Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

91–100 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#91
GDPR was known to be, is known to be, and will known to be a shit law that's not tied to reality. It did have some good (allowing you to know what they have on you in general, and asking them to delete some of that), but the rest is just bad, bad, bad.

I wish people would be rational when supporting privacy increasing things. GDPR could have been much better and it saddens me that it was ruined, and defended by, zealots.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#92
post #71

Earlier quoted context omitted.

cookieEnabled is not reliable for handling third-party cookies, unless you also load a third-party frame running JS. (And even then it doesn't work like you'd want in many browsers.)

Sorry if I missed something, but AFAIK grandparent wasn't talking about third party cookies, only about having cookies disabled and being unable to store the consent flag, so I don't see how this applies to this specific discussion.

It does. Most people concerned about the GDPR are concerned about third-party cookie tracking.

It also highlights how, in general, this is a hard problem. Compliance with this law without creating a dead-static page has subtle complications.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#93
post #9
post #2

We care about your privacy notices have become the bane of my life.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

> The majority of these aren't actually compliant

There is insufficient evidence attempting to comply with GDPR is worth the cost.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#94
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

That's actually a good idea. It's really frustrating how (in other types of news) a lot of buzz can be generated and then just silence and we forget it all and move on. But it's not really something that would sell well. Not many people care about yesterday's news, people want to know what's coming next and not what came out of some magazine's prediction several years ago.

Since we're talking about ideas for news services: I would love to be able to get a list of the most important news in a month or a year. Not a top 10 list but simply a way to try to catch up if you miss a few months.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#95
post #75

Earlier quoted context omitted.

> We're going to nag you until you click this button so we can't get in trouble for profiting off the data you give us. That is explicitly against the regulation. Consent should be freely given otherwise it's invalid. The problem is that there is no enforcement around this (despite it being very easy to detect this behavior at scale by running a web scraper) so they keep doing it and profiting off it.

> Consent should be freely given otherwise it's invalid. I tried to figure out what this actually means but it's very hazy. A naggy news website isn't performing a contract. Are they provisioning a service (assuming you did not buy or order or subscribe to anything)? "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the prov…

For starters, it simply means that if declining consent is harder/more annoying than accepting then it's already in breach, regardless of anything else.

If your website takes 1 click to accept tracking but several clicks to deny it then you're already in breach (assuming the law was actually enforced, which it isn't at the moment).

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#96

Earlier quoted context omitted.

>Don't stalk people The problem is there is no consistent definition of stalking in this context. Which could be the difference between a store manager watching how people move around a store vs following you home and going through your trash.

Stalking is collecting any information, that either by itself or combined with other information can be used to identify someone with reasonable probability. IP addresses, browser/device details (fingerprinting, etc), usage patterns can fall into this category.

By that definition, literally everybody in real life is stalking me just by seeing what I look like. That's not a terribly useful or reasonable distinction.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#97

Earlier quoted context omitted.

Providing the service assumes staying in business, no?

Not for this regulation. Business considerations do not matter, only technical ones.

The true hallmark of an ill-conceived law.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#98
post #49
post #6

I work as a developer in the European public sector, we already took privacy and security rather serious because the laws governing it had always been and are still tougher than the GDPR. I actually like that the EU is doing something, and I guess this is the best you get from a bureaucracy, but what it’s changed is that we document everything. Whenever I build anything that moves privacy data, even if it’s just hook…

There is a privacy benefit to adding friction to spreading personal data around everywhere. At the margin, some services will decide not to bother processing non-essential personal data just to avoid the paperwork. And really, that's one of the excesses that GDPR was a reaction to: that the "default" was "track everything in case the data magically becomes valuable," and now the it's become "perhaps not."

A lot of GDPR can be summarized as "GDPR makes PII into high-grade radioactive waste. You want the least of it, and take care of the remaining bits you end up with"

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#99
post #79

Earlier quoted context omitted.

Providing the service assumes staying in business, no?

No, there's no protection for failed business models, as there should not be.

The business model of Google isn't a failed business model.

What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the former.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#100
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.

Absolutely, given the current lack of enforcement. However, if you're going to be in breach, you might as well improve UX and not bother with the whole "consent management" thing, not to mention that the TrustArc garbage solution doesn't seem cheap.
Post reply on HN