Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

61–70 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#61
Coming up next: Full page with mandatory reading (through eye scanning which will require camera access with popup consent for camera access). Followed by a 10 Quizzes to test your understanding for what you consented for. Then an email/ID verification to confirm your identity and consent.

This is going to be fun.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#62
post #44

Nonsurprisingly, the Interactive Advertising Bureau has a slightly different spin on the ruling [1]: "APD Ruling Clears Way For Work on Developing TCF into a Formal GDPR Code of Conduct". I'm surprised that ICCL very assertively states that all data collected through TCF must be deleted. The Belgian DPA only mentions a €250.000 fine and gives IAB two months to present an action plan [2]. Interesting to see how this p…

The PDF[0] linked to from the original article says this, in "Sanctions" C.533:

2) In application of Article 100, §1, 10° DPA, order IAB Europe to permanently delete all TC Strings and other personal data already processed in the TCF from all its IT systems, files and data carriers, and from the IT systems, files and data carriers of processors contracted by IAB Europe;

Page 114.

[0] https://www.gegevensbeschermingsautoriteit.be/publications/b...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#63
post #4

It was obvious to anyone technical they didn't work as they presented themselves to work, but it takes time for the courts to deal with such things. They are also totally annoying and I suspect there primary purpose was to annoy users and not actually comply with the GDPR. It was a way for these companies to fight the GDPR with a war of attrition. I'm glad you see with this round hasn't worked... Yet. I suspect that…

> Instead I predict another round of pseudo compliance and a more annoying user experience. Eventually they'll start a policy campaign in earnest stating that the GDPR is unworkable.

I predict all of this to fail, at considerable expense for the IAB and its clients. The GDPR is popular amongst us EU residents.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#64
post #11

Earlier quoted context omitted.

I wish my government looked out for me like this.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

There's a bit of that. But I think a big part of the reason is that national governments can not address international issues.

The EU represents 300M people, and has the economic and political weight to make a dent.

The same goes for other international issues, such as climate change, corporate tax evasion, cyber crime, etc.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#65

Earlier quoted context omitted.

I want one for "If your business model is advertisement, get off my Internet".

Isn't this already possible with uBlock and just configuring it to not allow you to go to sites that have any trackers at all?

Does it also scrub those sites from search results?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#66

Collecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.

> Collecting and selling digital data is not a legitimate business enterprise.

According to who, you?

> It’s spyware.

How is it spying when the people are freely giving away their data?

> If no one wants to pay for your product, the market has spoken. Too bad.

Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data?

> We must correct the insanity and digital economic imbalance that spyware businesses have created.

Fair enough, but that entails not creating or fostering an imbalance by constantly providing the internet with your personal information.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#67
post #31
post #7

Quoted post unavailable.

> I wish there was an HTTP header that meant "I don't give a shit about what you do with my data, just let me get the information I want from this website". I'm OK with that as long as there is an equivalent HTTP header which means "NO! Do not track anything, do not profile, do not collect any information besides the bare minimum PROVEN to be essential for the site to function at all. Either something's truly essenti…

> I'm OK with that as long as there is an equivalent HTTP header which means "NO! Do not track anything".

Why is there a condition attached to this? If I communicate clearly to Google that they should track me as much as they want and hide all popups from me, say by sending them a notarized letter, what legitimate interest do you have at this point to interfere?

Given how much of my time and wellbeing has been wasted the last couple of years with those popups, my instinctive reaction to this phrasing is honestly that the GDPR-fanboy faction would be well punished if they had to continue to deal with them for the rest of their earthly lives.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#68
I don't understand the findings. The TCF system doesn't collect personal information. The spec is at [0]. CMPs are the popups responsible for creating the TCF string. The IAB provides a spec for how these should operate, but does not supply one of its own. These can absolutely misbehave, and the IAB has previously notified the adtech industry about known misbehaving CMPs.

[0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#69
post #6

My favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them…

It's also extremely important that companies can't insulate themselves from consequences by outsourcing compliance functions to a "designated villain".

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#70

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

How is anything enforced? I don't see this as much different from anything else that companies have to apply with. You can never reach 100% certainty that anyone complies with the law. Be it GDPR, work environment law, product health req, etc.

You do inspections. You demand proves of compliance, and when said proves are deemed inadequate you sanction them until something adequate is provided.

Like everything else with law its fuzzy and ongoing.

Post reply on HN