Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

301–310 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#301

Here is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?

This is a good question. I think the answer is that it's difficult to define up-front what is illegitimate "online tracking" and what is legitimate tracking of users necessary for things like accounts and saving of preferences (without drowning in special cases and loopholes).

The idea was to let users decide for themselves, case by case, whether they wanted the tradeoff of being tracked for the rewards (including things like saving your preferences).

The tracking industry didn't want to be banned and wouldn't give up without a fight, so they looked for a loophole in this fake consent spam.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#302

Earlier quoted context omitted.

I wish there was one I could set that just said "Fine, send me your cookies just don't expect them back".

Cookies are already pretty much irrelevant. IP address, user agents and browser fingerprinting is where it's at.

I know, I just wish they would stop asking me about it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#303
post #11

Earlier quoted context omitted.

I wish my government looked out for me like this.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

I would argue that many national governments (and local data protection agencies) are doing things, this was the Belgium national data protection agency. The issue is really Ireland, whose data protection agency has been twarting enforcement efforts. The reason why they are important is that they are technically responsible for enforcement against many of the big guys because they have their hqs in Ireland, which was also the reason why they didn't want to enforce, economic interests.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#304

Earlier quoted context omitted.

They lose all the data though. They may have avoided some name smearing but it's the data that they really want.

I'd argue that the data has already been integrated into ML models or mixed in such a way that there's no way to even tell where the data originated from. While the logical conclusion would be to just delete any data they can't prove a legitimate origin for, I very much doubt this is going to happen. Most importantly, tens of billions have already been made using this ill-gotten data.

I wonder if these models would become inaccurate over time without the data inflow.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#305

Earlier quoted context omitted.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

If you run a company that violates the GDPR, you might get sued and have to pay some fines. This is a calculated risk taken by many executives. If you then get a letter from the regulator stating that you were in violation, and have to delete some data, and you answer that you did, and signed it -- then you're likely up to criminal charges if that was a lie. This is not a line most executives are comfortable with cro…

> There might or might not be auditors visiting you after the first letter.

The ICO in the UK doesn't work like that, AFAIAA. You first get a polite letter; then a firmer letter containing helpful advice on how to come into compliance.

After that, you join a huge queue of companies awaiting legal enforcement action. The ICO is deliberately underfunded; it always has been. The government passed data protection laws, but they reserved the power of enforcement to an agency that was crippled from the start.

I welcome this court decision, obviously.

[Edit] Most of the penalties levied by the UK ICO used to be against local governments and government agencies. They were rarely against commercial operations. I see that there are some companies (that I've never heard of) now appearing in the list.

https://ico.org.uk/action-weve-taken/enforcement/

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#306
post #286

Earlier quoted context omitted.

Or just force all models to be deleted that had any input of that data in the first place. If they don't do that in practice let the whistleblowers do their job in exposing the companies.

Good luck identifying these models. By now what caused what is so muddled, it could get a small army of lawyers to even start detangling

According to the GDPR the burden of proving compliance is on the controller by keeping paper trails and documentation. So technically they would already need to be able to prove were all data has come from, or else they can't have it. So either they start untangling or they delete it. :)

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#307
post #2

Google, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

> Does this mean it will be a long term of conditions like apple does every time we use a website?

No. Freely and unambiguous given informed consent means that the users need to actually be able to understand what they consent to. Encrypting the information in a 500 page novel, obfuscating it beyond human ability to understand or interpret it, is not informed consent.

ToS are not currently under the same requirement of Freely and unambiguous given informed consent. They just require consent, which for now has been interpreted to mean basically anything that a lawyer want it to mean. People have given away their spiritual souls and first born child in ToS, through the ability to enforce such contracts is open to debate.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#308

Earlier quoted context omitted.

They lose all the data though. They may have avoided some name smearing but it's the data that they really want.

I'd argue that the data has already been integrated into ML models or mixed in such a way that there's no way to even tell where the data originated from. While the logical conclusion would be to just delete any data they can't prove a legitimate origin for, I very much doubt this is going to happen. Most importantly, tens of billions have already been made using this ill-gotten data.

The GDPR doesn't apply to data that can't be related to a natural person. Those models would therefore no longer be under the scope.

Another example: You get consent from me, count your distinct visitors for January and I revoke my consent tomorrow. You do not have to change your visitor count retroactively.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#310
post #207

Some crazy figures here: The maximum fine for such a breach is 4% of the company's global revenue. Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96. Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of da…

> making them liable for a fine of up to $32.3Bn per year > their fine is 250k euros massive disconnect between reality and imaginary worlds.

System is very broken if they can avoid liability with this.
Post reply on HN