Live data from Hacker News

Meta prohibited from using personal data for advertisement

noyb.eu

421–430 of 443 posts

Re: Meta prohibited from using personal data for advertisement

#421

Earlier quoted context omitted.

Nothing in the regulation requires the dark pattern popups that the tech puts up. Literally nothing.

Failure to consider the second-order effects of regulation causes the greatest harm to society. Because of GDPR, consent to cookies must be freely given, specific, informed, and based on an explicit affirmative action . On a webpage, it's pretty clear that action must be a click. The regulation does require it if you want to use cookies, and it's near impossible to code any useful page without storing state (cookies)…

> Failure to consider the second-order effects of regulation causes the greatest harm to society.

Ah yes. "Companies are willingly flaunting the law, so the law is bad"

> Because of GDPR, consent to cookies must be freely given, specific, informed, and based on an explicit affirmative action.

Indeed. So if you do ask for consent, there have to be two explicitly labeled buttons: "Agree", and "Disagree". How many of the greedy leeches siphoning user data are providing that? And how many are instead waiting how long they can get away with it before the regulators get to them?

> The regulation does require it if you want to use cookies, and it's near impossible to code any useful page without storing state (cookies).

Nope. This is a lie that has been sold to you buy the same greedy leeches that have sold you the lie that it is the GDPR that is bad, the GDPR that is requiring these bad cookie popups etc.

First thing you could do is open the law (it's not that long and is not that complex) and try to find where cookies are mentioned. Hint: they are mentioned nowhere in the main body of text, and are only mentioned in one of the Recitals.

However, you rely on the industry to tell you that the law is bad even if the industry is extremely interested in painting the law in a bad light.

So.

If the data you get/process/store is strictly required for the functioning of your business (whether it's for storing login info or a shopping cart, or because other laws say so as they do in the case of banks), consent is not required.

If you get/process/store that data for any other reason, you must get a specific informed consent from the users. And no, pre-selected checkboxes, hiding "disagree/reject" behind fifteen clicks etc. is not it.

Re: Meta prohibited from using personal data for advertisement

#422

Earlier quoted context omitted.

I'm happy to be an EU citizen for all the great tech regulations that are actually passing here !

On the other hand, this seems like an easy way to avoid addressing Europe's lack of it's own tech industry. If Europe wants more ethical tech, they should make an honest effort to create an environment that supports that. I.e., invest in their own tech industry.

> On the other hand, this seems like an easy way to avoid addressing Europe's lack of it's own tech industry.

The only reason the US has its tech industry is:

- lax laws for everything: from data protection to labor laws

- unlimited investor money that can sustain unprofitable businesses for decades Most of the top HN darling have never been profitable, and have been losing billions of dollars for years. The rest haven't been profitable for most of their existence

On top of that it helps to have a huge largely homogenous market

Re: Meta prohibited from using personal data for advertisement

#423

Earlier quoted context omitted.

Thankfully the GDPR mandates that the "accept" option can't be more prominent than the "decline" one.

The endless barrage of insipid GDPR cookie consent banners have corrected a weird English-language blind spot I had: it turns out that the opposite of "accept" is not "reject," but rather "customize settings" or "view preferences."

Those banners are illegal according to GDPR. Once there's a threat of a fine on the horizon all those "insipid banners" quickly change to show you a reject button https://noyb.eu/en/where-did-all-reject-buttons-come

Re: Meta prohibited from using personal data for advertisement

#424
post #354

Earlier quoted context omitted.

If this was true, every major German news website would violate the GDPR because that's exactly what they do. Can you cite the relevant GDPR article?

Those websites are in violation of the GDPR. Article 7 item 4: “When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia , the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.” This basically means that if providing the service is made con…

That's a misconception. "Provision of a service" only means paid services and doesn't apply to websites offering content for free.

Re: Meta prohibited from using personal data for advertisement

#425
post #75

Meta can still use personal data for ads. They just have to explicitly ask for consent. I do not like these sensationalized titles on HN.

I would be totally fine with a regulation where they had to ask before using personal data to show ads. The overreach is that the GDPR requires that the user be able to say "no" but still use the service -- you can't make use of the service conditional on accepting ads, and you can't require users to pay instead.

jeff. We've been through this multiple times already. You working for the ad portion of Google has made you madly in love with ads to the point that you pretend that not letting you siphon and sell my personal data wholesale means you can't show ads. This is not true. Multiple people have told you that already, across a multitude of threads.

