Why doesn't the main browsers implement some mechanism to help with the notification and consent of cookies? Some standards based description about the cookies/etc. that could be consented. Non-consent means the cookie isn't accepted by the browser.
Certainly with the cookie law, I feel the EU should have legislated the top browser makers to make this a spec and be implemented in the browser, than to rely on each and every website.
GDPR and Google Analytics
71–80 of 130 posts
Re: GDPR and Google Analytics
#72Earlier quoted context omitted.
It being fundamentally incorrect and you not liking it are two very different things.
Yet it is fundamentally incorrect. I'm not an EU citizen, so I have zero reason to care about their laws. I will simply ignore them, and the EU has no recourse, other than possibly mandating that their ISPs block me or something. Which I also do not care about.
Re: GDPR and Google Analytics
#73Earlier quoted context omitted.
A lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.
I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."
Re: GDPR and Google Analytics
#74Earlier quoted context omitted.
Looking at the EUs antitrust fine for Google - https://www.google.ch/amp/s/www.bloomberg.com/amp/news/artic... it's clear it does have the ability. The message is "you want to profit from EU citizens? You follow the rules"
No, you're confused. Google has a physical presence and business partners in Europe; I do not. (Profiting from EU citizens is beside the point.)
Re: GDPR and Google Analytics
#75Earlier quoted context omitted.
I think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."
To which the entirely reasonable response from anyone without a legal nexus in the EU (or physical products to ship) is "we don't care and you have no legal right or ability to enforce that". And the entirely reasonable response from anyone thinking of creating a legal nexus in the EU without an extremely business-critical reason is "let's stay in our own country where it's safer and we only have one jurisdiction to…
The US has forced its laws on other countries in this way for decades, always to protect profits, it's great that now another actor enforces its laws the same way, for the public.
Re: GDPR and Google Analytics
#76Earlier quoted context omitted.
You are anthropomorphizing companies here, and I think it's a pretty poor analogy. Corporations do not have a memory, they have records, and those records comprise the personal data of everyone who encounters them; data those companies don't own. You seem to be characterizing GDPR as unfair towards the corporate end of the interaction, but that ignores the massive power differential that currently exists. Corporation…
>data those companies don't own I don't know if it's possible to have a productive discussion about what seems to be a question of fundamental philosophy and values, but that's ridiculous on its face. If I'm a shop owner and a customer buys something from me, the cash register prints two receipts: one the customer owns, one I own. If a customer writes me an email, I own my copy of that email. If a customer comes in a…
The paper you printed to ban someone from you store falls under Art1, §1, Section f of the GDPR; your interest in keeping that person out of the store outweighs their interest in keeping their details private.
Re: GDPR and Google Analytics
#77Earlier quoted context omitted.
Against small companies with almost no footprint in EU maybe. But against huge multinational corporations that want access to the 500m+ people market they sure can.
Exactly, that's the distinction.
Enforcing laws internationally is easy, considering that there are systems designed to allow the police of one country to freeze the assets of citizen of another country.
You might just wake up one morning with your bank accounts frozen and your credit cards revoked if you violate the GDPR.
Governments have previously seized entire airplanes to pay for a single $500 fee that an airline refused to pay, don't expect it won't happen to you.
Re: GDPR and Google Analytics
#78Earlier quoted context omitted.
Uh? This is already how the world works. It does not matter where you are located as long are you are transacting with EU citizens. In extreme cases of non-compliance, avenues for enforcement that have been discussed reuse existing Anti Money Laundering mechanisms: once flagged in the system, banks will simply freeze your business assets connected to EU countries and you might be arrested upon crossing any EU border.
I have no business assets connected to any EU countries, and I don't have any desire to cross any EU borders. So I will continue to enjoy life in my home country and ignore your provincial laws.
... because laws that enable mass-surveillance are somehow worldly?
Re: GDPR and Google Analytics
#79It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…
Feedback from the trenches: it is a very good thing. Suddenly corporate people are beginning to care about security and privacy: we receive spontaneous inquiries from customers about compliance as well as various questions about password storage policy and proper encryption. Previously the very same people were laughing in our face when we told them passwords must not be stored as plaintext. Whatever the content itself, the message of the GDPR is clear: companies have to care about their users privacy and security, or they'll get a wild kick in the guts.
Re: GDPR and Google Analytics
#80Earlier quoted context omitted.
Imagine you’re living in a country which allows you to sell drugs freely, then it’s clear that you can sell them in a country where they are banned. I don’t really think this is different regarding privacy. You have to obey to the law where you run your business. It’s up to you wether you change your business or leave the market. Your argument that it’s weird that you have to “adhere to their laws” is a fallacy. Your…
While I agree with most of what you said, where my perspective differs is this - The WWW is called the World Wide Web for a reason. A platform to showcase your service globally, without borders. Suddenly, the EU thinks "Oh, if you have a website that is accessible from the EU, then you need to display X". Sorry, then what was the point of WWW? And more important, why should I update my code? It costs me money and you…
I may remind you of the Megaupload case, where a German is under arrest in New Zealand for breaking US law by offering his site to American visitors.
The US has created the precedence for enforcing local law internationally during both the piracy enforcement cases, and the NSA cases.
As result, it is just expected that other countries will use this tool for their own purposes — in this case, the EU is using it even for ghe benefit of the people. Something you can't say about the use the US made of it.