Live data from Hacker News

Meta prohibited from using personal data for advertisement

noyb.eu

431–440 of 443 posts

Re: Meta prohibited from using personal data for advertisement

#431

[flagged]

> It is the lack of a predictable regulatory landscape in Europe

What are on about? Europe's regulatory landscape is very predictable. GDPR was in the works for several years, and then had a two year grace period after going into effect. How more predictable do you want it to be?

> that keeps them from being a hotbed of technological innovation

Here are the reason why the US has a "hotbed of technological innovation": https://news.ycombinator.com/item?id=34265902

> keeps their people poorer

Ah yes. Poorer. Remind me what's the rate of medical bankruptcies, people on food stamps and people working two jobs is in the US vs. the EU?

> and requires continuous free-riding off of the US across a wide swath of sectors including healthcare and tech.

Ah yes. "free riding off the US" wat? If you think that cost of healthcare is what your insurance tower of babel is telling you, you need a doze of reality pills (too bad they are too expensive in the US).

The US only spends about 5% of its healthcare spending on actual R&D (~$170-180 billion). While it's more than Europe ($100-110 billion) it's not enough to say that Europe is "free loading"

> This decision, as I understand it, renders large swathes of tech service revenue models untenable.

If your "revenue model" relies on wholesale collection and sale of people's private data, good riddance.

Re: Meta prohibited from using personal data for advertisement

#432

Earlier quoted context omitted.

> I am 100% convinced - from people around me - that those who use FB and IG don't give a damn about privacy and would rather it be free of charge. When Apple forced apps to implement App Tracking Transparency which asks a neutral, OS-provided question to the user, only 4% opted in. Furthermore, people generally don't care about privacy because they don't understand the ramifications of that decision (which is exactl…

100% agreed - the issue is that people aren't giving _informed_ consent, I think it'd be great to have a law that basically says "the default has to be not tracking, and you can prompt and allow users to opt-in for targeted ads"

That... that is literally what GDPR is about: default is no tracking, no extra data collection. Users can opt in to data collection if they so wish.

Re: Meta prohibited from using personal data for advertisement

#433

Earlier quoted context omitted.

> Failure to consider the second-order effects of regulation causes the greatest harm to society. Ah yes. "Companies are willingly flaunting the law, so the law is bad" > Because of GDPR, consent to cookies must be freely given, specific, informed, and based on an explicit affirmative action. Indeed. So if you do ask for consent, there have to be two explicitly labeled buttons: "Agree", and "Disagree". How many of th…

There are many ways to target cookies without saying 'cookies' directly. >If the data you get/process/store is strictly required for the functioning of your business This is also quite the oversimplification, by this logic Facebook/Google don't need any consent as that user data and ability to serve targeted ads is required for the business to function. It's also telling that the GDPR.EU website itself seems to flaun…

> There are many ways to target cookies without saying 'cookies' directly.

Because cookies are just one piece of data, and GDPR is, suprise, General Data Protection Regulation

> This is also quite the oversimplification, by this logic Facebook/Google don't need any consent as that user data and ability to serve targeted ads is required for the business to function.

It is an oversimplification that works in the vast majority of cases. Even if targeted ads are required, protection of user data is still required. And when pressed Meta and Google have to prove that they actually need, say, a full facial profile of every person on the planet to sell someone a haemorrhoids cream.

> It's also telling that the GDPR.EU website itself seems to flaunt the law with this

This is a good catch. I think they changed that in not-so-distant past. Things like this need to be called out and fixed.

And not swept under the rug with a shrug and "the law is bad". That's exactly what happened before GDPR but without any visibility: every country had its own version of data protection laws, and all tech companies couldn't care less. Suddenly they care (and try to blame the law).

Re: Meta prohibited from using personal data for advertisement

#434

Earlier quoted context omitted.

Where is this fantasy world where the US has more appropriate medical care than the EU?

The US develops more therapies, drugs, and treatments than the entire EU despite having a fraction of the population. Europe benefits from the US doing that for them and then paying low prices that don't cover the costs of drug R&D.

