Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

71–80 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#71
post #31

Earlier quoted context omitted.

> I wish there was an HTTP header that meant "I don't give a shit about what you do with my data, just let me get the information I want from this website". I'm OK with that as long as there is an equivalent HTTP header which means "NO! Do not track anything, do not profile, do not collect any information besides the bare minimum PROVEN to be essential for the site to function at all. Either something's truly essenti…

> I'm OK with that as long as there is an equivalent HTTP header which means "NO! Do not track anything". Why is there a condition attached to this? If I communicate clearly to Google that they should track me as much as they want and hide all popups from me, say by sending them a notarized letter, what legitimate interest do you have at this point to interfere? Given how much of my time and wellbeing has been wasted…

> Why is there a condition attached to this?

Because the law explicitly wants to avoid companies being able to annoy people into doing this, and thus requires to make the opposite action equally possible and easy.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#72
post #11

Earlier quoted context omitted.

I wish my government looked out for me like this.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

This is not really accurate.

The enforcement of GDPR is still up to national civil services/judiciaries, in this case it was a cooperation of multiple national protection authorities.

Even the legislation itself necessarily involved national governments and national civil servants in national ministries

GDPR being an EU level legislation has more to do with the absolute nightmare it would be for the internal market to have 27 different standards and the drastically lower leverage available for enforcement than disinterest in the subject

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#73
post #13

Earlier quoted context omitted.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

Business pepe works just say the minimum is name, email address, etc. is the minimum in that case... And if you don't provide it, the site won't work

that can be challenged in court though.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#74
post #10

Those popups did teach one good thing: when you see "legitimate interest" you know you're about to get scammed.

Indeed. Then again, I'm pleasantly surprised by those rare web sites that, even when using some standard "consent" dialog, default the legitimate consent bit to objected. Thanks for not scamming me, I guess...

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#75
We designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's when behavior that's bad for your users and bad for the world become a silently absorbed into your corporate praxis.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#76
post #12

Earlier quoted context omitted.

Yep, overall I'm really happy with the GDPR. The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. That way we could finally end this farce of the ad-industry's attempts at weaseling their way around the word of the law (and the latest rulings) by designing dark patte…

In general, I agree that it would be nice. Not sure what the right way to legislate that would be, but I'm sure there are ways. However, if DNT/GPC (which can signal opt out but not much else) becomes legally binding (as they very well might, with DSA), that'd be a huge win for me personally, because I don't see my self ever consenting, and reading consent dialogs isn't worth my time. As I understand it, GPC is alrea…

No need for that if they just complied with GDPR.

Consent must be given consciously in informed way - therefore NOTHING can be pre-checked by any dialog to make it comply with GDPR.

They just need to somehow ban dark patters, or standardize the dialog. To be honest, just one high profile case that interprets dark pattern as 'uninformed consent'(therefore not legal under GDPR) would be enough.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#77
post #64

Earlier quoted context omitted.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

There's a bit of that. But I think a big part of the reason is that national governments can not address international issues. The EU represents 300M people, and has the economic and political weight to make a dent. The same goes for other international issues, such as climate change, corporate tax evasion, cyber crime, etc.

445 million people.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#78
post #11

Earlier quoted context omitted.

I wish my government looked out for me like this.

The scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out…

> Our national elected governments are not interested in actually fixing things like this

Data protection laws existed before GDPR. GDPR itself is not that different from Swedish data protection laws, for example.

Everyone ignored them for years (in case of French laws, for decades, apparently). So, the next step is to pass and enforce the law through the EU.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#79

Earlier quoted context omitted.

Isn't this already possible with uBlock and just configuring it to not allow you to go to sites that have any trackers at all?

Does it also scrub those sites from search results?

Depending on the search engine you use, you can figure that manually, yes.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#80

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

You can enforce it by feeding a system with data, then checking if the data is in the system (e.g. by trying to buy the data, or pretending to be an advertiser).
Post reply on HN