Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

321–330 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#321

Collecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.

Is it "spyware" if I install it myself to track my own activities?

Is it "spyware" if I get someone to install it so that I can track my own activities?

Is it "spyware" if it is someone else's idea to install it and get data related to me but I know about it and I am OK with it?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#322

Good. Now pick a random one of the companies that used this particular product/service and make an example of them. The problem I think until now has basically been that sites that rely on tracking ads know they are in violation. They don't want to comply, because it would be too costly. Basically, a meeting at one of these businesses (I'm imagining) has a conversation where people say "Ok what do we do about the coo…

If you want to solve the problem, roll up on Google and Facebook headquarters, throw Sundar and Zuckerberg in jail for a year. Companies will think twice about their approach of "claim compliance until proven otherwise and then take the wrist slap". Put CEOs in prison and you'll see lasting change. As long as they can harm billions of people and only pay a modest fine in return, they will not change.

You are confused about what the "lasting change" would be.

What would happen is that most of these major tech companies would simply ban all EU users.

If the EU wants to be shut out of most of the tech world, fine. Because that would absolutely be the result of if all "tracking" was effectively blocked or stopped.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#323
post #50

Earlier quoted context omitted.

I'd love to know how often a 'reject all' button actually objected to all 'legitimate interest' crap too. I expected the answer is site and consent management system dependent, so where I really couldn't avoid one of these sites, I'd manually object to all legitimate interest first before pressing it. Such a PITA and probably pointless ultimately, but hey..

Never, as far as I could tell. That was the whole point of the "reject all" button: to trick you into implicitly "agreeing" to the "legitimate interest" section.

"reject all", then go to "legitimate interest" and click "object all". Or, you know, just disable JS.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#324

Earlier quoted context omitted.

Countless articles and media pieces over the years on the plethora of unethical ways our data gets sold, resold and abused and still you ask what's wrong...

Yet No alternative have arrived to ads, people are used to free software how do you circumvent these things ?

It amazes me how people--even technical people--have been tricked into believing that ads require pervasive tracking.

Ads have been around for as long as there has been trade. So, thousands of years. Pervasive tracking has been around for less than thirty years. But yeah, "how in the world will we ever be able to show ads to people and pay for software?"

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#325

Here is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?

> and leave blank what consent means

Actually, this is not left blank at all...

--------------------

Consent means offering individuals real choice and control. Genuine consent should put individuals in charge, build trust and engagement, and enhance your reputation.

Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent.

Keep your consent requests separate from other terms and conditions.

Be specific and ‘granular’ so that you get separate consent for separate things. Vague or blanket consent is not enough.

Be clear and concise.

Make it easy for people to withdraw consent and tell them how.

Avoid making consent to processing a precondition of a service.

https://ico.org.uk/for-organisations/guide-to-data-protectio...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#326

Earlier quoted context omitted.

> Without knowing what was collected how can they prove it was deleted? They don't need to know what data was collected. GDPR requires you to track all data and mark where you got it from, so the companies are legally required to track this for you, they should already have a switch where they can delete this data at the notice of the user, so they should have no problems honouring such a request from the government.…

What you're saying is literally illogical in the case of IAB acting as an intermediary... Not sure you know what you're talking about in this case. The entire point of the original article is that the user's data is being fed through via IAB to tracking companies. This isn't a normal GDPR situation where the user's data directly is being stored in a way that's accessible to the user as well. Obviously in that scenari…

> how will the Council know if the end-tracking companies deleted their data?

There could be a tipoff, for example, from an employee. And if that whistleblower is right, then the company will suffer huge fines.

Or any other numerous ways that someone might be caught for a crime.. it lets go with whistleblower, as that is easy to understand.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#327

Earlier quoted context omitted.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

> Does this mean it will be a long term of conditions like apple does every time we use a website? I guess it is the opposite. GDRP requires clear and understandable text in privacy policies.

Ironically, nothing about GDPR itself is clear and understandable, as is evidenced by the fact that everyone keeps discovering years after implementation that some random country disagrees on their interpretation of it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#328

Earlier quoted context omitted.

The same way ads work in every other industry. Have you ever been to Times Square?

You mean the same ad industry that was easily supplanted by internet ads? So you want a regression, why exactly? If you don’t want to be tracked stop using sites that track you and install ad block.

> So you want a regression, why exactly?

Yes, if you get market advantages from harming people, you will eventually be required to at a minimum give it up again.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#329

Earlier quoted context omitted.

I know that. What I consider "scary" is that the EU can only do this because they're aren't directly elected and so not as subject to the typical democratic pressures. It points at a clear weakness of democracy.

Pressure your government to vote "no" on policies you don't like or pressure your government to initiate other legislation. They have the power and responsibility. And yes, I personally would like to have a stronger EU Parliament relative to the Commission and Council. However there is no reason to let the national government escape with "it's EU law" after they approved it. (And yes, Council doesn't require unanimou…

I think you misunderstand.

Almost all law coming out of the EU is really beneficial for the people, in my experience. Making a law like the GDPR and implementing it is hard work that doesn't grab headlines and first gives us a few years of annoying popups, but in the end it will actually improve privacy for EU citizens.

And national politicians can't do this anymore, because they have to be in the news each day and be in constant campaign mode because the next election may come sooner than expected. They need big words and shiny results.

If we make the EU more democratic, will it become less effective too?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#330
post #210

Earlier quoted context omitted.

Can the site deny your access then?

They cannot coerce you to sign away your fundamental rights in exchange for service. If they cannot offer service without violating your rights, then the service is illegal in Europe.

Then the result will be that those services simply stop serving EU customers.
Post reply on HN