Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

41–50 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#41
post #22

Earlier quoted context omitted.

But don't the adtech vendors have to declare what they do with the data? (Purposes and Special Features)?

IAB europe had a shared list of vendors and their purposes amongst the ad industry, and everyone's popups using the TCF framework just prompted with the same list because they _might_ be in the ads, not because they'd actually be on the page. Many of the vendors claimed every purpose, often as legitimate interest, regardless of what they actually planned to do and if they _did_ count as legitimate interest.

Also, in loading ads from these vendors, many often included external JS to whatever flavor-of-the-month adtech vendors or trackers they were using.

These were often not even listed in the framework. There was little-to-no compliance/auditing that I am aware. It was business as usual for many ad networks.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#42
Collecting and selling digital data is not a legitimate business enterprise. It’s spyware.

If no one wants to pay for your product, the market has spoken. Too bad.

We must correct the insanity and digital economic imbalance that spyware businesses have created.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#43
post #12
post #5

Finally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok. I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.

Yep, overall I'm really happy with the GDPR. The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. That way we could finally end this farce of the ad-industry's attempts at weaseling their way around the word of the law (and the latest rulings) by designing dark patte…

>The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own.

I love that idea. Something like Apple's nutrition labels but with check boxes next to data uses. However this is only good if it's legally enforceable since there is no API that would prove/verify data is used the way it's been given permission to.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#44
Nonsurprisingly, the Interactive Advertising Bureau has a slightly different spin on the ruling [1]: "APD Ruling Clears Way For Work on Developing TCF into a Formal GDPR Code of Conduct".

I'm surprised that ICCL very assertively states that all data collected through TCF must be deleted. The Belgian DPA only mentions a €250.000 fine and gives IAB two months to present an action plan [2]. Interesting to see how this plays out. :)

[1] https://iabeurope.eu/all-news/apd-ruling-clears-way-for-work... [2] https://www.dataprotectionauthority.be/citizen/iab-europe-he...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#46

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

When GDPR was introduced we flagged every datapoint with their point of origin I believe big tech did the same.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#48
> The Belgian Data Protection Authority said IAB Europe “was aware of risks linked to non-compliance” and “was negligent”. It also found that IAB Europe had failed to honour its data protection obligations to maintain records of data processing (Article 30 GDPR), to conduct a data protection impact assessment (DPIA) (Article 35 GDPR), and to appoint a Data Protection Officer (Article 37 GDPR).

Even if you were to give IAB the greatest possible benefit of the doubt, the fact that they didn't appoint a data protection officer makes it clear just how little they care(d).

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#49

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

[deleted]

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#50
post #10

Those popups did teach one good thing: when you see "legitimate interest" you know you're about to get scammed.

I'd love to know how often a 'reject all' button actually objected to all 'legitimate interest' crap too.

I expected the answer is site and consent management system dependent, so where I really couldn't avoid one of these sites, I'd manually object to all legitimate interest first before pressing it. Such a PITA and probably pointless ultimately, but hey..

Post reply on HN