Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

71–80 of 82 posts

Re: GDPR and automated email marketing

#71

Earlier quoted context omitted.

Please stop spreading misinformation. Things are changing with the GDPR. In particular, the consent requirements are significantly stronger under GDPR than under either the 1995 directive itself (95/46/EC) or the implementations of that directive in various member states. Organisations that followed reasonable and honest practices at the time of collecting personal data, for example when setting up a mailing list, co…

It has only changed for people who were playing stupid games with what consent means, like interpreting scrolling past an already checked checkbox as consent when it was clearly nothing of the sort. If you were being clear and direct with users about what they were signing up for, then you have nothing to fear from GDPR. I don't have any sympathy for business who were complying with the letter of the law while findin…

I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law.

Neither do I. It's the organisations who were complying with the letter of the law, the spirit of the law, and generally accepted good practices at the time and still won't be compliant under GDPR that I'm worried about.

As a concrete example, every single charity that I support regularly has written to me at some point over the past few months, in order to get the kind of explicit consent they apparently believe they need to continue communicating with their supporters exactly as they have been for years before.

Now, there are really only two possibilities here. One is that all of those charities have this wrong, despite their resources and surely having taken professional legal advice on their particular situations. The other is that the usual HN suspects who maintain that the GDPR isn't a big deal and doesn't change much in practice are underestimating the concerns the GDPR raises for these legitimate organisations wanting to send legitimate communications to people who have previously been happy to receive them.

Since those exercises mean my donations are being wasted on red tape instead of their intended purposes like literally helping to cure cancer, I think it's fair that I have a problem with that.

Re: GDPR and automated email marketing

#72

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Short of quizzing the user, you can't prove that they understood. But our lawyers and compliance officers seem to think it's enough to make it so that a decision not to understand is intentionally made by the user. Like T&Cs, everybody knows that most people don't read them. Nobody's going to start quizzing their user, so what's a reasonable compromise? Forcing the user to at least scroll through some (or all) of it…

I would really like to see that challenged in a court. A company cannot reasonably expect their users to read and understand tens or hundreds of pages of T&C legalize. No one reads them. That's the fact.

Re: GDPR and automated email marketing

#73

Earlier quoted context omitted.

It has only changed for people who were playing stupid games with what consent means, like interpreting scrolling past an already checked checkbox as consent when it was clearly nothing of the sort. If you were being clear and direct with users about what they were signing up for, then you have nothing to fear from GDPR. I don't have any sympathy for business who were complying with the letter of the law while findin…

I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law. Neither do I. It's the organisations who were complying with the letter of the law, the spirit of the law, and generally accepted good practices at the time and still won't be compliant under GDPR that I'm worried about. As a concrete example, every single charity…

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally. If they had been following the spirit of the law instead of just what they could get away with, then they would have gotten affirmative consent previously. They are not immune from committing bad marketing behavior just because they are charities.

Re: GDPR and automated email marketing

#74

Earlier quoted context omitted.

I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law. Neither do I. It's the organisations who were complying with the letter of the law, the spirit of the law, and generally accepted good practices at the time and still won't be compliant under GDPR that I'm worried about. As a concrete example, every single charity…

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally. If they had been following the spirit of the law instead of just what they could get away with, then they would have gotten affirmative consent previously. They are not immune from committing bad marketing behavior just because they are charities.

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally.

But equally, you're leaving out the possibility that charities really were clear and honest about what they would like to send and really did provide a genuine choice, yet would fall foul of one of the technical requirements under GDPR that wasn't in force at the time. This is probably the case for most if not all of the charities I support myself, so absent evidence to the contrary I have to assume it was widespread practice.

People keep talking about the "spirit of the law", but there's a danger that this becomes a euphemism for "what I wish the law had said, even though it didn't". Usually when people contrast the spirit of the law with the letter of the law, they are making a point about avoiding the obvious purpose of legislation by relying on legal technicalities or subtle implications that most people wouldn't pick up.

In this sort of case, I don't see how it's against even the spirit of previous data protection law if a charity clearly and honestly stated that it would like to send information to donors about how their money was being used, which probably many donors would indeed like to receive, but for example they checked the box by default. There was an explicit provision for businesses to send marketing mail to previous customers or prospects without requiring consent at all, as long as it related to products or services similar to what the recipient had been interested in before and as long as some reasonable requirements about opting out were met, so clearly this isn't some absurd idea just dreamed up by charity fundraisers.

Re: GDPR and automated email marketing

#75

Earlier quoted context omitted.

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally. If they had been following the spirit of the law instead of just what they could get away with, then they would have gotten affirmative consent previously. They are not immune from committing bad marketing behavior just because they are charities.

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally. But equally, you're leaving out the possibility that charities really were clear and honest about what they would like to send and really did provide a genuine choice, yet would fall foul of one of the technical requirements under GDPR that wasn't in force at the time. This is probabl…

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it. People who did that knew what they were doing. I don't have any sympathy that they now have to go back and ask for real consent.

Re: GDPR and automated email marketing

#76

Earlier quoted context omitted.

You're leaving out the possibility that the charities, like most other marketers, didn't bother to get affirmative consent originally. But equally, you're leaving out the possibility that charities really were clear and honest about what they would like to send and really did provide a genuine choice, yet would fall foul of one of the technical requirements under GDPR that wasn't in force at the time. This is probabl…

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it. People who did that knew what they were doing. I don't have any sympathy that they now have to go back and ask for real consent.

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it.

