Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

421–430 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#421

Earlier quoted context omitted.

The only people who misunderstand GDPR are people whose salaries depend on misunderstanding GDPR. The requirements are quite clear, advertiser just don't like them and are trying to avoid complying with them.

Yeah? So nobody in the EU is using Google Fonts, AWS, GCP, Azure, CloudFlare, Akamai or any other US provider then, given that this ruling is based on the fact that loading the consent settings screen from the shared domain requires "sharing" an IP address? Nobody in the EU runs an online business reliant on advertising? Of course they are. I'm convinced pro-GDPR views are always ideological in nature. It's impossibl…

> Every single requirement is vague and subjective - words like "appropriate", "necessary", "reasonable", "proportionate"

This is how laws work and why the "law as code" people are not going to succeed. The US leaves this to the enforcement stage, e.g. many tests in US law for ascertaining enforcement include things like the reasonable person test (https://en.wikipedia.org/wiki/Reasonable_person). Proportionality is a well enshrined standard in EU law in particular, and cuts both ways - it's why this ruling is not the maximum fine out the gate.

Or let's take this clause from the DMCA (regarding what is considered obsolete and therefore the library may format shift): "For purposes of this subsection, a format shall be considered obsolete if the machine or device necessary to render perceptible a work stored in that format is no longer manufactured or is no longer reasonably available in the commercial marketplace."

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#422

Earlier quoted context omitted.

If those companies extend their business beyond the US' jurisdiction, why do you feel they shouldn't be subject to some form of control where they operate? I'm legitimately asking. This is about something that was done within the EU to EU citizens. Why shouldn't the EU have a say?

I don’t feel that, actually. I’m not sure where you got that impression - maybe straw men are easier to debate? There are laws and then are how laws are enacted. Hint: pay attention to how homegrown EU companies are treated. EDIT: https://www.enforcementtracker.com/ Look here specifically. Sort by fine amount. Look at the companies that are being fined the hardest. It's not just the US that is being targeted. There's…

The largest fines are to US tech companies, which is expected due to (a) the fines being proportionate to revenue and these being the largest companies in the world and (b) these businesses having a significant involvement in large scale tracking of users.

I think the argument of like "well the law was passed to harm US companies specifically because US companies specifically do this" ignores that this is a undesirable behaviour with significant negative externalities, so this feels a bit like complaining that encouraging green energy at the expense of fossil fuels is discriminating against Russia and the middle east.

Once we get past the tech companies the next biggest fine is for H&M, for surveillance of call center employees, not just at workstations (which is probably also not allowed), but in their private lives, disclosure of that detail with managers, and targeted harassment from that information. This seems pretty egregious, and not political retribution against the UK.

Next up are some Italian companies fined in Italy, UK companies getting fined _by the UK_, and Vodafone subsidiaries getting fined everywhere. You could argue Vodafone is a UK company being unfairly targeted, but from what I remember of coverage of the (Spanish, I think?) ruling, they're a repeat offender in this regard.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#423

Earlier quoted context omitted.

Not quite. It does base some of its ruling on the consent string (it's the only personal data the IAB manages), but it does also conclude that the IAB is just as responsible as any complying participants. From what I understand, it argues that the IAB sets minimum requirements for the consent screens and ad serving, and those are not good enough. See also page 126 for a summary of the ruling. An editorial of my favou…

The whole thing is based on them declaring the IAB the controller of PII data (in this case the consent string). If upheld all the things you list will apply because these are the responsibilities of data controllers as per GDPR. If the TCF string was not deemed PII data then there would not be a controller because the GDPR would not apply. IMHO, if they were really serious about this, they would have to go after the…

this is just the first step. If the consent string wasn't PII, all the other data tied to the consent string would not be PII as well, because this is the cookie that brings all the data together.

So now that we have confirmed that they do indeed process PII and use the consent string as the unique identifier that ties the whole profile together we can start doing what you want. Going after the companies that attach other datasets to the consent string.

Before this ruling, the companies/controllers would have said that we process no personal data, thus GDPR doesn't apply. Now we have a ruling, saying that this is not a valid excuse.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#424

Earlier quoted context omitted.

It's true that the UK was always the biggest opponent, but don't kid yourself that the rest of the EU is on board with federalizing. There is no popular mandate for that whatsoever. Just look at what happens whenever some EU treaty needs ratifying by national referendum.

> There is no popular mandate for that whatsoever. that never stopped it before, just look at the "Constitution for Europe" rejected by the French and Dutch electorates it was then rejigged slightly and then pushed through as the Treaty of Lisbon (without pesky referendums)

The Lisbon Treaty did at least need a referendum in Ireland. It was rejected initially, partially as a warning shot to the then unpopular government between elections, and partially because of genuine concerns about the impact it would have on Ireland's military neutrality and for the concerns that the EU could then impose a minimum corporate tax rate on the country.

