Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

411–420 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#411

Americans think they can ignore the GDPR because it doesn't apply to them. Guess again. Moreover, other countries outside the EU are modeling their own, new legislation on the GDPR. Eventually, the US private sector will be forced to implement the GDPR for convenience' sake. The only issue will be the finding that because of built-in,NSA/FBI backdoors, data sent to the US cannot be secured under any circumstances.

I think you are confusing "Americans" with mega-corporations.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#412

Earlier quoted context omitted.

If you want to solve the problem, roll up on Google and Facebook headquarters, throw Sundar and Zuckerberg in jail for a year. Companies will think twice about their approach of "claim compliance until proven otherwise and then take the wrist slap". Put CEOs in prison and you'll see lasting change. As long as they can harm billions of people and only pay a modest fine in return, they will not change.

You are confused about what the "lasting change" would be. What would happen is that most of these major tech companies would simply ban all EU users. If the EU wants to be shut out of most of the tech world, fine. Because that would absolutely be the result of if all "tracking" was effectively blocked or stopped.

I think if locking up crooks cause them to stop doing crooked things in your country, that's an absolute success, and one of the ideal outcomes of putting people in prison. ;)

But also, I would strongly encourage the United States to do this. Extradition is obviously far more complicated, and as you say, could just lead them to excluding the geographic region that holds them responsible.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#413

Here is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?

The issue is that GDPR isn't fundamentally about online data collection or tracking, it's about all data collection in general. You can't ban everyone from collecting data about anyone in all situations, because there are many cases where people legitimately want or need their personal information to be collected and processed by someone else. For example medical records, magazine subscriptions, bank accounts, etc. These are all covered by the GDPR, in addition to illegitimate data collection for the purpose of ad tracking.

So how do you define, in law, when a person legitimately wants a company to process their personal information, and when it should count as illegal tracking? The GDPR actually makes an attempt at defining this (doesn't just leave it blank), but many adtech companies just ignore this and break that law. See the article for an example.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#414

Earlier quoted context omitted.

They don't know. But if evidence comes up showing a company didn't then they will take legal action against that company, in which case intent to break the law from the would be crystal clear so they would get maximum fines which are huge for GDPR. It isn't like laws prevents all crimes, the goal is to reduce illegit data usage, there is nobody who thinks it can ever get completely stamped out.

I'm asking what kind of evidence can exist that proves a negative? Without knowing what was collected how can they prove it was deleted? Doesn't make any sense.

Nothing can prove the negative. But if any shred of evidence comes out that they didn't comply, there will be severe consequences for them, which makes it at least reasonably safe to assume they will comply. It's hard to keep a secret like that.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#415

Collecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.

> Collecting and selling digital data is not a legitimate business enterprise. According to who, you? > It’s spyware. How is it spying when the people are freely giving away their data? > If no one wants to pay for your product, the market has spoken. Too bad. Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data? > W…

"freely giving away their data" is a misrepresentation. People are either putting up with their data being collected, or unaware that it is happening, because that is the only way many services can be accessed nowadays. I bet you couldn't find a single person off the street who would answer "yes" if asked whether they go on the internet specifically to give personal information to ad companies.

Or, to put it more briefly: "How is it spying when the White House employees freely hung up our gift painting with the bug in it on their wall?"

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#416
post #72

Earlier quoted context omitted.

This is not really accurate. The enforcement of GDPR is still up to national civil services/judiciaries, in this case it was a cooperation of multiple national protection authorities. Even the legislation itself necessarily involved national governments and national civil servants in national ministries GDPR being an EU level legislation has more to do with the absolute nightmare it would be for the internal market t…

There's this: • Austria: Datenschutz-Grundverordnung (DSGVO) • Belgium: algemene verordening gegevensbescherming / règlement général sur la protection des données (RGPD) • Bulgaria: Общ регламент относно защитата на данните • Croatia: Opća uredba o zaštiti podataka • Cyprus: Γενικός Κανονισμός για την Προστασία Δεδομένων • Czech Republic: obecné nařízení o ochraně osobních údajů • Denmark: generel forordning om datab…

This is just the translation of GDPR in the EU languages, did you mean to reply under a different comment?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#417

Earlier quoted context omitted.