You can still have ads on your site. GDPR does not preclude you from using ads on your site. GDPR doesn't care if you have ads on your site. Nothing in GDPR prevents you from having ads on your site.

How more clear can I write this?

Stop spreading lies and bullshit.

Re: Meta prohibited from using personal data for advertisement

#426

Earlier quoted context omitted.

Failure to consider the second-order effects of regulation causes the greatest harm to society. Because of GDPR, consent to cookies must be freely given, specific, informed, and based on an explicit affirmative action . On a webpage, it's pretty clear that action must be a click. The regulation does require it if you want to use cookies, and it's near impossible to code any useful page without storing state (cookies)…

> Failure to consider the second-order effects of regulation causes the greatest harm to society. Ah yes. "Companies are willingly flaunting the law, so the law is bad" > Because of GDPR, consent to cookies must be freely given, specific, informed, and based on an explicit affirmative action. Indeed. So if you do ask for consent, there have to be two explicitly labeled buttons: "Agree", and "Disagree". How many of th…

There are many ways to target cookies without saying 'cookies' directly.

>If the data you get/process/store is strictly required for the functioning of your business

This is also quite the oversimplification, by this logic Facebook/Google don't need any consent as that user data and ability to serve targeted ads is required for the business to function.

It's also telling that the GDPR.EU website itself seems to flaunt the law with this: "We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it"

Re: Meta prohibited from using personal data for advertisement

#427
post #75

Earlier quoted context omitted.

I would be totally fine with a regulation where they had to ask before using personal data to show ads. The overreach is that the GDPR requires that the user be able to say "no" but still use the service -- you can't make use of the service conditional on accepting ads, and you can't require users to pay instead.

jeff. We've been through this multiple times already. You working for the ad portion of Google has made you madly in love with ads to the point that you pretend that not letting you siphon and sell my personal data wholesale means you can't show ads. This is not true. Multiple people have told you that already, across a multitude of threads. You can still have ads on your site. GDPR does not preclude you from using a…

I left Google six months ago, and don't work in ads anymore.

Ads without fraud detection are worth very little, and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that.

Re: Meta prohibited from using personal data for advertisement

#429

Earlier quoted context omitted.

Wow. There's no way that should be legal. I hope somebody sues so a judge can rule on it.

Problem is that bringing on a lawsuit (especially against a large company) is difficult, so maybe laws such as the GDPR that forbid everyone from misusing personal data are better, instead of forcing citizens to spend time & money getting their own justice.

Well, yes, but we work with what we've got, and right now it's a lot easier and even cheaper to file a lawsuit than to get Congress to act.

Re: Meta prohibited from using personal data for advertisement

#430
post #427

Earlier quoted context omitted.

jeff. We've been through this multiple times already. You working for the ad portion of Google has made you madly in love with ads to the point that you pretend that not letting you siphon and sell my personal data wholesale means you can't show ads. This is not true. Multiple people have told you that already, across a multitude of threads. You can still have ads on your site. GDPR does not preclude you from using a…

I left Google six months ago, and don't work in ads anymore. Ads without fraud detection are worth very little, and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that.

> I left Google six months ago, and don't work in ads anymore.

But you did work there, and you keep saying the same things over and over again.

> and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that.

You posit your incorrect interpretations as if they were fact. And you keep on conflating several things into one. Even though you've had plenty of time to, you know, read something about the things you're talking about.

1. Not all ads need to be personalised ads. No, personalised ads are not a requirement. No, if it doesn't mean that you can't have ads at all.

2. No, fraud detection doesn't mean your ads are personalised. No, fraud detection doesn't mean that your ads must be personalised.

3. No, fraud detection doesn't mean you need to collect personalised data beyond what's necessary for fraud detection. No, fraud detection doesn't mean you can willy-nilly use that data in anything other than fraud detection. No, fraud detection doesn't mean you can use that data for personalised ads, sell that data to third parties, or keep that data indefinitely long.

And yet, here we are, again, when you keep saying that these three disparate things are one and the same and that "GDPR is an overreach that prevents sites from showing ads". You keep repeating the same falsehoods over, and over, and over again. Please, stop.

Post reply on HN