Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

431–433 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#431
post #207

Earlier quoted context omitted.

> making them liable for a fine of up to $32.3Bn per year > their fine is 250k euros massive disconnect between reality and imaginary worlds.

When the GDPR was first becoming law/being talked about a lot, I recall there being a lot of posts from people in Europe explaining to us Americans one of the major differences between the European system of regulations and ours, which I will paraphrase to the best of my understanding: When the EU sets a maximum fine level, that's there to give their courts discretion to drop the hammer on companies that have clearly…

That's pretty much it. Intent matters. A lot. Unless there's evidence suggesting they deliberately broke the law, the fine is going to be rather low.

If they keep doing it, they can't say they intended to follow the law, and they'll be punished more severely.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#432
post #423

Earlier quoted context omitted.

The whole thing is based on them declaring the IAB the controller of PII data (in this case the consent string). If upheld all the things you list will apply because these are the responsibilities of data controllers as per GDPR. If the TCF string was not deemed PII data then there would not be a controller because the GDPR would not apply. IMHO, if they were really serious about this, they would have to go after the…

this is just the first step. If the consent string wasn't PII, all the other data tied to the consent string would not be PII as well, because this is the cookie that brings all the data together. So now that we have confirmed that they do indeed process PII and use the consent string as the unique identifier that ties the whole profile together we can start doing what you want. Going after the companies that attach…

"Before this ruling, the companies/controllers would have said that we process no personal data, thus GDPR doesn't apply."

That is not correct. These companies use TCF because the GDPR applies. If it did not - they would not have to use it. The GDPR automatically applies as soon as cookies come into play - regardless of what is in the TCF string.

The main thing here is not that PII data comes into play but that the IAB is the controller. Until now the controller was/is the website that actually controls (and passes to 3rd parties) user data. That is why you have to agree to joint controller agreements if you want to integrate the TCF frameworks on larger web sites.

Some background in IPs: The ruling mentions the reason TCF is PII because it can be combined with IP addresses. No one challenges IP addresses as PII data anymore. There were many ruling that classify IPs as PII - specifically in Germany (even pre GDPR).

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#433
post #425

Earlier quoted context omitted.

What happens when, say, a restaurant does not allow inspectors to look at their operations? They get shut down or fined. Same thing. And, no, it's not different because the tech companies are serving up bits and bytes. Same mechanism.

restaurants provide food. serving bad food gets clients killed. no comparison whatsoever with some websites. what you're writing about has to do with state overreach.

I'm fine with the state as my representative physically shutting down and fining companies that without consent collect data on me and my loved ones. So, no overreach.
Post reply on HN