This is a lie, of course.

The US spends about 170-180 billion U.S. dollars on medical R&D, the EU spends about 100-110 billion dollars on medical R&D.

While not equally, but Europe is definitely not "freeloading".

The costs of US healthcare lie squarely within the insurance tower of babel.

Re: Meta prohibited from using personal data for advertisement

#435
post #369

Earlier quoted context omitted.

Could always be an auction-based market - you start with a trial and only do a day/week/etc and gauge your results - if they're good you know you can bid more next time. With enough "liquidity" on either side the true price of said ad inventory will naturally come up without any tracking necessary.

That works for performance advertising, where you're able to tell whether your specific ad is getting results. But most display advertising (by dollars) is brand advertising, where Ford cares that a real person is seeing their ad but isn't expecting you're going to drop everything and click through to buy a truck.

How has that problem been resolved in offline (print/TV/display) advertising be solved, and could those solutions be reused for the web?

It seems like the free-for-all with regards to personal data and decriminalisation of spyware has led the online ads market into a near-optimal situation with regards to targeting & fraud detection, but 1) is it a trade-off people are willing to accept (the GDPR being enacted suggests not) and 2) can there be alternatives that give both sides what they want?

Re: Meta prohibited from using personal data for advertisement

#436
post #427

Earlier quoted context omitted.

I left Google six months ago, and don't work in ads anymore. Ads without fraud detection are worth very little, and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that.

> I left Google six months ago, and don't work in ads anymore. But you did work there, and you keep saying the same things over and over again. > and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that. You posit your incorrect interpretations as if they were fact. And you keep on conflating several things into one. Even though you've had plenty of time to,…

I agree with your #1, #2, or #3 and you're right that I've been saying several different things in different parts of this thread, where it's not entirely obvious how they fit together. I do have a coherent view, though -- let me walk through the whole thing and try to clarify.

My main view is that it should be legal to offer advertising-supported services where users can't just opt out of the advertising. If before a service can show any ads they need to offer the user a free choice on whether to see ads, where there are no consequences for clicking "no" other than that they don't see ads, users will overwhelmingly click "no" and the site will not be viable.

(I additionally think that it should be legal to offer services that are supported only by personalized ads, where users can choose between (1) using the service and having personalized ads vs (2) doing neither. I've argued that elsewhere in this discussion, but that's a bit of an aside to my main point.)

While I don't think the GDPR as-written prohibits such services, with the decisions coming out of the data protection agencies in the more privacy sensitive European countries I think the GDPR as-interpreted does make them economically non-viable for most sites because viability requires effective fraud detection.

If a service is going to show ads even if the user has clicked "no" and consented to nothing, it needs to be able to run the full ads stack without relying on anything that requires user consent. This includes:

* No cookies or other client-side storage, not even for detecting ad fraud. See the recent CNIL decision against Microsoft. [1]

* No network requests to any server operated by a US company or any subsidiary of one. See Schrems II [2] and follow-up rulings on applications such as analytics [3], fonts [4], and CDNs [5].

Together these rule out all commercially available adtech options I know about.

But let's say you decide to build something fully in-house, or you use some future ad product from a startup run by very careful Germans. What do you still need to do?

The GDPR requires you to have one of several legal bases for any personal data you process. With "consent" out of the picture, almost all of them are irrelevant for ads, with the potential exception of "legitimate interest". [6] Is detecting ad fraud or other invalid traffic something a site has a legitimate interest in?

The ad industry has historically thought that sites did. For example, the TCFv2 categorizes this under "Special Purpose 1", with users having "No right-to-object to processing under legitimate interests" [7]. On the other hand, points 52 and 53 of the recent Microsoft ruling [8] read to me as saying that since users do not visit sites to see ads that sites cannot claim that they have a legitimate interest in using personal data to attempt to determine whether their ads are being viewed by real people. This is not fully settled; among other things the Microsoft ruling was on the interaction of GDPR and ePrivacy, and ePrivacy is stricter on some points. But I think it's more likely than not that when we get clarity from the regulators it will turn out that the kind of detailed tracking of user behavior necessary for effective detection of ad fraud is not considered to be within a publisher's legitimate interests.

