Live data from Hacker News

Study: Google is the biggest beneficiary of the GDPR

cliqz.com

91–100 of 140 posts

Re: Study: Google is the biggest beneficiary of the GDPR

#91

The author of this article didn't bother to read even a summary of the GDPR law. It doesn't matter what the user consents to, you cannot use their personal data ad hoc. You need to justify its collection, storage and transfer to the regulator, not the user. This is in contrast to the ill thought out cookie law where websites could get away with it by irritating consent banners. Sort of like, but not exactly the same…

I bet rafting consent forms are still useful in the sense that they discourage most people with trivial-to-moderate injuries from thinking about holding the company liable.

As someone who leads outdoor trips, I've been told (not sure how true) that one of the supposed benefits is that it informs about dangers. So someone who suffers an injury--not through negligence on the part of the trip leader--would have a tougher case arguing that no one told them that the activity was other than completely safe and they wouldn't have done it had they known.

On the other hand, I've also been told by lawyers that the usual scrawl your signature at the bottom of a paper after a quick glance probably doesn't make much of a difference.

Re: Study: Google is the biggest beneficiary of the GDPR

#92
post #87

Earlier quoted context omitted.

> If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. That's not exactly true either. For the consent to be valid, it must be freely given - that is: 1. The user must have a choice to give consent or not give it 2. The service provided should be the same regardless of #1, unless the consent is necessary for the service (e.g. consent to store address for delivery of goods - a…

That is not true you are confusing single purpose with a “valid” purpose from the users point of view which isn’t actually the case your business needs can be just as a valid reason under the GDPR as anything, you do not have to provide service to users who decline if say it affects your ad revenue the GDPR cannot force you to provide a “free” service to users. Consent is just one lawful basis for data collection, bu…

[deleted]

Re: Study: Google is the biggest beneficiary of the GDPR

#93
post #87

Earlier quoted context omitted.

> If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. That's not exactly true either. For the consent to be valid, it must be freely given - that is: 1. The user must have a choice to give consent or not give it 2. The service provided should be the same regardless of #1, unless the consent is necessary for the service (e.g. consent to store address for delivery of goods - a…

That is not true you are confusing single purpose with a “valid” purpose from the users point of view which isn’t actually the case your business needs can be just as a valid reason under the GDPR as anything, you do not have to provide service to users who decline if say it affects your ad revenue the GDPR cannot force you to provide a “free” service to users. Consent is just one lawful basis for data collection, bu…

The parent was responding to a claim that consent works as a base of processing, and only talking about that base. That other bases can work is true (I'm personally really curious how this is going to play out for ad-financed services), but just because they didn't mention it they aren't "confused" about anything.

Re: Study: Google is the biggest beneficiary of the GDPR

#94
post #75

Earlier quoted context omitted.

>but then those companies should stop using trackers all-together Yes, why do they have to track their users? Why don't use real targeted advertisement instead? If I go to a car forum, car related ads would be relevant for me. Using ML, tracking and profiling to give me ads for the fridge I did buy last week is not relevant

>Using ML, tracking and profiling to give me ads for the fridge I did buy last week is not relevant Come on, that's not what they are trying to do and you know it. There's so many valid arguments you could make, why use a strawman? But the answer to your first question, is because ads targeted to users pay more, get more clicks, and overall perform better than those that are targeted to the page.

patio11 had a great back of the envelope calculation awhile ago on this. Turns out showing ads for a fridge right after you just bought one might be highly successful.

Say the average person buys a fridge once every 10-20 years, the probability you're looking for a fridge this month is something like 1/120-1/240, call it .75 percent.

Some percentage of fridge purchases end up being returned. Let's say 2 percent of them. If you return a fridge, you pretty much are guaranteed to need a new one, so around 2 percent of people that just purchased a fridge are very likely to buy a new one.

That's over double the likelihood of someone that didn't just buy a fridge!

Re: Study: Google is the biggest beneficiary of the GDPR

#95
post #93

Earlier quoted context omitted.

That is not true you are confusing single purpose with a “valid” purpose from the users point of view which isn’t actually the case your business needs can be just as a valid reason under the GDPR as anything, you do not have to provide service to users who decline if say it affects your ad revenue the GDPR cannot force you to provide a “free” service to users. Consent is just one lawful basis for data collection, bu…

The parent was responding to a claim that consent works as a base of processing, and only talking about that base. That other bases can work is true (I'm personally really curious how this is going to play out for ad-financed services), but just because they didn't mention it they aren't "confused" about anything.

The parent is not correct however you can use consent as your lawful basis and deny services to users who do not consent under any business justification as long as you have one.

If targeted ads give you more revenue and you choose to use solely targeted ads because thats your business model GDPR does not forced you to provide a free service or a service that generate less revenue.

So no #2 doesn’t have to be as #1 this is confusing things with the single purpose clause in which case you can’t make X and Y being co dependent.

E.G. while I can perfectly refuse service if you do not accept ads I can’t refuse to sell you something for not wanting to join my mailing list.

Also not only that does nothing stopping you from having multiple bases for consent it’s actually the recommended approach.

Re: Study: Google is the biggest beneficiary of the GDPR

#96
post #55

Yeah, I wouldn't trust this source on anything privacy related. They present themselves as user privacy champions but primarily make money via, you guessed it, advertisements. They are owned by Burda, a large German media organization who, again, make money by advertisement and processing of their user's data. "We’re breaking new grounds when it comes to developing our business model. Bringing together targeting and…

This is also the company that acquired Ghostery.