As a result, the EU agreed a set of guarantees [1] that the Lisbon treaty would not be used to do either of these things (to Ireland specifically), and only then did it pass in Ireland.

An EU army has more widespread opposition these days, so hasn't been raised since. Minimum corporate tax rates did not pass through the EU, though this year the US led an effort that is going to result in them globally via other avenues.

[1]: https://www.iiea.com/images/uploads/resources/230535195500_L...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#425
post #212

Earlier quoted context omitted.

> If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. zero chance of this ever happening.

What happens when, say, a restaurant does not allow inspectors to look at their operations? They get shut down or fined. Same thing. And, no, it's not different because the tech companies are serving up bits and bytes. Same mechanism.

restaurants provide food. serving bad food gets clients killed.

no comparison whatsoever with some websites. what you're writing about has to do with state overreach.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#426
post #195
post #191

Earlier quoted context omitted.

How do you prove there is no PII in the ML model? It has been proven countless times that it's possible to extract learning data from models. I can't see how you can prove the opposite, except, maybe, with federated learning (but even then, you need to good "ratio" of noise)

> How do you prove there is no PII in the ML model? Is "innocent until proven guilty" not a maxim in European justice?

Not in money laundering.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#427
post #236
post #228

Earlier quoted context omitted.

> All data collected through the TCF there is no data collected via TCF: https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa... CMPs are the popups that save the preferences and thus enable the collection of the data. IAB only provides a spec.

This kind of "but technically" is not going to go well for them if that's what they try. Technically the CMPs don't collect the data either, the ads do and the website controls how the CMP relates to ad loading. The TCF is a spec, the industry agreed on this spec, built implementations and used it as justification of tracking. I think it's fair to call data collected by ads loaded under the idea that a valid implemen…

> but technically

well, the difference is quite important.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#428
post #367
post #351

Earlier quoted context omitted.

I made no mention of free speech. I'm Canadian and support the significant mechanisms we have in place to combat hate speech! My point is only that speech is not violence. One does not need to change the meaning of the word violence in order to place sensible restrictions on speech. It is a cheap rhetorical trick.

It's intrinsically linked to "free speech" exemptions through being violent, because violence doesn't have to be physical, here's an excerpt from Wikipedia's opening paragraph on violence[1]: > Other definitions are also used, such as the World Health Organization's definition of violence as "the intentional use of physical force or power, threatened[4] or actual, against oneself, another person, or against a group o…

Violence huh?

That's what this conversation is devolving into, a fluidic interpretation of violence? Seems like a strawman argument; change the topic to violence, then argue a truism that violence is bad... all the while maintaining a pretend causal link between privacy and violence?

Sorry. Not. Persuasive.

That said, for the sake of civility and moving past this distractio... I will concede the point you seem so adamant to make, violence is not so simple. But again, not on-topic here, and it adds nothing to the conversation.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#429

We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's whe…

>but not saying anything implies consent... Hey, lets have sex. WARNING: DO NOT ATTEMPT You seem to have gotten confused as to the fundamental nature of consent. See the problem is it isn't put in writing . Putting things in writing gets people to pay attention.

There's a big difference between groups gauging each others' attitudes and individuals communicating specific decisions. Humans instinctively try to be harmonious with their group, and the group not responding to something negative communicates that this group doesn't care about it enough to respond to it. Furthermore, group attitude influencing individual behavior is a well-known facet of humanity. This concept is the foundation of television and other types of advertising.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#430

Earlier quoted context omitted.

> Without knowing what was collected how can they prove it was deleted? They don't need to know what data was collected. GDPR requires you to track all data and mark where you got it from, so the companies are legally required to track this for you, they should already have a switch where they can delete this data at the notice of the user, so they should have no problems honouring such a request from the government.…

What you're saying is literally illogical in the case of IAB acting as an intermediary... Not sure you know what you're talking about in this case. The entire point of the original article is that the user's data is being fed through via IAB to tracking companies. This isn't a normal GDPR situation where the user's data directly is being stored in a way that's accessible to the user as well. Obviously in that scenari…

This isn't a normal GDPR situation where the user's data directly is being stored in a way that's accessible to the user as well.

It's you that fails to understand the GDPR: that situation is not possible. In this case, the IAB is acting as the data controller for this data. As per GDPR requirements, when they share this data (for whatever purpose) with third-party processors, they must ensure through their contracts that the processor can comply with data deletion requests coming from users through the IAB.

If they cannot comply with that, both the controller and the processor are in violation of the GDPR, the controller doubly so because the GDPR requires them to audit their chosen data processors for GDPR compliance.

Post reply on HN