Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

311–320 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#311

Earlier quoted context omitted.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

GDPR enforcement is completely arbitrary (in both senses of the word). People might cheer for the downfall of the tech giants but it's really just a way for the EU to control US companies, extending their power beyond their jurisdiction.

If those companies extend their business beyond the US' jurisdiction, why do you feel they shouldn't be subject to some form of control where they operate? I'm legitimately asking. This is about something that was done within the EU to EU citizens. Why shouldn't the EU have a say?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#312

Earlier quoted context omitted.

It's also extremely important that companies can't insulate themselves from consequences by outsourcing compliance functions to a "designated villain".

It seems like that's what's happening here though. The IAB appears to take all the blame while everyone else gets away.

I'm not sure to what extent this should be classified as a data breach, since the data was in effect illegally harvested and processed.

In case of a data breach, the controllers (i.e. the 1000+ companies) would be required to provide notification to the respective supervisory authorities of the affected users [33] -- although due to the one-stop-shop mechanism, that notification will be considered already done. But on top of that they would also be obligated to inform the affected users themselves [34].

Article 34 also includes this stipulation: The communication to the data subject [..] shall not be required if [..] it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

Note that these requirements are on the controllers, not the processor. IAB in this case is the processor. So if the data authority were to consider this a data breach, the controllers would not get away scot-free.

[33] https://gdpr-info.eu/art-33-gdpr/

[34] https://gdpr-info.eu/art-34-gdpr/

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#313

> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?

Yes, there are more popups when in Europe and they're often a lot bigger. You'll see it if you use a VPN to a server in Europe.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#314

Earlier quoted context omitted.

The "EU doing things" is not detached from your national government. In fact all EU legislation is being approved by your national government in the EU Council and the EU commission has to report there. (As well as the EU parliament, however the EU parliament is weak ...) Edit: maybe as addition in the last point in parentheses: The EU parliament is purposely weak, as the EU is a union of states and the member state…

> In fact all EU legislation is being approved by your national government in the EU Council it's via QMV, not unanimity so no need for "your" national government to approve it

Considering that almost all governments voted "yes" and only Austria voted "no" as they considered it to weak I think it is fair to say their government supported it.

https://web.archive.org/web/20171125221345/http://www.votewa...

In general you have somewhat of a point, but then it is democracy that the government would be responsible to argue for their point and convince others.

"EU did it" is a cheap excuse.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#315
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

So now they've destroyed user security in an attempt to destroy user privacy? That's actually genius.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#316
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

In the end it should be mandated that all user data is stored locally and cannot be processed outside of its local jurisdiction.

The U.S. is never going to accede that its intelligence agencies cannot access data gathered by its Tech Giants. All claims and soothing words to the contrary are a false belief.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#318
post #138

Earlier quoted context omitted.

I think you meant to use the word lose not loose. I suspect you mean lose the data as in delete it, not loose as in releasing the data to others.

There is a popular anti-drunk-driving campaign in the US with the slogan "Booze it and Lose It!" ("it" being your license) My town messed up on one of the billboards, though, and for a while commuters got to see "Booze it and Loose It!", which conveys a somewhat more carefree message.

Pics! or it didn't happen. j/k

These are the kind of classic "Spell checking. It's impotent!" type of situations. For long bits of text, I can see how somethings might slip through. When it's only 4 friggin words, and it's a campaign being slapped up on multiple billboards for everyone to see, one might think letting someone else review/approve would be a good idea. Thinking it might have actually done that and still nobody caught it is even more funny/sad.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#319

Good. Now pick a random one of the companies that used this particular product/service and make an example of them. The problem I think until now has basically been that sites that rely on tracking ads know they are in violation. They don't want to comply, because it would be too costly. Basically, a meeting at one of these businesses (I'm imagining) has a conversation where people say "Ok what do we do about the coo…

> Now pick a random one of the companies that used this particular product/service and make an example of them.

In particular, the random number should be a point on an interval that is split into regions proportional to the size of the companies, so bigger companies are more likely to be selected.

Is there a name for such a weighted random system? It seems like it could be used in some non-deterministic electoral systems too (which isn't as bad an idea as it sounds).

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#320

So, how long until at least one online media giant realizes that not tracking their users and good old display ads are the easy way out?

not gonna happen. (I don't know if it's related, twitter just showed me a cookie dialog out of the blue). Google is big enough to set their own consent standards, the IAB was a ruse anyway
Post reply on HN