Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

61–70 of 82 posts

Re: GDPR and automated email marketing

#62
post #30

Earlier quoted context omitted.

You must not get Azure emails. > We've added new features to Azure! Read this advertisement! > ... > This message from Microsoft is an important part of a program, service, or product that you or your company purchased or participates in. Microsoft respects your privacy. > [Lack of unsubscribe intensifies]

The three dots you omitted actually have this relevant text: To customize what's included in this email, who gets it, or to unsubscribe, set your Message center preferences. If you are receiving this email because your Admin added you as a recipient, please contact your Admin to unsubscribe. Microsoft respects your privacy. To learn more, please read our Privacy Statement.

they dont. Unsuscribe link behind a login wall suck.

Re: GDPR and automated email marketing

#63
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Spammers don’t tend to operate from first-world jurisdictions. (When they do, CAN-SPAM is decent about requiring working unsubscribe buttons). Spam is not a problem you can solve with regulation.

No, that annoys me the most, that I have to go and click the unsubscribe button and wait for the page to load and then click another button. They should have not sent me the email in the first place.

Re: GDPR and automated email marketing

#64
post #57

Unclear regulation? I am encountering this over and over again. Lets clear the unclearity... If you have my data, you will handle them in same manner as you would handle yours. You are not selling yours to get higher prices when buying something online? You are not selling your email account to spammers to get a lot of worthless emails to your email account each day? ... Now you wont do it withy my data either. It is…

I fully agree with you, but there are many technical services/platforms that assume things that are not compatible with that thinking. Those will have to change, but they are still not up to speed.

Let me preface my question with the statement that I mostly love the GDPR, and I think it greatly improves privacy and digital rights and I will exercise some of those rights come May 25:th against companies that I feel have needlessly collected data on me.

That said I (as a data controller) think that in many cases that the guidelines are very weak or undefined on subjects like logs or backups. I (as a private individual) think that any deletion request should automatically apply to logs and backups, but also I (as a data controller and...) as a operator of a service see it as a problem to have backups be mutable and have large swaths of data need to be deleted from backups and logs.

Is there any way to reconcile these ideas?

Re: GDPR and automated email marketing

#65
post #19
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

The good news is there's going to be at least some echo effect here. I work for a US based company, although the vast majority of our users are in Asia. We're implementing GDPR for everyone. It won't affect the companies that exist solely to spam you much, but for most companies the technical issues of ONLY implementing this in the EU are simply too great. So everyone will get at least some benefit. But ya, it'd be g…

I feel like it's also the case for many companies that they'd like to implement GDPR-like tools for users, but as long no one is paying them to do so it's a waste of time. GDPR is a nice excuse to build that functionality and roll it out to all your users.

Re: GDPR and automated email marketing

#66
post #20

Earlier quoted context omitted.

The GDPR won't be implemented for another month and a half.

GDPR is active now. It has been for almost two years. It is just now becoming enforced (with all its sanctions), after the two-year transition period.

Yes, the EU regulation, but the actual laws are not active.

Re: GDPR and automated email marketing

#67
post #30

Earlier quoted context omitted.

The three dots you omitted actually have this relevant text: To customize what's included in this email, who gets it, or to unsubscribe, set your Message center preferences. If you are receiving this email because your Admin added you as a recipient, please contact your Admin to unsubscribe. Microsoft respects your privacy. To learn more, please read our Privacy Statement.

No, they don't. The closest thing is: > Note: As an Azure customer, you are receiving this email because we are required to notify you of product changes that may affect your subscription. This is the only communication that you will receive directly from Microsoft regarding these product changes.

Seems like they're required by law to spam you. Of course they're going to at least use it for something worthwhile at the same time.

Re: GDPR and automated email marketing

#68
post #55

Earlier quoted context omitted.

This regulation is aimed at stopping the hidden checkbox, or the hidden clause in a ToS. All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted. Things like proper confirmed opt-in help.

All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted. It appears that you also need to have been all of those things, as far back as you've been collecting personal data, even if no such requirements existed at the time. Organisations might not be in that position even if they followed accepted good practices when signing people up to t…

That requirment has existed in the EU since 1995.

Re: GDPR and automated email marketing

#69
post #68

Earlier quoted context omitted.

All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted. It appears that you also need to have been all of those things, as far back as you've been collecting personal data, even if no such requirements existed at the time. Organisations might not be in that position even if they followed accepted good practices when signing people up to t…

That requirment has existed in the EU since 1995.

Please stop spreading misinformation. Things are changing with the GDPR.

In particular, the consent requirements are significantly stronger under GDPR than under either the 1995 directive itself (95/46/EC) or the implementations of that directive in various member states.

Organisations that followed reasonable and honest practices at the time of collecting personal data, for example when setting up a mailing list, could still find themselves out of compliance under the new rules.

Re: GDPR and automated email marketing

#70
post #68

Earlier quoted context omitted.

That requirment has existed in the EU since 1995.

Please stop spreading misinformation. Things are changing with the GDPR. In particular, the consent requirements are significantly stronger under GDPR than under either the 1995 directive itself (95/46/EC) or the implementations of that directive in various member states. Organisations that followed reasonable and honest practices at the time of collecting personal data, for example when setting up a mailing list, co…

It has only changed for people who were playing stupid games with what consent means, like interpreting scrolling past an already checked checkbox as consent when it was clearly nothing of the sort. If you were being clear and direct with users about what they were signing up for, then you have nothing to fear from GDPR. I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law.
Post reply on HN