Re: Study: Google is the biggest beneficiary of the GDPR

#97
post #93

Earlier quoted context omitted.

The parent was responding to a claim that consent works as a base of processing, and only talking about that base. That other bases can work is true (I'm personally really curious how this is going to play out for ad-financed services), but just because they didn't mention it they aren't "confused" about anything.

The parent is not correct however you can use consent as your lawful basis and deny services to users who do not consent under any business justification as long as you have one. If targeted ads give you more revenue and you choose to use solely targeted ads because thats your business model GDPR does not forced you to provide a free service or a service that generate less revenue. So no #2 doesn’t have to be as #1 t…

This goes against what I've seen in regard to consent (generally warnings to not use it unless truly necessary - if you require something put it as legitimate interest or requirement to perform the contract, do not ask for consent since it sets wrong expectations).

Re: Study: Google is the biggest beneficiary of the GDPR

#98
post #93

Earlier quoted context omitted.

The parent was responding to a claim that consent works as a base of processing, and only talking about that base. That other bases can work is true (I'm personally really curious how this is going to play out for ad-financed services), but just because they didn't mention it they aren't "confused" about anything.

The parent is not correct however you can use consent as your lawful basis and deny services to users who do not consent under any business justification as long as you have one. If targeted ads give you more revenue and you choose to use solely targeted ads because thats your business model GDPR does not forced you to provide a free service or a service that generate less revenue. So no #2 doesn’t have to be as #1 t…

Google has introduced non-targeted ads for GDPR compliance. It sounds like a sizeable chunk of the market disagrees with you that you can force the use of data for targeting on users under GDPR.

https://www.marketingdive.com/news/google-will-support-non-t...

Re: Study: Google is the biggest beneficiary of the GDPR

#99
post #97

Earlier quoted context omitted.

The parent is not correct however you can use consent as your lawful basis and deny services to users who do not consent under any business justification as long as you have one. If targeted ads give you more revenue and you choose to use solely targeted ads because thats your business model GDPR does not forced you to provide a free service or a service that generate less revenue. So no #2 doesn’t have to be as #1 t…

This goes against what I've seen in regard to consent (generally warnings to not use it unless truly necessary - if you require something put it as legitimate interest or requirement to perform the contract, do not ask for consent since it sets wrong expectations).

I also don't think consent is the right basis to use all the time (however it's important to note that no lawful basis takes precedence over any other) and good vetted vital interests and a contractual agreement is preferable, however consent is the easy way out.

"This is what we do do you agree: yes/no" is much easier than to develop a valid vital 1st and 3rd party interest for each case and most online services don't require a contract.

However the idea that somehow you have to provide services to people who do not consent is simply false.

That you can't do is tie completely unrelated interests to a single consent for example:

I have a website that shows you local events and allows you to sign up for them, my business model is to sell your contact details to promoters. If you do not consent there is no reason under the GDPR to compel me to provide you with a service that costs me money to run while you refuse to participate in my revenu stream.

What I can't do is say if I run a ticket website to refuse to sell you a ticket if you do not consent to me using the details you've put into in order to purchase them to be sold to promoters or in other words under the GDPR the information collected for the purpose of selling you a ticket cannot be used for another purpose selling your info to promoters.

It's also important to note that in some cases the "I agree" isn't actually used for consent it's just a UX quirk, you can still allow people to opt out even if you don't use consent as the lawful basis for example I can display you the following message:

"I collect the following information: XYZ, and issue the following tracking cookies: ZYX the lawful basis for this is the vital interest of my company and my business partners" I still technically need to give you a way to opt out, so the windows that says opt-out or agree isn't necessarily a consent window from a GDPR point of view.

And as previously mentioned I can deny a service to you if you opt-out because I can't monetize you in which case I can legally redirect you to a page that says you can't access by website until you agree to my terms, in this case again consent is not necessarily a lawful basis rather than you acknowledging the lawful basis i presented under my terms of service.

Re: Study: Google is the biggest beneficiary of the GDPR

#100

Earlier quoted context omitted.

The parent is not correct however you can use consent as your lawful basis and deny services to users who do not consent under any business justification as long as you have one. If targeted ads give you more revenue and you choose to use solely targeted ads because thats your business model GDPR does not forced you to provide a free service or a service that generate less revenue. So no #2 doesn’t have to be as #1 t…

Google has introduced non-targeted ads for GDPR compliance. It sounds like a sizeable chunk of the market disagrees with you that you can force the use of data for targeting on users under GDPR. https://www.marketingdive.com/news/google-will-support-non-t...

A sizeable chunk of the market doesn't disagree with me but rather get something than nothing.

If Google can generate the same ad revenue of close enough to it without having you to force your users to agree or opt-out into oblivion in which case you lose the revenue stream from all users that opt-out.

It's also important to note that Google's non-targeted ads server two functions as they both allow you to display ads to users who did not consent to data collection as well as potentially protects you as an advertiser from ensuring that your ads are delivered in a GDPR compliant manner.

Under the broader interpretation of the GDPR you as an advertiser might be liable if you buy spaces for targeted ads that are displayed unlawfully and this is because GDPR essentially mandates that you must ensure the compliance of your partners.

Post reply on HN