Live data from Hacker News

GDPR complaint claims Google and IAB ad category lists leak intimate data

techcrunch.com

51–60 of 68 posts

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#51

These categories apply to the content, not the cookie (when a cookie is even available which it isnt in many places). This is not personal, it's the contextual targeting everyone wants. These blog posts never understand adtech.

The point is that bid requests may (do) contain both an identifier and data about that person. "Is reading a financial news article" being an attribute of the content, sure, but broadcast such that it can be associated with the person.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#52

Setting aside penalties for a moment, what is the minimum set of changes to programmatic advertising practices that would bring it into compliance with GDPR? Would removing the targeting categories that relate to intimate data be sufficient? Or is something deeper, more structural in the crosshairs?

Remove userid / cookie sync / whatever you name it from bid requests, and make them only context based. Also, forbid cookies from ads providers to be stored on the end user machine.

Note that this doesn't disallow websites with first party data and user consent to add user related information to the bid requests to increase their value, it just doesn't allow to correlate the information with a person after the RTB process ends. Of course it totally changes the role of data providers in the current ecosystem, but that wouldn't necessarily be a bad thing.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#53

These categories apply to the content, not the cookie (when a cookie is even available which it isnt in many places). This is not personal, it's the contextual targeting everyone wants. These blog posts never understand adtech.

The point is that bid requests may (do) contain both an identifier and data about that person. "Is reading a financial news article" being an attribute of the content, sure, but broadcast such that it can be associated with the person.

That's just how context works. If you visit another site then there would be different categories involved and has nothing to do with the user.

There's also no personal identity, it's just a cookie if available, used mostly to frequency cap.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#54
post #36

Earlier quoted context omitted.

Agree. GDPR and programmatic ads are totally incompatible. I believe this is intentional on part of the EU.

Basically anything that hurts American tech companies is intentional on the part of the EU. That's why they're keeping both eyes shut on the plethora of violations many European companies are doing.

You have to report the violating companies. There are no government organizations actively looking for violations.

The American companies are simply bigger target and have the attention of more people, so their reported more quickly.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#55

Setting aside penalties for a moment, what is the minimum set of changes to programmatic advertising practices that would bring it into compliance with GDPR? Would removing the targeting categories that relate to intimate data be sufficient? Or is something deeper, more structural in the crosshairs?

Offer users a meaningful reason to actually consent to such targeting. Current "consent" forms are not meaningful in that most users are probably clicking "ok" just to get rid of the pop up and not because they actually agree.

Why would users actually provide meaningful consent to having a tracking profile? You need to actually offer something to users. The law essentially says you cannot just start profiling them without their permission.

You could offer users a subscription based ad free browsing experience. User pays 50 euro a year, you take a 10% margin, leaving 45 euro behind to provide the ad free experience. At 164 impressions per day (stretched inference from the article) you bid 0.075 cents per ad space. If an ordinary advertiser bids less then this to show you an ad, then no ad would be shown instead and the content publisher would still get paid. At any time you could cancel your subscription and demand that the profile be deleted. This is just one idea on how you could collect meaningful consent for an ad profile.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#56
Here’s a few more highly sensitive labels that are being attached to web users’ identities and shared with potentially thousands of bidding ad companies — in this case the labels are ones which the IAB uses: Special needs kids, endocrine and metabolic diseases, birth control, infertility, diabetes, Islam, Judaism, disabled sports, bankruptcy.

I'm jealous that at least Europeans can complain legally.

In the U.S., we believe that the free market knows best and that's freedom and such. Meanwhile, we're being profiled by these vile companies (FB, Google) and our data resold. Aside from individual rights being violated (hint, individual rights aren't just rights against government intervention), there's a huge societal threat here: what happens when this data is used to pit us against one another? Are we still free, then?

In the U.S. it will take a cataclysmic event to reach a GDPR-like desire by the population. The sad reality is that the EU has its citizens' interests generally in mind (consumer protections, GDPR), while in the U.S. Big Brother has the interests of large corporations at heart (namely by allowing them to run roughshod over our rights).

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#57

Earlier quoted context omitted.

I by no means and expert on the subject, but I believe that the "simplest" change would be to target based on content, rather than the individual user.

The ad categories mentioned in this complaint are the content categories.

I don't mean the "content categories" of the user.

If a page on some website is about cars, then you sell that page as being about cars to the advertisers. At no point would you care about the user, just the assumption that a person reading about the latest Toyota might be in the marked for a new car.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#58
post #8

Earlier quoted context omitted.

I agree but is this a Google specific thing? So many companies gather data on people without letting them see anything... I feel like we need legislation regarding this for all of them.

How is legislation going to fix this unless you mandate region locking of the internet? The moment a website loads some script from a Chinese site all bets are off from a legislative protection standpoint.

Under GDPR, an EU website owner is responsible for the Chinese scripts they load onto their site, as part of the Controller-Processor relationship. That doesn't help for Chinese companies without a locus of business in the EU, but it covers the hypothetical case that you raised.

In practice, legislation goes into effect globally by being in a large enough market that companies would rather comply than lock themselves out. Several companies have rolled out their GDPR compliance updates globally rather than just to the EU. It's the same reason that lots of products in the US comply with standards that only exist in California.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#59
post #29

Earlier quoted context omitted.

But more enforcement. GDPR enforcement has been disappointing so far.

That's because DPAs understand that if they reinforced GDPR properly then half the companies, particularly small businesses, in Europe would have to be fined. I'm not just talking tech companies either.

All those small businesses mostly have data about subjects they are conducting business with. In general this is a valid reason to have that data and GDPR compliance is merely about implementation details.

The data subjects of ad networks however are completely different entities from their customers, which makes it a very different compliance problem. It might not be possible at all to conduct that kind of business in a compliant way.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#60

Earlier quoted context omitted.

The point is that bid requests may (do) contain both an identifier and data about that person. "Is reading a financial news article" being an attribute of the content, sure, but broadcast such that it can be associated with the person.

That's just how context works. If you visit another site then there would be different categories involved and has nothing to do with the user. There's also no personal identity, it's just a cookie if available, used mostly to frequency cap.

Can't adtech companies associate that cookie with the category and build a profile over multiple pages? Then they can correlate the data and identifiers Google provides to any that they collect on their own (e.g. their own pixels served in the ads that actually get shown). If they connect their own pixel identifiers to data that they buy, then they are building up a decent profile.
Post reply on HN