fine is already kinda big for GDPR (4% global rev for big companies) but Google has gotten away with way worse on way more regulated fronts i.e. their antitrust case which slapped them on the wrist.

If GDPR wants to be effective they need a ridiculous company-breaking fine for big abusers like COPPA and the like. Something like a per-user fine for violations that means they either can't do business in the EU or they have to become compliant otherwise risk being basically destroyed (for reference, violating child protection laws in the US can break and have broken companies before).

EDIT: also as for the tracking growth comment -- I agree on this, but the effects of GDPR on growth tools reach far beyond this. Even basic metrics are hard to get without a bunch of hoops. Even if you store no data you have to have a bunch of checkboxes and banners everywhere. Just for using Google Analytics that just relies on what they know about your computer (fingerprinting), and uses no PII at all, you need a banner and privacy policy. The laws are making it hard to use even basic analytics without fearing a misstep.

Re: Google’s GDPR Workaround

#33
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

That fine qualifies as a "slap in the hand" for Google if it happens infrequently enough (which is the case).

Re: Google’s GDPR Workaround

#34
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

[deleted]

Re: Google’s GDPR Workaround

#35

Earlier quoted context omitted.

Unless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative: > The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements. From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties

In context, "relatively bigger" would mean something like a progressive tax bracket. $20MM up to $500MM rev, 4% up to $1BB rev, 5% up to $2BB rev, 6% up to $5BB rev, etc... A straight 4% would be absolutely bigger, but relatively the same (once beyond $500M).

I think it's not about "income brackets", it is about profit margins which can vary a lot between industries. 4% of revenue is enough to bankrupt traditional business, like Wallmart with profit margins of 2,48%. Google is a low-cost business, with profit margin of 25%, so even the maximum GDPR fine is something they can just write off.

Re: Google’s GDPR Workaround

#37
post #17
post #8

It's really funny to see that yesterday, I was branded as a 'privacy nut' after the release of Android 10 as I was concerned about the privacy issues that are in Android. Then the Go modules proxy issue around the Go Programming language that raised suspicions about tracking usage statistics around downloading modules turned on by default without any consent and now this. I think there are some folks at Google who ha…

The Go module hash checking seems to be more about avoiding the problems encountered by other language repos integrity and versioning issues ( cough NPM), and in terms of tracking it seems about as invasive as Debian's popcon. Enabled by default can and should be the default for security-related features. I tend to agree about the rest of the creepiness, especially anything personally behavioral.

Debian's popcon is not enabled by default.

Re: Google’s GDPR Workaround

#38
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Sure you didn't mean to say that what's actually sad is that the US federal government/DoJ doesn't take real action?

Well, I am an European, it's sad about the US Gov./DoJ, but that is not something I have the right to demand from my part.

Re: Google’s GDPR Workaround

#39
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

> Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be. GDPR penalties are a flat fee or a percentage of revenue, whichever is higher . If Google is truly willfully violating the GDPR, the maximum penalty…

If their whole business model is selling personal data, then 4% is clearly just a cost of running their business.

Re: Google’s GDPR Workaround

#40
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

I was curious what the maximum fine for Google could be under GDPR.

Google's 2018 revenue was $136.22 billion. GDPR allows for a maximum fine of 4% of global turnover.

At a maximum 4%, GDPR could impose up to a $5.5 billion fine. I agree, getting something closer to the maximum might help the situation. Although ultimately, my bet is that Google is already baking the 4% revenue risk into their business model. If that's the case, GDPR's maximum penalty should be reconsidered.

Post reply on HN