Live data from Hacker News

GDPR complaint claims Google and IAB ad category lists leak intimate data

techcrunch.com

61–68 of 68 posts

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#61
post #60

Earlier quoted context omitted.

That's just how context works. If you visit another site then there would be different categories involved and has nothing to do with the user. There's also no personal identity, it's just a cookie if available, used mostly to frequency cap.

Can't adtech companies associate that cookie with the category and build a profile over multiple pages? Then they can correlate the data and identifiers Google provides to any that they collect on their own (e.g. their own pixels served in the ads that actually get shown). If they connect their own pixel identifiers to data that they buy, then they are building up a decent profile.

Those profiles would quickly become so broad as to be useless. Context in the moment is the most important thing, which is why even Google shows ads targeted to your actual search query.

Cookies are also not an identity and refreshed very often. Their main use is to cap ad frequency and track conversions over the short-term (hours to days).

Google and Facebook do not provide any personal identifiers. That would be a massive breach of their core 1st party dataset. What little data they did provide is now gone with GDPR.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#62
post #7

We should also be able to access our marketing categories without a Google account, since sensitive data is collected and a profile is built even if you don't have a Google account.

Throwaway of an ex search engineer here. This can’t work because how would google reliably only give you your information without a login account? They are only useful enough in aggregate to google so they can’t know it is only you with 100% certainty until you log in. AFAICT anyone telling you anything else is probably nonsense fearmongering, or maybe doesn’t understand how sophisticated attackers of google are and hasn’t thought through what happens when you have a logged out way of spoofing someone’s internet behavior to get their whole data.

This is effectively a) putting everyone’s approximate search histories on the internet, or b) outlawing google search’s buisiness model.

The consequences of trying option a and failing even once are so great, I argue if that’s your goal you should ban logged out personalization before anyone deludes themselves into thinking they can do it without leaking everyone’s info publically. I also think that’s going to harm consumers more than it actually helps them but I am obviously biased as an ex google search engineer.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#63

Earlier quoted context omitted.

The point is that bid requests may (do) contain both an identifier and data about that person. "Is reading a financial news article" being an attribute of the content, sure, but broadcast such that it can be associated with the person.

That's just how context works. If you visit another site then there would be different categories involved and has nothing to do with the user. There's also no personal identity, it's just a cookie if available, used mostly to frequency cap.

I'm not sure what you mean be "that's just how context works", but perhaps to illustrate the disconnect, it is just as incompatible with GDPR to share the page URL itself, let alone data derived from it like the page category. Doing so is sharing user data in a way that is not consented to.

I don't know what you mean to say about the cookie either, the whole point of this kind of advertisement is to persist associatable data about a person for the lifetime of the cookie.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#64

Earlier quoted context omitted.

That's because DPAs understand that if they reinforced GDPR properly then half the companies, particularly small businesses, in Europe would have to be fined. I'm not just talking tech companies either.

That's also because fining isn't the first step, its pretty much the last. You will have received a warning that you are not compliant and been given a deadline ito fix it in most cases.

Like Google did in France? (receiving a warning before getting fined)

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#65

Earlier quoted context omitted.

That's just how context works. If you visit another site then there would be different categories involved and has nothing to do with the user. There's also no personal identity, it's just a cookie if available, used mostly to frequency cap.

I'm not sure what you mean be "that's just how context works", but perhaps to illustrate the disconnect, it is just as incompatible with GDPR to share the page URL itself, let alone data derived from it like the page category. Doing so is sharing user data in a way that is not consented to. I don't know what you mean to say about the cookie either, the whole point of this kind of advertisement is to persist associata…

Page URL is not personal information, that's a ridiculous overreach and misinterpretation of GDPR.

Cookies are an anonymous identifier, they are specifically not a person. As I said, it's a short-term stable ID used to control the amount of ads shown and track any conversions for campaigns. Adtech companies do not know who you are, only Google and Facebook do.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#66

Earlier quoted context omitted.

I'm not sure what you mean be "that's just how context works", but perhaps to illustrate the disconnect, it is just as incompatible with GDPR to share the page URL itself, let alone data derived from it like the page category. Doing so is sharing user data in a way that is not consented to. I don't know what you mean to say about the cookie either, the whole point of this kind of advertisement is to persist associata…

Page URL is not personal information, that's a ridiculous overreach and misinterpretation of GDPR. Cookies are an anonymous identifier, they are specifically not a person. As I said, it's a short-term stable ID used to control the amount of ads shown and track any conversions for campaigns. Adtech companies do not know who you are, only Google and Facebook do.

You're incorrect, or at least that's what this complaint claims, and I personally have been expecting it for awhile.

The fact that cookies are pseudonymous has 0 effect here -- literally their entire purpose is to be able to associate third party data with a person's browser.

Your contention that all they're used for is frequency capping isn't true either, but even if it was, it's not relevant -- "I'm just using it for frequency capping" isn't acceptable under the GDPR, just as much as "I need the data to do advertising" isn't a reason acceptable under the GDPR for keeping a piece of data in the first place.

Here's the text of the GDPR on cookies: https://gdpr-info.eu/recitals/no-30/

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#67

Earlier quoted context omitted.

The ad categories mentioned in this complaint are the content categories.

I don't mean the "content categories" of the user. If a page on some website is about cars, then you sell that page as being about cars to the advertisers. At no point would you care about the user, just the assumption that a person reading about the latest Toyota might be in the marked for a new car.

That’s literally what this amendment is about. They are talking about the content categories.

Re: GDPR complaint claims Google and IAB ad category lists leak intimate data

#68
post #7

We should also be able to access our marketing categories without a Google account, since sensitive data is collected and a profile is built even if you don't have a Google account.

Throwaway of an ex search engineer here. This can’t work because how would google reliably only give you your information without a login account? They are only useful enough in aggregate to google so they can’t know it is only you with 100% certainty until you log in. AFAICT anyone telling you anything else is probably nonsense fearmongering, or maybe doesn’t understand how sophisticated attackers of google are and…

We don't expect relinked data to be viewable, because that is ripe for exploitation, but we do want to access and control the data that is linked to the advertising cookies that were placed on our devices.
Post reply on HN