Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

31–40 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#31
post #7

Quoted post unavailable.

> I wish there was an HTTP header that meant "I don't give a shit about what you do with my data, just let me get the information I want from this website".

I'm OK with that as long as there is an equivalent HTTP header which means "NO! Do not track anything, do not profile, do not collect any information besides the bare minimum PROVEN to be essential for the site to function at all. Either something's truly essential or it isn't, there is NO Legitimate Interest category".

Unlike the failed Do Not Track header, this one should actually have legal teeth (well, at least in EU) and sites which refuse any service to visitors carrying this header should be fined (after a grace period to implement any needed changes). And why not, add provisions to pierce the corporate veil so they can't set up a hollow company to take the fall for noncompliance.

Remember, you can still show ads and profit from them, you can't just violate my privacy and vacuum all my data to Feed The Beast.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#34
post #11
post #2

Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

I wish my government looked out for me like this.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale.

But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out regulations that achieve the right thing.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#35

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is because they know they’ll get away with it, one way or another. You can’t expect to enforce any of this if you don’t also legislate the technical specifics of how data must be collected, stored and processed so that its provenance is maintained.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#36
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

I’m not sure how true this is, many types of data have diminishing returns after a few months. I’d be surprised if they lost money compared to not using these methods —- they’ve just lost the tail of incremental value.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#37
This ruling should not be a surprise.

The writing has been on the wall for a long time that GDPR informed consent is to be interpreted in a narrow sense (i.e. actually being informed, not just clicking). And we know EU legal measures often take a long time but can bite hard. So here we are now!

[Edit]: Note that the decision can be appealed - so it's going to be a long while before we get a final verdict.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#38
post #13

Earlier quoted context omitted.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

I want one for "If your business model is advertisement, get off my Internet".

Isn't this already possible with uBlock and just configuring it to not allow you to go to sites that have any trackers at all?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#39
post #7

Quoted post unavailable.

The industry should really get together and set up something like P3PP but good. These settings should be set in the browser, not in the client.

Of course the ad and web stalking people don't want that, because that means users can easily opt out. With Google's misguided attempt to force FLOC down everyone's throats we may see them join forces with Apple, Microsoft and Mozilla at some point to develop a consent protocol that can be configured easily without the stupid popups.

For example, the browser could hide all the requested consent in a little button in the top right that opens into a menu to let the user pick what they do or do not consent to for what parties (with UI to show the necessary reasons for processing), with defaults configurable in the settings. The defaults would differ per browser of course (probably opt-in on Firefox and Safari, opt-out in Chrome and Edge) but it'd still work out for users because they could change the defaults.

Hell, with the rate HTTP is evolving (bodies in GET requests, QUERY, etc.) I can see a HTTP CONSENT verb coming to http4 eventually.

There are definitively other concerns with such a protocol, like the ability for malicious actors to use it for fingerprinting, but I think it's the only way forward for browsers. Big tech has ignored legislation for a while now, but if they don't show initiative the law will only get worse for them.

I bet the EU would happily list such a protocol as a requirement for most websites. People like you could just blanket allow everything, people like me could blanket block everything, and we'd all get rid of these stupid popups forever.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#40
post #22

Earlier quoted context omitted.

But don't the adtech vendors have to declare what they do with the data? (Purposes and Special Features)?

IAB europe had a shared list of vendors and their purposes amongst the ad industry, and everyone's popups using the TCF framework just prompted with the same list because they _might_ be in the ads, not because they'd actually be on the page. Many of the vendors claimed every purpose, often as legitimate interest, regardless of what they actually planned to do and if they _did_ count as legitimate interest.

The list is here [0] if anyone is interested.

[0] https://vendor-list.consensu.org/v2/vendor-list.json

Post reply on HN