Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

391–400 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#391

To be frank, the practical result of GDPR is that it made my browsing experience worse. Nearly every website opens with an annoying cookie popup, often blocking the content (or reducing it to a fraction of my screen on mobile). I've never once clicked "Yes, track everything", except by accident when tricked into it by deceptive UI (eg. a button designed to look more inviting than its less invasive counterpart). I get…

This is those companies successfully instrumenting you to lobby on their behalf. It is purposely and spitefully made to be annoying. Let's not reward that.

Don't mistake my comment as an endorsement for data collection.

It was about the practical effects that came about after the legislation was introduced. I hardly believe webmasters around the world coordinated a premeditated, mass conspiracy to annoy their visitors. I rather think the mess results from a misunderstanding on the part of businesses about what is actually required by the various legislation, complacence by the poor chap who's just trying to publish a site, and, yes, dark patterns on the part of platforms providing elements of the stack.

e.g. Those annoying banners aren't needed if you construct your site to not use cookies at all, until they're actually required for functions a user explicitly requests. Platforms have no business asking for my consent in the first place to cookies they know darn well do not serve any bonafide interest for the user.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#392

Earlier quoted context omitted.

> Basically your point is that most content on the internet should go away because you don’t like ads. No. I'm conpletely fine with ads. This isn't about ads vs.no ads. This is about "bad" ads. The wholeseale trading in people's information. It's a transaction where the price (Being their PII sold somewhere) isn't visible to the buyer. The reason we ended up where we are now where a site MUST use horrible adtech, is…

And, to go a step further: At least according to what I have read, before "bad" ads existed, the overall advertising budget of the corporate sector was roughly the same as it is now. This means that ad-supported business models were just as viable without all this crap. The problem is that the tracking and whatnot is perceived to increase value, so the ad spending shifted to prefer the more invasive and "targeted" ty…

If the budgets stay the same then some content might go where the ad money is. For example, the internet strangled the free metro newspaper business because having an ad-supported print media in the 2000's was difficult. If internet ads became dumber, then print ads don't look so dumb. And some money might flow back into things like this: https://en.wikipedia.org/wiki/Metro_(Swedish_newspaper) So if anything, the ad-supported content might shift to other places such as print.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#393
post #207

Some crazy figures here: The maximum fine for such a breach is 4% of the company's global revenue. Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96. Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of da…

> making them liable for a fine of up to $32.3Bn per year > their fine is 250k euros massive disconnect between reality and imaginary worlds.

When the GDPR was first becoming law/being talked about a lot, I recall there being a lot of posts from people in Europe explaining to us Americans one of the major differences between the European system of regulations and ours, which I will paraphrase to the best of my understanding:

When the EU sets a maximum fine level, that's there to give their courts discretion to drop the hammer on companies that have clearly been abusive. Expected practice there is more generally to lead with something that's more of a warning. Then, if they do it again, they can escalate toward the maximum.

The 32.3 billion figure there was the maximum possible fine for the combination of Microsoft, Google, and Amazon. Personally, I'm unclear on whether anyone besides IAB is currently being fined, but in either case, the point here appears to be to send the message "what you're doing isn't OK, clean it up now" rather than "all your revenue are belong to us".

For now.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#394

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

Most large companies have ethics hotlines you are expected to call when there is something questionable ethically or legally going on that might be difficult to bring up to a superior. Personally I'd refuse to add a dark pattern cookie dialog, but I'm in the privileged position of being able to switch jobs. But regardless, I'd probably send the ethics hotline an email saying that regulations are violated. Perhaps I'd…

Unfortunately the CEO does not report to the ethics hotline.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#395

So, how long until at least one online media giant realizes that not tracking their users and good old display ads are the easy way out?

Unfortunately, this is a Prisoners' Dilemma. If there were no personalized ads, regular ads would soak up all the ad budget and therefore be sustainable. But as soon as there are personalized ads, they quickly outcompete regular ads. Hence regulation is required.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#396

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

Most large companies have ethics hotlines you are expected to call when there is something questionable ethically or legally going on that might be difficult to bring up to a superior. Personally I'd refuse to add a dark pattern cookie dialog, but I'm in the privileged position of being able to switch jobs. But regardless, I'd probably send the ethics hotline an email saying that regulations are violated. Perhaps I'd…

Weird— I haven't worked for a big software development organization in some time but I've never heard of that. That's a positive thing if the company has good corporate culture and uses the information well instead of just calling your boss and asking them to consider being more ethical because you complained.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#397

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

> We designers must [...] This isn't something that's inflicted on us by web developers (on the whole); it's done by accountants. So fines are the most appropriate remedy. No judge wants to impose a fine that bankrupts a company; but fines that start gently, but double after each offence, are much more likely to cause the accountants to smell the coffee.

Absolutely. Ideally it's a policy problem that's all on management which should be too expensive to dissolve into some megacorp's operating budget.

Discussing how we can make achievable improvements now is also important.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#398

Earlier quoted context omitted.

The GDPR doesn't apply to data that can't be related to a natural person. Those models would therefore no longer be under the scope. Another example: You get consent from me, count your distinct visitors for January and I revoke my consent tomorrow. You do not have to change your visitor count retroactively.

I don't think that's a fair example, because the issue is not about inaccurate data (the view count), but illegally gathered data. An analog example would be stealing paint and painting your car with it. Should the paint be stripped off the car and given back? I don't know, but the victims are entitled to compensation, which isn't happening in the Google/Amazon case.

With your paint analogy, it feels like a "you wouldn't download car paint" situation.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#399

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

> We designers must [...] This isn't something that's inflicted on us by web developers (on the whole); it's done by accountants. So fines are the most appropriate remedy. No judge wants to impose a fine that bankrupts a company; but fines that start gently, but double after each offence, are much more likely to cause the accountants to smell the coffee.

It's not really done by accountants either. It's done by executives.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#400

Earlier quoted context omitted.

If you want to solve the problem, roll up on Google and Facebook headquarters, throw Sundar and Zuckerberg in jail for a year. Companies will think twice about their approach of "claim compliance until proven otherwise and then take the wrist slap". Put CEOs in prison and you'll see lasting change. As long as they can harm billions of people and only pay a modest fine in return, they will not change.

You are confused about what the "lasting change" would be. What would happen is that most of these major tech companies would simply ban all EU users. If the EU wants to be shut out of most of the tech world, fine. Because that would absolutely be the result of if all "tracking" was effectively blocked or stopped.

That would be the biggest business opportunity in human history if major tech companies simultaneously decided to surrender access to one-sixth of the world's economy.
Post reply on HN