Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

381–390 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#381

I seem to be the only HN user who really does not care at all if I am tracked. Judging from the horrible quality of ads I get, they're infinitely far away from reaching an accurate model of my behavior.

Just because you get bad ads doesn’t mean you’re not getting tracked well. In fact, it might mean you’re tracked really well and the only ads you’re getting served are those that are by one bidder. Everyone else decided you weren’t worth advertising to - so you get generic mass appeal ads that are very low cost to the company.

No different than getting spam snail mail that gets delivered to every house. Sure - you toss it in the recycling every week but someone will read it eventually and it’s basically nothing for the company to send out.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#382
post #63

Earlier quoted context omitted.

> Instead I predict another round of pseudo compliance and a more annoying user experience. Eventually they'll start a policy campaign in earnest stating that the GDPR is unworkable. I predict all of this to fail, at considerable expense for the IAB and its clients. The GDPR is popular amongst us EU residents.

I hope it does fail. Although I'm not in the EU I like the ideas the GDPR puts forward. My fear is that is legislation works in EU anything like it does in the US is that things that the people like but the corporations do not like... Well, corporate interests win out. I suspect that the whole reason the GDPR was allowed to pass was the corporations figured they could ignore it. Now finding out they can't they will f…

My not-yet-completely-cynical take is that EU still puts people before corporations, so we still have a chance to win. Fingers crossed.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#383

So, how long until at least one online media giant realizes that not tracking their users and good old display ads are the easy way out?

Never, as long as their core business model is based on privacy invasive tracking? They have every incentive to fight this back and none to actually comply (unless fines start getting higher, I suppose).

Well, me they've lost, I'm ad blocked to the hilt. But back in the day when tracking became pervasive the only thing that all that presumably smart coding did was irritate me, especially because I never saw a single ad that really appealed to me. This may well be because I'm weird, but even then: that's what tracking is for right, to personalize the experience.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#384
post #272
post #244

Earlier quoted context omitted.

Of course you can’t prove that some data cannot be de-anonymized unless there are duplicate entries. However, GDPR explicitly encourages anonymization, or “pseudonymization”, which therefore suggests that reasonable attempts to keep data generic are considered legal by this particular law. People have already pointed out that GDPR’s language here is too vague and makes bad assumptions about how identifying multiple q…

GDPR encourages pseudonymization as a best practice, but also draws a sharp distinction between anonymous and pseudonymous data. Pseudonymous data is still personal data and subject to all other obligations under GDPR. Any data that's pseudonymous would still be subject to the deletion order.

I shouldn’t have mentioned pseudonymization, that wasn’t my point. It doesn’t change the fact that the law is vague and to some degree contradicts itself, suggesting that data can be anonymous. There is a real and actual overlap between anonymized data and personally identifiable data. The way the GDPR is written, it would be extremely difficult to prosecute someone for breach of data they had taken best practice steps to anonymize. The law wasn’t written to handle ML based de-anonymization. It also doesn’t help here that if you Google PII, the hundreds and hundreds of examples are things like name and address, nothing remotely close to anonymous yet identifiable.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#385

I seem to be the only HN user who really does not care at all if I am tracked. Judging from the horrible quality of ads I get, they're infinitely far away from reaching an accurate model of my behavior.

No, I'm European and use a pixel phone with all data sharing enabled. I also enabled facial recognition in Google photos last time I was in the USA. I also share all my exercise data with Google, including heart rate via Google fit. I block most ads, except for Google ads and analytics. I always click on "accept all" when I get cookie and GDPR forms. My Google Drive is full of documents like scans of my passport, ESTA requests and some financial documents. I also have zero of the Google account privacy options enabled.

I'm also a local guide on Google Maps with a real photo, and my real name on the profile.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#386

Earlier quoted context omitted.

I disagree with what you’re saying. Basically your point is that most content on the internet should go away because you don’t like ads. Good luck with that. Instead, you should treat all the sites that have ads as inaccessible and personally use the small percentage that fit your needs. Everyone wins.