[1] https://news.ycombinator.com/item?id=34096210

[2] https://trustarc.com/blog/2022/11/30/schrems-ii-decision-cha...

[3] https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-...

[4] https://www.theregister.com/2022/01/31/website_fine_google_f...

[5] https://www.theregister.com/2021/12/08/germany_cookie_servic...

[6] https://gdpr.eu/article-6-how-to-process-personal-data-legal...

[7] https://iabeurope.eu/iab-europe-transparency-consent-framewo...

[8] https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000046768989

Re: Meta prohibited from using personal data for advertisement

#437
post #369

Earlier quoted context omitted.

That works for performance advertising, where you're able to tell whether your specific ad is getting results. But most display advertising (by dollars) is brand advertising, where Ford cares that a real person is seeing their ad but isn't expecting you're going to drop everything and click through to buy a truck.

How has that problem been resolved in offline (print/TV/display) advertising be solved, and could those solutions be reused for the web? It seems like the free-for-all with regards to personal data and decriminalisation of spyware has led the online ads market into a near-optimal situation with regards to targeting & fraud detection, but 1) is it a trade-off people are willing to accept (the GDPR being enacted sugges…

The traditional way to handle this in the offline world is with ratings agencies like Nielsen. This is the thing where they try to figure out how many people are watching each TV channel or who read a given paper.

The problem is, this requires the readings agency to build up a representative panel of people, and track their behavior. This is pretty coarse, but it works in a relatively centralized world like traditional TV where there are only a few dozen channels. On the web, however, people visit so many different sites that the panel would either have to be extremely large or you would only be able to generate reasonable ratings for the largest sites, probably both. This would be yet another force pushing hard toward internet consolidation.

Another option is that you could somehow build a new technology into browsers with some sort of privacy preserving API. I used to work in this area [1] but I am pessimistic about it: it's very hard (and may not be possible) to build something that gets all three of (a) minimal load on the users browser (b) actually useful fraud detection and (c) sufficiently private (with a separate question of whether usage would require consent under GDPR).

[1] https://privacysandbox.com/open-web/

Re: Meta prohibited from using personal data for advertisement

#438
post #436

Earlier quoted context omitted.

> I left Google six months ago, and don't work in ads anymore. But you did work there, and you keep saying the same things over and over again. > and (my interpretation is) the GDPR requires consent (including the ability to say no without consequences) for that. You posit your incorrect interpretations as if they were fact. And you keep on conflating several things into one. Even though you've had plenty of time to,…

I agree with your #1, #2, or #3 and you're right that I've been saying several different things in different parts of this thread, where it's not entirely obvious how they fit together. I do have a coherent view, though -- let me walk through the whole thing and try to clarify. My main view is that it should be legal to offer advertising-supported services where users can't just opt out of the advertising. If before…

> I agree with your #1, #2, or #3

> I do have a coherent view, though

It's strange that you agree... and yet your coherent view keeps on repeating the same lies, falsehoods, and keeps conflating things.

> My main view is that it should be legal to offer advertising-supported services where users can't just opt out of the advertising.

Let me re-iterate: You can still have ads on your site. GDPR does not preclude you from using ads on your site. GDPR doesn't care if you have ads on your site. Nothing in GDPR prevents you from having ads on your site.

I mean, come on. Go to spotify.com, download Spotify, and you will disover (undoubtedly to your surprise) that it offers exactly two tiers: ad-supported, and paid.

It's GDPR-compliant.

> it needs to be able to run the full ads stack without relying on anything that requires user consent

You can do that. Again. To re-iterate:

Not all ads need to be personalised ads. No, personalised ads are not a requirement. No, it doesn't mean that you can't have ads at all.

> No cookies or other client-side storage, not even for detecting ad fraud. See the recent CNIL decision against Microsoft. [1]

This is, of course, a blatant misinterpretation of that decision bordering on a lie. And a false generalisation.