There was no trickery involved. Not even slightly, not in even one case where I was choosing to be a supporter. The indications of what would or wouldn't be sent were invariably perfectly clear, and the only things that ever have been sent were in line with what was stated.

Again, "dark pattern" is too often used as a euphemism for "something I don't like". If you have a genuine option that is clearly shown, that's not a dark pattern. And if most of the people filling in the form are going to choose to turn on that option, I fail to see how having it turned on as the default is unreasonable either.

We're not talking about something presented deceptively in the middle of a long and complicated page full of other options to add some unwanted but chargeable extra on your holiday booking here. We're talking about charities doing important work wanting to show their supporters that the money they're donating is making a difference, and showing an immediately clear and readily understood option that is part of a short, simple form for supporters to fill in. They did ask for real consent. You just don't like how they did it, and I'm not sure why your personal opinion should outweigh widely established practice that was doing no real harm.

Re: GDPR and automated email marketing

#77

Earlier quoted context omitted.

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it. People who did that knew what they were doing. I don't have any sympathy that they now have to go back and ask for real consent.

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it. There was no trickery involved. Not even slightly, not in even one case where I was choosing to be a supporter. The indications of what would or wouldn't be sent were invariably perfectly clear, and the only things that ever have been sent were in line with what was stated. Again, "dark pattern" is…

It is well established that checking the box by default results in much, much higher conversion rates than leaving it unchecked. That clearly indicates that people are not really making a decision to consent when they leave it checked. That is exactly why the practice was disallowed by GDPR.

Re: GDPR and automated email marketing

#78
post #57

Unclear regulation? I am encountering this over and over again. Lets clear the unclearity... If you have my data, you will handle them in same manner as you would handle yours. You are not selling yours to get higher prices when buying something online? You are not selling your email account to spammers to get a lot of worthless emails to your email account each day? ... Now you wont do it withy my data either. It is…

I fully agree with you, but there are many technical services/platforms that assume things that are not compatible with that thinking. Those will have to change, but they are still not up to speed. Let me preface my question with the statement that I mostly love the GDPR, and I think it greatly improves privacy and digital rights and I will exercise some of those rights come May 25:th against companies that I feel ha…

Sorry for late reply. For old data, the easyest way is to burn the tapes and make new backups. Now about new backups, here it becomes nasty as typically they aren't organized granulary enough (but you also need this for exporting the data on user request, so you just need to do it). Instead of backuping the whole databases, backup each users data separately, maybe database partitioning, table inheritance (postgres) or something else, hard to be specific here. Once you did that, backup the data by encrypting them with random key (long enough, we are using 32 bytes of random garbage) for each user while storing those keys on simply modifiable storage, cloud, whatever in triplets. Once the user requests data deletition, just destroy the key. We did it this way and it is great solution (and we DID burn the tapes literaly, luckly we have business data separated physically from everything else from the start).

Logs are destroyed each week and the customer will be notified. Also we anonymize ips and reverse lookups by hashing them, while we still can identify the same visitor.

I hope I was helpful :)

Re: GDPR and automated email marketing

#79

Earlier quoted context omitted.

Checking the box by default is a dark pattern designed explicitly to trick people into signing up without realizing it. There was no trickery involved. Not even slightly, not in even one case where I was choosing to be a supporter. The indications of what would or wouldn't be sent were invariably perfectly clear, and the only things that ever have been sent were in line with what was stated. Again, "dark pattern" is…

It is well established that checking the box by default results in much, much higher conversion rates than leaving it unchecked. That clearly indicates that people are not really making a decision to consent when they leave it checked. That is exactly why the practice was disallowed by GDPR.

Maybe so, but that was still standard practice. If there was nothing deceptive or misleading about how the choice was presented, and if it genuinely was a choice that someone could easily turn off if that was their preference, I think it's quite a stretch to attach labels like "dark pattern" or claim that organisations weren't "following the spirit of the law".

There are going to be organisations wasting time and money on reconfirmation exercises for mailing lists they've been building up for a long time because despite using double opt-ins, only sending relevant messages to people who genuinely want to receive them, and providing readily accessible options to opt out again, they didn't record exactly what the wording said on their web site on 13 April 2008 when someone signed up to that list.

Clearly the GDPR sets out different requirements now, but my original comment stands: things are changing, and this is going to introduce significant burdens even on a lot of organisations that were following reasonable and honest practices when they collected personal data before.

Re: GDPR and automated email marketing

#80

Earlier quoted context omitted.

It has only changed for people who were playing stupid games with what consent means, like interpreting scrolling past an already checked checkbox as consent when it was clearly nothing of the sort. If you were being clear and direct with users about what they were signing up for, then you have nothing to fear from GDPR. I don't have any sympathy for business who were complying with the letter of the law while findin…

I don't have any sympathy for business who were complying with the letter of the law while finding any excuse they could to subvert the spirit of the law. Neither do I. It's the organisations who were complying with the letter of the law, the spirit of the law, and generally accepted good practices at the time and still won't be compliant under GDPR that I'm worried about. As a concrete example, every single charity…

It's interesting that you mention charities, because as we know in the UK many of them were breaking the law and there has been considerable regulatory action to bring them back into compliance with the existing PECR and DPA.

The fact that they're all contacting people saying "We need to re-gain permission under GDPR" just means that a bunch of organisations were, and still are, clueless about data protection. This, combined with the lack of fines, should be somewhat reassuring to the GDPR sceptics. The laws are widely broken; the regulator hasn't been seeking fines; this is unlikely to change in future under GDPR.

Post reply on HN