Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

361–370 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#361
post #306
post #286

Earlier quoted context omitted.

Good luck identifying these models. By now what caused what is so muddled, it could get a small army of lawyers to even start detangling

According to the GDPR the burden of proving compliance is on the controller by keeping paper trails and documentation. So technically they would already need to be able to prove were all data has come from, or else they can't have it. So either they start untangling or they delete it. :)

The models aren't the data and aren't regulated under GDPR. It would be crazy to try to do so tbh.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#362
post #361
post #306

Earlier quoted context omitted.

According to the GDPR the burden of proving compliance is on the controller by keeping paper trails and documentation. So technically they would already need to be able to prove were all data has come from, or else they can't have it. So either they start untangling or they delete it. :)

The models aren't the data and aren't regulated under GDPR. It would be crazy to try to do so tbh.

The models aren't subject to GDPR, but which data went to which model is: every data treatment must be documented.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#363

Earlier quoted context omitted.

There is a popular anti-drunk-driving campaign in the US with the slogan "Booze it and Lose It!" ("it" being your license) My town messed up on one of the billboards, though, and for a while commuters got to see "Booze it and Loose It!", which conveys a somewhat more carefree message.

Pics! or it didn't happen. j/k These are the kind of classic "Spell checking. It's impotent!" type of situations. For long bits of text, I can see how somethings might slip through. When it's only 4 friggin words, and it's a campaign being slapped up on multiple billboards for everyone to see, one might think letting someone else review/approve would be a good idea. Thinking it might have actually done that and still…

[deleted]

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#364

Earlier quoted context omitted.

Ok but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.

The issue here is larger than using the right language. I'm browsing through the full ruling [0], but C.1. Breaches, pages 115-117 is a good summary. - "First, the consent of the data subjects is currently not given in a sufficiently specific, informed and granular manner" - "Second, the legitimate interest of the organisations participating in the TCF is outweighed by the interests of the data subjects, in view of t…

Thanks! This is an informed take.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#366

Earlier quoted context omitted.

If those companies extend their business beyond the US' jurisdiction, why do you feel they shouldn't be subject to some form of control where they operate? I'm legitimately asking. This is about something that was done within the EU to EU citizens. Why shouldn't the EU have a say?

I don’t feel that, actually. I’m not sure where you got that impression - maybe straw men are easier to debate? There are laws and then are how laws are enacted. Hint: pay attention to how homegrown EU companies are treated. EDIT: https://www.enforcementtracker.com/ Look here specifically. Sort by fine amount. Look at the companies that are being fined the hardest. It's not just the US that is being targeted. There's…

Sorry, it was not my intention to construct a strawman: maybe I misunderstood what you were saying.

> a way for the EU to control US companies, extending their power beyond their jurisdiction

How are they extending their power beyond their jurisdiction, considering that this is something done in the EU to EU citizens?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#367
post #351
post #340

Earlier quoted context omitted.

"Free speech" is not a good example in my opinion when we already have so many exceptions to it: https://en.wikipedia.org/wiki/United_States_free_speech_exce... I'll reconsider not defending free speech from getting a "hate speech" exception when so called "free speech" proponents start talking about getting rid of the copyright exception instead of just wanting to say racist stuff. It makes complete sense to want to…

I made no mention of free speech. I'm Canadian and support the significant mechanisms we have in place to combat hate speech! My point is only that speech is not violence. One does not need to change the meaning of the word violence in order to place sensible restrictions on speech. It is a cheap rhetorical trick.

It's intrinsically linked to "free speech" exemptions through being violent, because violence doesn't have to be physical, here's an excerpt from Wikipedia's opening paragraph on violence[1]:

> Other definitions are also used, such as the World Health Organization's definition of violence as "the intentional use of physical force or power, threatened[4] or actual, against oneself, another person, or against a group or community, which either results in or has a high likelihood of resulting in injury, death, psychological harm, maldevelopment, or deprivation."[5]

There's no doubt that hate speech _does_ commit psychological harm, for example, but the article contains way more nuance than I have time for in this post so I implore you to read the article -- "violence" is just not as simple and limited as physical harm.

[1]: https://en.wikipedia.org/wiki/Violence

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#368

Earlier quoted context omitted.

If you want to solve the problem, roll up on Google and Facebook headquarters, throw Sundar and Zuckerberg in jail for a year. Companies will think twice about their approach of "claim compliance until proven otherwise and then take the wrist slap". Put CEOs in prison and you'll see lasting change. As long as they can harm billions of people and only pay a modest fine in return, they will not change.

You are confused about what the "lasting change" would be. What would happen is that most of these major tech companies would simply ban all EU users. If the EU wants to be shut out of most of the tech world, fine. Because that would absolutely be the result of if all "tracking" was effectively blocked or stopped.

That would be a great outcome for the EU. It means that EU companies have a home market that is shielded from their biggest competitors, while being free to compete on the world wide market.

If the EU would do that intentionally there would quickly be a complaint at the WTO.

In reality, as long as Google, Facebook, etc can make money in the EU, they are not going to leave.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#369

Earlier quoted context omitted.

MEPs sit in the European Parliament, which is a talking shop, with very limited powers. It's hardly surprising that few Europeans know who their MEP is.

I don't really have a MEP that's "mine", it's proportional representation,not a district system.

No districts? Is this a national "party list" system?

Where is that (pardon my inquisitiveness, and feel free not to answer)?

Instinctively it feels wrong not to be able to vote for a representative you can identify; but I can't formulate a coherent reason why it's wrong.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#370
post #155

Good, but i 'd like to see someone going after the root perpetrators of this racket, the advertisers themselves. That industry is surprisingly immune from scrutiny despite the fact that they 've wholesale sold their soul to google which is now both the buyer and seller of billions of advertiser money. They re just enabling the monopoly

Advertisers need content to advertise on. The GDPR basically forces content providers to get rid of tracking. That will require Google to provide an ad platform without tracking. And then the fun is over for the advertisers.

Of course with underfunded government privacy enforcement bodies, that process takes a long time. And then there is Ireland.

Post reply on HN