> Basically your point is that most content on the internet should go away because you don’t like ads. No. I'm conpletely fine with ads. This isn't about ads vs.no ads. This is about "bad" ads. The wholeseale trading in people's information. It's a transaction where the price (Being their PII sold somewhere) isn't visible to the buyer. The reason we ended up where we are now where a site MUST use horrible adtech, is…

And, to go a step further:

At least according to what I have read, before "bad" ads existed, the overall advertising budget of the corporate sector was roughly the same as it is now. This means that ad-supported business models were just as viable without all this crap.

The problem is that the tracking and whatnot is perceived to increase value, so the ad spending shifted to prefer the more invasive and "targeted" types of ads. But if we outlawed invasive, targeted ads and the tracking required to generate them...yes, there would be a certain amount of redistribution of ad spend, but overall, it doesn't seem like it would actually dry up and blow away.

So there's no good reason to think that getting rid of the really bad stuff would reduce the overall amount of ad-supported content out there.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#387
post #378
post #374

Earlier quoted context omitted.

No, advertisers want attention. And they are lazy, they are not going to look for content that fits their product. Google tells them "i have X users interested in your product" and that's what they buy. What's going to happen is they will move all their ad inventory into google search advertising.

Google will still tell them 'I have X users interested in your product'. It is just that Google will compute that from the contents of the wedsite instead of from tracking users. It would be amazing if there would be no ads outside google search. But that will not happen. That is a void that will be filled very quickly.

> no ads outside google search

There will be no content then, so the inside of google will be equally empty

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#388

I seem to be the only HN user who really does not care at all if I am tracked. Judging from the horrible quality of ads I get, they're infinitely far away from reaching an accurate model of my behavior.

Its cute that people still think that all of the data that Google and Metabook are amassing is used to sell them toothpaste.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#389

This headline and article is a gross misrepresentation of the ruling. The ruling is that the TCF consent string contains personal data and that the IAB is the data controller for this bit of data. This ruling has no impact what so ever on consent popups. It basically "just" trashes the industry standard that is used to pass consent signals. There are plenty of custom or non TCF implementations (all equally awful) of…

Not quite. It does base some of its ruling on the consent string (it's the only personal data the IAB manages), but it does also conclude that the IAB is just as responsible as any complying participants. From what I understand, it argues that the IAB sets minimum requirements for the consent screens and ad serving, and those are not good enough.

See also page 126 for a summary of the ruling. An editorial of my favourites:

> order the defendant to

> a. prohibit, via the terms of use of the TCF, the reliance on legitimate interests as a legal ground for the processing of personal data by organisations participating in the TCF

> d. take technical and organisational measures to prevent consent from being ticked by default in the consent interfaces

> e. force consent management platforms to adopt a uniform and GDPR-compliant approach to the information they submit to users

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#390

Earlier quoted context omitted.

I don’t feel that, actually. I’m not sure where you got that impression - maybe straw men are easier to debate? There are laws and then are how laws are enacted. Hint: pay attention to how homegrown EU companies are treated. EDIT: https://www.enforcementtracker.com/ Look here specifically. Sort by fine amount. Look at the companies that are being fined the hardest. It's not just the US that is being targeted. There's…

Sorry, it was not my intention to construct a strawman: maybe I misunderstood what you were saying. > a way for the EU to control US companies, extending their power beyond their jurisdiction How are they extending their power beyond their jurisdiction, considering that this is something done in the EU to EU citizens?

Because judgements are arbitrary and in practice unfairly hurts foreign companies.

There's an analogue that has happened in the U.S. Let's say that my little white town passes a law that forbids jaywalking. Protects pedestrians... Makes it easier to drive... Sensible law right? But in practice, it's the 1940's and the cops ONLY ticket black people. In practice, it's not a law against jaywalking - it's a law to drive out all the black people and make the white town inhospitable to anybody with skin tone.

GDPR claims to protect the people but is used as an economic weapon.

Post reply on HN