Live data from Hacker News

GDPR enforcer rules that IAB Europe’s consent popups are unlawful

iccl.ie

81–90 of 433 posts

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#81
post #29

Earlier quoted context omitted.

https://globalprivacycontrol.org/ goes kind of in that direction. It's a rebranded Do Not Track header, but referencing specific privacy rights under GDPR/CCPA. That hopefully makes it enforceable, whereas advertisers could just ignore Do Not Track.

I like the idea, but that protocol is too simple. For example, I don't have too much of a problem with Matomo tracking cookies, but I don't want Google Analytics to follow me around the web. This header doesn't specify any of that, and I'd still need to give some kind of consent through a cookie pop-up to websites that want me to use that stuff. I'd rather see a modern version of P3P ( https://en.wikipedia.org/wiki/P…

I see your point, but one of the main problems of P3P was its complexity. There's more than two decades of privacy-enhancing technology research showing that privacy controls need to be fundamentally simple.

I think DNT/GPC can be more fine-grained than you make it out to be. The spec is simple, but there's nothing in there that stops you from developing a browser extension that only sends DNT/GPC signals to a curated list of known bad trackers. That would give you as an advanced user some configurability while it's a simple checkbox for most folks.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#82

Collecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.

Isn't the point you're making already possible with "if no one visits your spyware ridden site, the market has spoken, too bad?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#83

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

This comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is…

> how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable.

If you're not familiar with Northern European culture, I'm quite sure the companies can expect literal inspectors in their offices expecting clear answers to where the data is and what was done with it. They will be pleasant but firm, focused and unswerving. Infractions and evasions will be carefully noted. These notes will then form the basis of further lawsuits. These people are not fucking around.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#84
post #32

Earlier quoted context omitted.

Why kidding?

Because voting doesn’t matter when your choices are corporate stooge A and corporate stooge B.

I always think of South Park. It's always a choice between a giant douche or a turd sandwich.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#85
post #13

Earlier quoted context omitted.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

I want one for "If your business model is advertisement, get off my Internet".

This is a popup I'd be happy to see.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#86

>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.

Well, that's their problem. They must delete the data or face legal consequences. That should act as a deterrent to future "too smart for their own good" ad people.

[deleted]

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#87
post #59
post #32

Earlier quoted context omitted.

Why kidding?

Say you live in a two-party first past the post system. If what you want to express is "I like privacy regulations", the single bit of information that your vote conveys does a very limited job of communicating what issues you actually care about. The signal in traditional voting is very diluted. You vote on a person that you think supports some of the things you care about. You are not allowed to weight in on indivi…

How many EU countries run a "two-party first past the post system" nowadays?

If you are in a first past the post system, and in a safe seat, vote for one of the no-chance-of-winning candidates who best represents your views. Although they won't win, the fact that they are getting votes will be noticed and the main 2 parties will respond by adopting some of their policies. E.g. in the UK as more people vote for the Green party, other parties will become more Green to get those votes back, even though the Green party has only ever got a single MP.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#88
post #13
post #7

Quoted post unavailable.

I wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".

Good news: no special header is necessary, this should be the default as per the GDPR.

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#89
post #62
post #44

Nonsurprisingly, the Interactive Advertising Bureau has a slightly different spin on the ruling [1]: "APD Ruling Clears Way For Work on Developing TCF into a Formal GDPR Code of Conduct". I'm surprised that ICCL very assertively states that all data collected through TCF must be deleted. The Belgian DPA only mentions a €250.000 fine and gives IAB two months to present an action plan [2]. Interesting to see how this p…

The PDF[0] linked to from the original article says this, in "Sanctions" C.533: 2) In application of Article 100, §1, 10° DPA, order IAB Europe to permanently delete all TC Strings and other personal data already processed in the TCF from all its IT systems, files and data carriers, and from the IT systems, files and data carriers of processors contracted by IAB Europe; Page 114. [0] https://www.gegevensbeschermingsa…

Thanks for the pointer! Do we have any idea why the Belgian DPA's press release would skip this part?

Re: GDPR enforcer rules that IAB Europe’s consent popups are unlawful

#90
post #7

Quoted post unavailable.

The industry should really get together and set up something like P3PP but good. These settings should be set in the browser, not in the client. Of course the ad and web stalking people don't want that, because that means users can easily opt out. With Google's misguided attempt to force FLOC down everyone's throats we may see them join forces with Apple, Microsoft and Mozilla at some point to develop a consent proto…

> The industry should really get together and

The industry already got together and decided they are going to ignore GDPR in particular and people's privacy in general.

Post reply on HN