The only people who misunderstand GDPR are people whose salaries depend on misunderstanding GDPR. The requirements are quite clear, advertiser just don't like them and are trying to avoid complying with them.

Yeah? So nobody in the EU is using Google Fonts, AWS, GCP, Azure, CloudFlare, Akamai or any other US provider then, given that this ruling is based on the fact that loading the consent settings screen from the shared domain requires "sharing" an IP address? Nobody in the EU runs an online business reliant on advertising? Of course they are. I'm convinced pro-GDPR views are always ideological in nature. It's impossibl…

>Why is asking users for consent, a key piece of GDPR compliance previously, suddenly not OK?

Asking for consent is still OK. Just the way how IAB has been doing it is not OK as it was found to not constitute explicit consent.

And before you say that explicit consent is not defined there are easily accessible guidelines from the European Data Protection Board. https://edpb.europa.eu/our-work-tools/our-documents/guidelin...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#418

This headline and article is a gross misrepresentation of the ruling. The ruling is that the TCF consent string contains personal data and that the IAB is the data controller for this bit of data. This ruling has no impact what so ever on consent popups. It basically "just" trashes the industry standard that is used to pass consent signals. There are plenty of custom or non TCF implementations (all equally awful) of…

Not quite. It does base some of its ruling on the consent string (it's the only personal data the IAB manages), but it does also conclude that the IAB is just as responsible as any complying participants. From what I understand, it argues that the IAB sets minimum requirements for the consent screens and ad serving, and those are not good enough. See also page 126 for a summary of the ruling. An editorial of my favou…

The whole thing is based on them declaring the IAB the controller of PII data (in this case the consent string). If upheld all the things you list will apply because these are the responsibilities of data controllers as per GDPR. If the TCF string was not deemed PII data then there would not be a controller because the GDPR would not apply.

IMHO, if they were really serious about this, they would have to go after the actual controllers (not the inventor of the spec) - mainly the actual websites that implement these (misleading) banners in the first place. It's beyond me how they can qualify the IAB as a controller when they never collect, process or store any of TCF data.

If this wasn't so politically charged I'd say the IAB has a solid shot of getting this overturned in court.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#419

Anybody wants to shed some light what exactly was illegal at the consent popups? I think Google, Microsoft and others use all different/branded popups, so I would want to know what the problem is there.

From a UI point of view, the failures I typically see is that agreeing to everything is easy but declining is difficult despite both options needing to be equally prominent. From a technical point of view, the tracking scripts are often loaded to begin with (where your IP address & browser fingerprint is already leaked) and declining tracking merely "asks them nicely" with no guarantee they'll obey the signal or whet…

Also the legitimate interest abuse was also ruled against. Many of these claim legitimate interest so they have a second set of options you need to untick or click "object" to individually. This isn't valid consent as not giving consent is harder than giving it, and per the ruling isn't valid legitimate interest as the companies did not conduct an adequate balancing of the user's interests vs the businesses and when the DPAs did so they did not find the company's interest outweighed the user's privacy interests.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#420
post #411

Americans think they can ignore the GDPR because it doesn't apply to them. Guess again. Moreover, other countries outside the EU are modeling their own, new legislation on the GDPR. Eventually, the US private sector will be forced to implement the GDPR for convenience' sake. The only issue will be the finding that because of built-in,NSA/FBI backdoors, data sent to the US cannot be secured under any circumstances.

I think you are confusing "Americans" with mega-corporations.

Plenty of American HN commenters agree with the mega-corporations in these threads, including at least some not employed by them
Post reply on HN