Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

351–360 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#351
post #340
post #296

Earlier quoted context omitted.

> Spyware is illegal. So it’s just a matter of defining the data collection practices of internet companies as spyware. I’ve seen this phenomenon before but never so explicitly. When you can’t convince someone that something is bad, you re-define it as something they do consider bad. Some examples I’ve seen: - Some speech is so hateful and racist that its opponents wish to define it as “violence”. - Facebook offers a…

"Free speech" is not a good example in my opinion when we already have so many exceptions to it: https://en.wikipedia.org/wiki/United_States_free_speech_exce... I'll reconsider not defending free speech from getting a "hate speech" exception when so called "free speech" proponents start talking about getting rid of the copyright exception instead of just wanting to say racist stuff. It makes complete sense to want to…

I made no mention of free speech. I'm Canadian and support the significant mechanisms we have in place to combat hate speech!

My point is only that speech is not violence. One does not need to change the meaning of the word violence in order to place sensible restrictions on speech. It is a cheap rhetorical trick.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#352
post #195
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

It is, however in this case innocence means having a complete paper trail of your data processing as defined under GDPR. Not having such a paper trail is one of the things the IAB was found guilty of in this ruling.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#353
Can someone explain to me what the actual ruling is? Is the agency in question out of compliance, their specific implementation of a consent pop up, or the entire concept of a consent popup?

We use a consent pop up for non-advertising related cookies. And I'm trying to figure out if we are no longer in compliance.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#354
This headline and article is a gross misrepresentation of the ruling. The ruling is that the TCF consent string contains personal data and that the IAB is the data controller for this bit of data. This ruling has no impact what so ever on consent popups. It basically "just" trashes the industry standard that is used to pass consent signals. There are plenty of custom or non TCF implementations (all equally awful) of consent dialogs.

This ruling puts Google and FB in a much more powerful position - because they do not have to rely on standards like TCF to pass consent signals.

Instead of going after publishers and website owners who integrate these popups in the first place - they went after the inventor of the spec.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#355
post #72

Earlier quoted context omitted.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

This is not really accurate. The enforcement of GDPR is still up to national civil services/judiciaries, in this case it was a cooperation of multiple national protection authorities. Even the legislation itself necessarily involved national governments and national civil servants in national ministries GDPR being an EU level legislation has more to do with the absolute nightmare it would be for the internal market t…

There's this:

• Austria: Datenschutz-Grundverordnung (DSGVO) • Belgium: algemene verordening gegevensbescherming / règlement général sur la protection des données (RGPD) • Bulgaria: Общ регламент относно защитата на данните • Croatia: Opća uredba o zaštiti podataka • Cyprus: Γενικός Κανονισμός για την Προστασία Δεδομένων • Czech Republic: obecné nařízení o ochraně osobních údajů • Denmark: generel forordning om databeskyttelse • Estonia: isikuandmete kaitse üldmäärus • Finland: yleinen tietosuoja-asetus • France: règlement général sur la protection des données (RGPD) • Germany: Datenschutz-Grundverordnung (DSGVO) • Greece: Γενικός Κανονισμός για την Προστασία Δεδομένων • Hungary: általános adatvédelmi rendelet • Ireland: An Rialachán Ginearálta maidir le Cosaint Sonraí / General Data Protection Regulation (GDPR) • Italy: regolamento generale sulla protezione dei dati (RGPD) • Latvia: Vispārīgā datu aizsardzības regula • Lithuania: Bendrasis duomenų apsaugos reglamentas (BDAR) • Luxembourg: règlement général sur la protection des données (RGPD) / Datenschutz-Grundverordnung (DSGVO) • Malta: Regolament Ġenerali dwar il-Protezzjoni tad-Data • The Netherlands: algemene verordening gegevensbescherming • Poland: ogólne rozporządzenie o ochronie danych • Portugal: Regulamento Geral sobre a Proteção de Dados (RGPD) • Romania: Regulamentul general privind protecția datelor • Slovakia: všeobecné nariadenie o ochrane údajov • Slovenia: Splošna uredba o varstvu podatkov • Spain: Reglamento general de protección de datos (RGPD) • Sweden: Dataskyddsförordning • The United Kingdom: General Data Protection Regulation (GDPR)

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#356

> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?

If you live in the US as I do: yes, they are. I traveled to Germany and Belgium shortly before COVID, and the pop-ups were everywhere , even on sites that I know didn't have them back home. Anyway, I'd prefer if we had privacy laws like this in the US too.

California does. There is no comparable federal legislation. No other State comes close to California.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#357
post #109

> The Belgian Data Protection Authority said IAB Europe “was aware of risks linked to non-compliance” and “was negligent”. It also found that IAB Europe had failed to honour its data protection obligations to maintain records of data processing (Article 30 GDPR), to conduct a data protection impact assessment (DPIA) (Article 35 GDPR), and to appoint a Data Protection Officer (Article 37 GDPR). Even if you were to giv…

Even with good salary, who in their right mind would possibly accept the DPO job at IAB? That's pretty much guaranteed legal trouble, because IAB will always try to point their finger at you. Unless you're fresh in the job market and still believe in the good of people, maybe.

Normally, you could outsource that function.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#358

Earlier quoted context omitted.

My point is that I want everyone to be provided a clear choice - that's what the GDPR attempts to do. The GDPR doesn't actually outlaw targeted ads, it just mandates that the user is given a clear breakdown of the data being collected and how it will be used and then they can choose whether they're willing to opt-in. By your reasoning, malware should also be legal and it's up to people to learn the ramifications of i…

Malware is already legal to begin with. And yes, people should learn to trust trusted entities. Those entities will not allow malware. Government intervention is unnecessary.

I don't know where you're from but malware is definitely illegal in my country.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#359

Earlier quoted context omitted.

> Does this mean it will be a long term of conditions like apple does every time we use a website? I guess it is the opposite. GDRP requires clear and understandable text in privacy policies.

Ironically, nothing about GDPR itself is clear and understandable, as is evidenced by the fact that everyone keeps discovering years after implementation that some random country disagrees on their interpretation of it.

The only people who misunderstand GDPR are people whose salaries depend on misunderstanding GDPR. The requirements are quite clear, advertiser just don't like them and are trying to avoid complying with them.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#360
post #271

Earlier quoted context omitted.

What does Yahoo Japan have to do with Europe?

Not sure exactly what your question means but I'll attempt an answer: They currently offer services in the EEA and UK, such as webmail and news alerts (all in Japanese) and they will withdraw those services (presumably by geoblocking) in April.

Hopefully that will encourage Japanese expats living in the EEA and UK to push for equally good data protection laws back in Japan.
Post reply on HN