> No network requests to any server operated by a US company or any subsidiary of one. See Schrems II [2]

Exactly. Because the US literally said: we don't care about user privacy and we assert the right to view and peruse any data of any citizen of any country in the world if they use American companies.

It is just amazing to me that for a person who keeps saying "I care about privacy" you complain about everything that improves privacy.

> The GDPR requires you to have one of several legal bases for any personal data you process.

Yes. Of course. Why do you want it any other way?

> With "consent" out of the picture, almost all of them are irrelevant for ads

Not all ads need to be personalised ads. No, personalised ads are not a requirement. No, if it doesn't mean that you can't have ads at all.

> Is detecting ad fraud or other invalid traffic something a site has a legitimate interest in?

No, fraud detection doesn't mean you need to collect personalised data beyond what's necessary for fraud detection. No, fraud detection doesn't mean you can willy-nilly use that data in anything other than fraud detection. No, fraud detection doesn't mean you can use that data for personalised ads, sell that data to third parties, or keep that data indefinitely long.

> The ad industry has historically thought that sites did.

No, The ad industry has historically thought that users' data is a free for all buffet with no consequences. They are now facing those consequences, and you go out of your way to protect the status quo.

Re: Meta prohibited from using personal data for advertisement

#439
post #436

Earlier quoted context omitted.

I agree with your #1, #2, or #3 and you're right that I've been saying several different things in different parts of this thread, where it's not entirely obvious how they fit together. I do have a coherent view, though -- let me walk through the whole thing and try to clarify. My main view is that it should be legal to offer advertising-supported services where users can't just opt out of the advertising. If before…

> I agree with your #1, #2, or #3 > I do have a coherent view, though It's strange that you agree... and yet your coherent view keeps on repeating the same lies, falsehoods, and keeps conflating things. > My main view is that it should be legal to offer advertising-supported services where users can't just opt out of the advertising. Let me re-iterate: You can still have ads on your site. GDPR does not preclude you f…

> Go to spotify.com, download Spotify, and you will discover (undoubtedly to your surprise) that it offers exactly two tiers: ad-supported, and paid. It's GDPR-compliant.

Why do you think Spotify is GDPR compliant? For example, if you look at https://support.spotify.com/us/article/gdpr-article-15-infor... they say "we use your personal data to tailor advertising to your interests" and their declared legal basis is "Our legitimate interests here include using advertising to fund the Spotify Service, so that we can offer much of it for free."

I agree there are tons of ad-supported services where if you decline their consent banners they still show you ads. But I think somewhere between "extremely few" and "none" of them are actually GDPR-compliant.

> for a person who keeps saying "I care about privacy" you complain about everything that improves privacy.

Where am I saying "I care about privacy"? My recent privacy writing is https://www.jefftk.com/p/privacy-tradeoffs and https://www.jefftk.com/p/preparing-for-less-privacy

I think there are commonly significant tradeoffs involved around privacy, and "maximize privacy over everything else" is not my view.

> > Is detecting ad fraud or other invalid traffic something a site has a legitimate interest in?

> No, fraud detection doesn't mean you need to collect personalised data beyond what's necessary for fraud detection. No, fraud detection doesn't mean you can willy-nilly use that data in anything other than fraud detection. No, fraud detection doesn't mean you can use that data for personalised ads, sell that data to third parties, or keep that data indefinitely long.

You're not engaging with my point. I agree that if you say you're doing something for "fraud detection" but it isn't actually needed for fraud detection than the GDPR prohibits that. But what I wrote in my previous message is that even "actually trying to do fraud detection and nothing else" is very likely not something courts will consider to be within the legitimate interest of companies.

Re: Meta prohibited from using personal data for advertisement

#440

[flagged]

For many industries like these that are heavily driven by development of intellectual property and heavily regulated by the government, nearly all the profit is made in the US market, while selling to the entire rest of the world adds a few % of revenue that by itself would not be enough to justify the investment.

Indeed. As I recall about 80% of pharmaceutical profits are made in the United States, while these same drugs are sold in other countries at much lower negotiated prices.
Post reply on HN