Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

51–60 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#51
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

> All data collected through the TCF must now be deleted

At best the companies will have to delete months of data, the rest being stale or already fed through some ML loop that extracted any useful value from it.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#52
post #4

It was obvious to anyone technical they didn't work as they presented themselves to work, but it takes time for the courts to deal with such things. They are also totally annoying and I suspect there primary purpose was to annoy users and not actually comply with the GDPR. It was a way for these companies to fight the GDPR with a war of attrition. I'm glad you see with this round hasn't worked... Yet. I suspect that…

You are right. I also believe many publishers knew this too but the IAB provides a shield of sorts and buys time when it is inevitably (as in now) ruled illegal.

Most ad-tech, and programatic advertising, is not compatible with GDPR. I think that is intentional on part of the EU - and something I am a fan of personally.

The industry needs to shift - contextual ads or other innovations - others have done this. They refused to self-regulate all these years and had opportunity to move away from their invasive practices.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#53
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

> Which will probably be a nice deterrent against them pulling the same shit again. Unfortunately, there are reasons they want these cookies on there so badly that justify the cost to figure out how to comply with the policy and try again.

> that justify the cost to figure out how to comply with the policy and try again

I wonder if this judgment opens them up to civil suits.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#54
post #41
post #22

Earlier quoted context omitted.

IAB europe had a shared list of vendors and their purposes amongst the ad industry, and everyone's popups using the TCF framework just prompted with the same list because they _might_ be in the ads, not because they'd actually be on the page. Many of the vendors claimed every purpose, often as legitimate interest, regardless of what they actually planned to do and if they _did_ count as legitimate interest.

Also, in loading ads from these vendors, many often included external JS to whatever flavor-of-the-month adtech vendors or trackers they were using. These were often not even listed in the framework. There was little-to-no compliance/auditing that I am aware. It was business as usual for many ad networks.

A former employer in the adtech space did audit that the ads were only including vendors from the list, but I don't know how many of our competitors did the same.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#56
post #29
post #13

Earlier quoted context omitted.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

https://globalprivacycontrol.org/ goes kind of in that direction. It's a rebranded Do Not Track header, but referencing specific privacy rights under GDPR/CCPA. That hopefully makes it enforceable, whereas advertisers could just ignore Do Not Track.

I like the idea, but that protocol is too simple. For example, I don't have too much of a problem with Matomo tracking cookies, but I don't want Google Analytics to follow me around the web.

This header doesn't specify any of that, and I'd still need to give some kind of consent through a cookie pop-up to websites that want me to use that stuff.

I'd rather see a modern version of P3P (https://en.wikipedia.org/wiki/P3P) with UI designed in this decade.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#57
post #13

Earlier quoted context omitted.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

I want one for "If your business model is advertisement, get off my Internet".

Wouldn’t this be easier to implement as a server side header that said “if you don’t like my business model get off my internet”?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#58
post #12
post #5

Finally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok. I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.

Yep, overall I'm really happy with the GDPR. The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. That way we could finally end this farce of the ad-industry's attempts at weaseling their way around the word of the law (and the latest rulings) by designing dark patte…

This is what the DoNotTrack header was designed for, originally.

I guess the big corporations didn't like it and lobbied for the next-worst thing, the cookie popups, hoping that it would become a big failure.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#59
post #32

Earlier quoted context omitted.

Then vote for it! Just kidding.

Why kidding?

Say you live in a two-party first past the post system. If what you want to express is "I like privacy regulations", the single bit of information that your vote conveys does a very limited job of communicating what issues you actually care about.

The signal in traditional voting is very diluted.

You vote on a person that you think supports some of the things you care about. You are not allowed to weight in on individual issues in a way that matters.

The person works for several years, and the only feedback you have on that process, the only tether that holds that person accountable, is whether you vote for them the second time.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#60
post #11

Earlier quoted context omitted.

I wish my government looked out for me like this.

Then vote for it! Just kidding.

I do, as near as I can anyway. My government has been captured by the capital class and will be difficult to recover.
Post reply on HN