Live data from Hacker News

GDPR will pop the adtech bubble

blogs.harvard.edu

61–70 of 454 posts

Re: GDPR will pop the adtech bubble

#61
post #14

From one of the references in the article: The Google consent interface greets site visitors with a request to use data to tailor advertising, with equally prominent “no” and “yes” buttons. If a reader declines to be tracked, he or she sees a notice saying the ads will be less relevant and asking to “agree” or go back to the previous page.

Which is certainly fine with me. I'm always amused that the notion that I will regret not having "relevant" ads. Where "relevant" means more likely to get me to buy things I was not intending to buy.

Ads make sense to me in the age of information scarcity. But now if I need a thing, searching always turns up what I want. If I need to figure out what kind of thing to buy, I can read review at places like The Wirecutter. If I want to keep up with what's new in a field, I can follow experts via Twitter, mailing lists, etc. And if I have a problem I don't know how to solve I can talk to friends or use social media.

Please do give me random ads; they're easier for me to entirely ignore.

Re: GDPR will pop the adtech bubble

#62

Earlier quoted context omitted.

Bunch of strawmen here. > Is it wrong if I sit on my porch and record in a notebook the hair color of different people? If you only count the number of redheads, you are in the clear. If you follow them around, find out where else they go, where they live, how many people live in their household, the household income, etc., you might violate some laws. > Is it wrong if I observe that one of my coworkers has a Harley…

>Bunch of strawmen here. Learn the definition of the words you are using before using them. The only thing this statement shows is you are arguing in bad faith, have no interest in attempting to gain new perspective and simply want to shut my argument down since it doesn't agree with your priors. >If you only count the number of redheads, you are in the clear. If you follow them around, find out where else they go, w…

I'm a bit baffled how you think that recording personal information of people you see from your porch, without even telling them what or why are you doing it, is anything but unethical.

Re: GDPR will pop the adtech bubble

#63
post #31

Earlier quoted context omitted.

Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. Personal data consists of things that identify individuals, but also things that can be used in conjunction with other information to identify individuals. You might not like that, but the regulators are pretty clear on this point.

The ICO does not consider IP addresses personal data since more than one person could use a computer in a household.

That's their position at the moment. GDPR makes it a bit more explicit: if you can combine the IP address with other information to identify a natural person it becomes personal data.

Re: GDPR will pop the adtech bubble

#64

Earlier quoted context omitted.

How is IP and browser personal data ? If you think it is, you should not be on the internet.

Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. Personal data consists of things that identify individuals, but also things that can be used in conjunction with other information to identify individuals. You might not like that, but the regulators are pretty clear on this point.

> Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time.

That's actually the most frightening thing I've heard in a long time. Does the GDPR actually make that connection? If so, it literally links people to an IP address, rather than simply a connection.

If that line is accurate, I'm surprised it hasn't been mentioned before, associating an IP address to an specific person. I have to believe you are wrong, otherwise the legal implications are scary.

For those that don't understand: my concern is that in the US, for a long time, in copyright claims by the RIAA or MPAA, for example, was to go after someone because of an IP address, a common defense was basically: An IP Address is not a person. The above commenter made the claim that an IP address alone can be associate a specific person. So, I'm wondering if 1) that's accurate and 2) what are the ramifications of an IP address being a person in the world of law enforcement?

Re: GDPR will pop the adtech bubble

#65

Earlier quoted context omitted.

> Also can you explain why information that is placed on my server belongs to someone Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? > If someone has access to your laptop and downloads their photos onto it, who do those photos belong to? Rights to creative works, unlike personal da…

>Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? Yes the EU invented a new right for its citizens which is the prerogative of the EU because of their bastardized idea of what constitutes privacy. Privacy is a basic human right, that much is obvious. There is no human right however to…

> The author of a creative work doesn't have the right to force me to delete something from my laptop if I obtained it lawfully.

A valid point - the rights only address the USE of the photos. You can use them privately all you want and would not have to delete them (unless ordered by a court for whatever odd legal reason such as if they were stolen not uploaded).

The difference with personal info is that the lawmakers saw two choices: prevent the use or the keeping of the data. They chose to outlaw the keeping of the data - which is why this law is huge, invasive and clumsy. But it’s also the only reason it makes a difference at all imho. I don’t trust anyone to keep the personal data of millions of people safe.

Re: GDPR will pop the adtech bubble

#66

Earlier quoted context omitted.

> Also can you explain why information that is placed on my server belongs to someone Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? > If someone has access to your laptop and downloads their photos onto it, who do those photos belong to? Rights to creative works, unlike personal da…

>Isn’t this more or less the gist of GDPR and “right to be forgotten” laws? That my personal data doesn’t automatically “belong” to anyone else just because I entered it onto a server? Yes the EU invented a new right for its citizens which is the prerogative of the EU because of their bastardized idea of what constitutes privacy. Privacy is a basic human right, that much is obvious. There is no human right however to…

The author of a creative work doesn't have the right to force me to delete something from my laptop if I obtained it lawfully.

Maybe not technically, but in practice, yes. You may be able to keep them, but you can't actually open and view them. As per MAI Systems Corp. v. Peak Computer, Inc., loading something into RAM counts as copying, so you need a license to do that. And even if you had one once, it can be revoked (not all licenses are non-revokable).

Re: GDPR will pop the adtech bubble

#67
post #31

Earlier quoted context omitted.

Under GDPR guidance, IP addresses are considered personal data because they can be used to identify an individual in a moment in time. Personal data consists of things that identify individuals, but also things that can be used in conjunction with other information to identify individuals. You might not like that, but the regulators are pretty clear on this point.

The ICO does not consider IP addresses personal data since more than one person could use a computer in a household.

That's not true; I can only assume you're reading the 2011-era DPA guidance.

Under GDPR, an IP address must explicitly be considered as personal data, and any processing of them must be written in the documentation of the data processing activities:

https://ico.org.uk/for-organisations/guide-to-the-general-da...

As another commenter has mentioned, this is included in the legislation. There isn't much interpretation to apply here.

Re: GDPR will pop the adtech bubble

#68
> tracking people without their knowledge, approval or a court order is just flat-out wrong.

Requiring them to check an "I agree to be tracked" checkbox and signing an agreement (which has just happened to me yesterday in an EU country in accordance to GDPR) before they can use a product/service is hardly much better. This reminds me of the Android app permission system which requires you to allow an app to do everything it wants (including ridiculous requirements like when a game requires access to your contacts list) or just give up the idea of installing it (as for me I just grant the permissions at the installation time and then block everything redundant with XPrivacy). So I doubt it is going to do much good, a way like the cookie law doesn't really do anything but just introduces useless cookie warning banners.

Re: GDPR will pop the adtech bubble

#69

Earlier quoted context omitted.

If someone has access to your laptop and downloads their photos onto it, who do those photos belong to? Good analogy! They belong to the person who took them, as per copyright law, not to the owner of the laptop.

The author of a creative work doesn't have the right to force me to delete something from my laptop if I obtained it lawfully. If a creator downloads their entire collection onto my laptop I can use that to train my models and target ads as I see fit.

Nope, as I mentioned in my other comment: https://news.ycombinator.com/item?id=17060447

Loading into RAM counts as copying, for which you need a license.

Post reply on HN