Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

341–350 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#341
post #293

Earlier quoted context omitted.

GDPR enforcement is completely arbitrary (in both senses of the word). People might cheer for the downfall of the tech giants but it's really just a way for the EU to control US companies, extending their power beyond their jurisdiction.

Or just a way to keep peoples’ data inside EU and not allowing it to leak for-profit companies.

That is one purpose yes and that’s why it has support of the people. The PATRIOT Act is similar. Its purpose is to protect Americans from terrorism.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#342

Here is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?

> They clearly mean to ban online tracking.

There's your error. GDPR is not about online advertising.

Things regulated by GDPR:

* CCTV in public spaces.

* Medical records.

* Employment records that businesses keep about their employees.

* Credit reports.

* Government records like voter databases and housing information.

* Trawling public business filings to send direct-mail spam.

* The loyalty card issued by your grocery store which tracks your purchases.

* The CRM database used by the sales guys in your SaaS company to keep track of hot leads.

GDPR regulates a wide array of data collection, and outright banning is not the correct solution for most of them. So it's about what obligations are attached to data collection and processing. Online advertising is only a small part of what's being regulated.

Even online, there are modes of data collection which are permissible. E.g. collecting anonymous site statistics for your own internal use. The obligations get harder and harder to satisfy when your business practice is to spread data hither and yon to whomever will pay a nickel for it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#343

To be frank, the practical result of GDPR is that it made my browsing experience worse. Nearly every website opens with an annoying cookie popup, often blocking the content (or reducing it to a fraction of my screen on mobile). I've never once clicked "Yes, track everything", except by accident when tricked into it by deceptive UI (eg. a button designed to look more inviting than its less invasive counterpart). I get…

I always click the "Yes, track everything" because it gives me better ads.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#344

Earlier quoted context omitted.

GDPR enforcement is completely arbitrary (in both senses of the word). People might cheer for the downfall of the tech giants but it's really just a way for the EU to control US companies, extending their power beyond their jurisdiction.

If those companies extend their business beyond the US' jurisdiction, why do you feel they shouldn't be subject to some form of control where they operate? I'm legitimately asking. This is about something that was done within the EU to EU citizens. Why shouldn't the EU have a say?

I don’t feel that, actually. I’m not sure where you got that impression - maybe straw men are easier to debate?

There are laws and then are how laws are enacted. Hint: pay attention to how homegrown EU companies are treated.

EDIT: https://www.enforcementtracker.com/ Look here specifically. Sort by fine amount. Look at the companies that are being fined the hardest. It's not just the US that is being targeted. There's this island nation that recently decided they didn't want to be part of the EU...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#345
post #262
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

I don't think it's much of a deterrent, because there's no clawback of the ill gotten gains from the use of that data. That's something done routinely in, say, fraud cases.

They did get a 250,000 eur fine, however that is based just on IAB membership fees.

This ruling should make it a lot harder for advertisers to hide behind the IAB though. One would hope that opens members up to more substantial fines in the future.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#346
post #162

Earlier quoted context omitted.

I think the point is that megacorps' business structure is way too complex for anyone to actually understand. Why is Gmail free? It makes money for Google, that part is clear, but I have no idea how exactly. I'm not even sure they can measure it exactly. Those companies have transformed the internet, and its users, by offering services for free, in exchange for user data. We have raised an entire generation (two, may…

> Of course, we cannot simply ban all advertising and start charging for everything. But I'm of the firm opinion that, in order to go forward, we have to leave this business model behind, as humanity. The only way to achieve this is by making it unattractive via legislation. What exactly are you proposing? Anyone who wants to pay for email can do so already. It's very trivial to not use any of Google's services or be…

Here's a job. You need a job. It pays in company scrip [1]. People took those jobs despite the negative consequences. The government eventually made such schemes illegal.

Your argument is "People have free choice, so anything that they do is legal."

The excuse of the perpetrators is "I'm not the one (directly) responsible for your poor economic situation, or your lack of education, so it's fair and moral for me to offer you a terrible proposition that you absolutely would not make if you were in a better economic situation." This is just where extreme capitalism gets you.

The list of examples is endless. Scrip. Children working in mines or cleaning chimneys. Click-through TOS. "Free" email. Indentured servitude.

At the end of the day it's no different than "You need to get on this boat to america, or this gentleman here is going to cut your wife's throat. Hey, it's not me doing the cutting. I'm the good guy. I'm trying to keep you safe. But its your choice."

It really depends on what we mean by "choice".

[1] https://en.wikipedia.org/wiki/Company_scrip

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#347
Americans think they can ignore the GDPR because it doesn't apply to them. Guess again. Moreover, other countries outside the EU are modeling their own, new legislation on the GDPR. Eventually, the US private sector will be forced to implement the GDPR for convenience' sake. The only issue will be the finding that because of built-in,NSA/FBI backdoors, data sent to the US cannot be secured under any circumstances.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#348

Earlier quoted context omitted.

I'd argue that the data has already been integrated into ML models or mixed in such a way that there's no way to even tell where the data originated from. While the logical conclusion would be to just delete any data they can't prove a legitimate origin for, I very much doubt this is going to happen. Most importantly, tens of billions have already been made using this ill-gotten data.

The GDPR doesn't apply to data that can't be related to a natural person. Those models would therefore no longer be under the scope. Another example: You get consent from me, count your distinct visitors for January and I revoke my consent tomorrow. You do not have to change your visitor count retroactively.

I don't think that's a fair example, because the issue is not about inaccurate data (the view count), but illegally gathered data.

An analog example would be stealing paint and painting your car with it. Should the paint be stripped off the car and given back? I don't know, but the victims are entitled to compensation, which isn't happening in the Google/Amazon case.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#349
post #195
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

If you choose to handle PII you have to keep track of where it ends up. Feeding PII into a black box and pretending it isn't there anymore without taking reasonable precautions, especially on something like ML that is known to leak its input, doesn't seem like it should be an option. If you don't know the safe assumption should be that the ML model can leak PII and should be destroyed along with the training data.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#350
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

In the end it should be mandated that all user data is stored locally and cannot be processed outside of its local jurisdiction. The U.S. is never going to accede that its intelligence agencies cannot access data gathered by its Tech Giants. All claims and soothing words to the contrary are a false belief.

That's a very likely outcome. Saudi Arabia passed its own GDPR (the PDPL) which does not permit the transfer of Saudi PII outside the Kingdom except in "extreme" circumstances.
Post reply on HN