Earlier quoted context omitted.
It is illegal, they cannot offer free but tracked vs paid and untracked service. I guess GDPR enforcement didn't reach them yet.
weird. they are well known in germany
GDPR – No reject option – what to do?
61–70 of 74 posts
Re: GDPR – No reject option – what to do?
#62Checking whether cookie banners are compliant should be mostly straightforward for regulatory bodies. In 90% of cases it’s clear if there’s opt in or not. Why can’t regulatory bodies set up automated flows and tools to handle this at scale? Don’t need to catch every case but they should be able to massively scale the complaints process for this.
Re: GDPR – No reject option – what to do?
#63Earlier quoted context omitted.
DPAs including the German on are quite “business” friendly unless it will be challenged in court. You can’t force someone to provide their business at a loss. As long as you don’t penalize or segregate users based on their decision alone it does not run afoul of GDPR, neither does blocking someone completely you just need to have a valid business reason for doing that and it has to be tied to the nature of the servic…
> You can’t force someone to provide their business at a loss. Of course not. But no one is forced to provide the ad funded service at all.
It’s not upto the DPAs to regulate things at this level just like you could run an astrology service and collect PII to give people readings, astrology is horseshit but you won’t run into issues with GDPR if you request users to give you their birthday and email to get spammed with BS on a daily basis.
Re: GDPR – No reject option – what to do?
#64Earlier quoted context omitted.
That would create a perverse incentive inevitably leading to corruption.
It creates an incentive (to identify entities breaking the law), but I don't see how this is perverse. It's the desired result.
Re: GDPR – No reject option – what to do?
#65Earlier quoted context omitted.
> You can’t force someone to provide their business at a loss. Of course not. But no one is forced to provide the ad funded service at all.
No but it’s a valid business model. It’s not upto the DPAs to regulate things at this level just like you could run an astrology service and collect PII to give people readings, astrology is horseshit but you won’t run into issues with GDPR if you request users to give you their birthday and email to get spammed with BS on a daily basis.
Processing or possibly even keeping a birthdate for an astrology newsletter is clearly a legitiamate interest for the subscriber of that newsletter.
> but it’s a valid business model.
What is? Showing ads to provide a service is a valid business model yes. Showing tracking ads or blocking those who don't accept the ads - no.
But "I need to show the ads to keep the lights on" is NOT a legitimate interest to the visitor. The reason for handling the personal infrmation needs to be a hard requirement to provide service itself. Not merely part of the "business model". You cannot set up a separate service (paid subscription) and argue that because that other service exists, your ad-funded service deserves special exceptions from the GDPR e.g. that it can show ads which are tracked or else users are blocked. It's pretty clear in the regulation that "cookie walls" aren't allowed, just like pre-checked/assumed consent isn't.
Re: GDPR – No reject option – what to do?
#66Earlier quoted context omitted.
No but it’s a valid business model. It’s not upto the DPAs to regulate things at this level just like you could run an astrology service and collect PII to give people readings, astrology is horseshit but you won’t run into issues with GDPR if you request users to give you their birthday and email to get spammed with BS on a daily basis.
> you could run an astrology service and collect PII to give people readings Processing or possibly even keeping a birthdate for an astrology newsletter is clearly a legitiamate interest for the subscriber of that newsletter. > but it’s a valid business model. What is? Showing ads to provide a service is a valid business model yes. Showing tracking ads or blocking those who don't accept the ads - no. But "I need to s…
You can provide users with a binary choice, as long as it’s all or nothing and the free service and paid service are separate it’s acceptable.
Re: GDPR – No reject option – what to do?
#67Earlier quoted context omitted.
> you could run an astrology service and collect PII to give people readings Processing or possibly even keeping a birthdate for an astrology newsletter is clearly a legitiamate interest for the subscriber of that newsletter. > but it’s a valid business model. What is? Showing ads to provide a service is a valid business model yes. Showing tracking ads or blocking those who don't accept the ads - no. But "I need to s…
Legitimate interest as defined in the GDPR isn’t that of the user, it’s that of the business. You can provide users with a binary choice, as long as it’s all or nothing and the free service and paid service are separate it’s acceptable.
Re: GDPR – No reject option – what to do?
#68Earlier quoted context omitted.
It creates an incentive (to identify entities breaking the law), but I don't see how this is perverse. It's the desired result.
The same reason funding police departments on ticket revenues is bad. It incentives overzealous enforcement, where it's not so much about preventing people from breaking the law, but instead figuring out what you can pin on them.
Re: GDPR – No reject option – what to do?
#69Earlier quoted context omitted.
Legitimate interest as defined in the GDPR isn’t that of the user, it’s that of the business. You can provide users with a binary choice, as long as it’s all or nothing and the free service and paid service are separate it’s acceptable.
Legitimate interest can be for anything (user, business, society as a whole) but it's still highly questoinable whether sharing peoples PII for ads alone is a legitimate interest (It's not clear it isn't either - the text is deliberately vague). What's clear is that you can't show people "by entering you accept to". You have to show them an opt out and if they opt out they need to get a service that is as good as if…
I too thought GDPR is much stricter but in reality it’s not. Both the ICO and several continental DPAs including the German one allow for binary choice.
Re: GDPR – No reject option – what to do?
#70Earlier quoted context omitted.
It creates an incentive (to identify entities breaking the law), but I don't see how this is perverse. It's the desired result.
The same reason funding police departments on ticket revenues is bad. It incentives overzealous enforcement, where it's not so much about preventing people from breaking the law, but instead figuring out what you can pin on them.
Police enforcement includes the police powers of arrest and detention.
GDPR enforcement is (I believe) limited to a fine which can be appealed to a court. If the enforcement department turns out to be wasting court time, then there are likely to be significantly negative consequences for that department (at least, more than for the police in the US).
I agree that fine collection is not an ideal way of funding a department, but not all incentives are perverse just because they exist - incentives are allowed to align.