Live data from Hacker News

Google's widespread tracking across the web

simpleanalytics.com

91–100 of 108 posts

Re: Google's widespread tracking across the web

#91

Earlier quoted context omitted.

I'm not pretty sure about that. I get cookie banners from US companies all the time and choose to reject them. Just visited www.vmware.com. Site is located in the US. Company is located in USA, and OneTrust's cookie banner welcomed me, and allows me to make choices.

VMware wants to sell to European clients. If they didn’t they wouldn’t have cookie banners.

Basically, if you have any tracking on your site, you either

a) Show the cookie banners if somebody is coming from a GPDR or GDPR-compliant country, since it's required by EU law and these GPDR-compliant laws.

b) You geofence your site and prevent access.

So, in practice regardless you whether sell anything or not, if your site, proverbially, touches European soil, you have to show these choices.

Re: Google's widespread tracking across the web

#92
post #79

Earlier quoted context omitted.

You mean old timey wimey marketing pre-internet? Just target people instead of Bob at 17th Rosewood St. How about this, I set a preference for some stuff I am interested in and that’s what they can show me.

They don’t track Bob at 17th Rosewood St. They put him into groups of things they think he is likely to buy. Which is close to targeting people.

Multiple groups. And if you take the intersection of those groups you end up on 17th Rosewood St.

Re: Google's widespread tracking across the web

#93
post #87
post #81

Earlier quoted context omitted.

You picked an example at the extreme end, so let me choose another example at the opposite end. Breaking into people's homes and taking their stuff is illegal. It would happen a lot more if there were no laws against it.

You've completely missed the point. I'll break it down. When you break a law, it doesn't magically summon an LEO and judge to catch you in the act and give you the proper penalty, so words in a code is not a deterrent. The deterrent is knowing someone will hunt you down, getting thrown in jail, it's fines that hurt your bottom line. Yes, our society places a premium on policing break ins very harshly. Police have hug…

So you are saying we should not have laws because who is going to enforce them?

Re: Google's widespread tracking across the web

#94

Earlier quoted context omitted.

VMware wants to sell to European clients. If they didn’t they wouldn’t have cookie banners.

Basically, if you have any tracking on your site, you either a) Show the cookie banners if somebody is coming from a GPDR or GDPR-compliant country, since it's required by EU law and these GPDR-compliant laws. b) You geofence your site and prevent access. So, in practice regardless you whether sell anything or not, if your site, proverbially, touches European soil, you have to show these choices.

What’s the EU going to do to you if you don’t have operations in the EU?

Re: Google's widespread tracking across the web

#95
post #93
post #87

Earlier quoted context omitted.

You've completely missed the point. I'll break it down. When you break a law, it doesn't magically summon an LEO and judge to catch you in the act and give you the proper penalty, so words in a code is not a deterrent. The deterrent is knowing someone will hunt you down, getting thrown in jail, it's fines that hurt your bottom line. Yes, our society places a premium on policing break ins very harshly. Police have hug…

So you are saying we should not have laws because who is going to enforce them?

No.

Re: Google's widespread tracking across the web

#97
post #31

> Even in countries with strict laws like the GDPR, Google's trackers are still everywhere. That raises questions about how effective these regulations really are in practice. This is basically it. GDPR is a stupid unenforceable law, and should be wiped from the books. Try again with something new.

It took a while, but is starting to work. Many "cookie banners" have finally started to work in the EU. Once you deny PII processing many sites don't load GA etc... The time of malicious compliance is starting to pass. Some sites have figured it out and realized they really don't need personalized analytics and have replaced implementations with privacy respecting ones(ex, plausible). This lets them remove the dark-p…

Once you deny PII processing many sites don't load GA etc

The way you phrase this is expressly non-compliant with the GDPR, because what you're describing is an opt-out. To be compliant, websites should only load GA etc after you accept PII processing.

Re: Google's widespread tracking across the web

#98
post #84
post #24

User tracking only exists because it generates money. We should ban the entire practice. No more targeted ads (with very little exceptions).

> User tracking only exists because it generates money. 3-letter-agencies.gif

Ironically these agencies buy user information from third parties because it cost less and is legal.

Re: Google's widespread tracking across the web

#99
post #97
post #31

Earlier quoted context omitted.

It took a while, but is starting to work. Many "cookie banners" have finally started to work in the EU. Once you deny PII processing many sites don't load GA etc... The time of malicious compliance is starting to pass. Some sites have figured it out and realized they really don't need personalized analytics and have replaced implementations with privacy respecting ones(ex, plausible). This lets them remove the dark-p…

Once you deny PII processing many sites don't load GA etc The way you phrase this is expressly non-compliant with the GDPR, because what you're describing is an opt-out. To be compliant, websites should only load GA etc after you accept PII processing.

Sorry. They do wait and force a choice before loading the external scripts.

That's the only mechanism one can use to really be compliant as GA (and other providers) stick identifiers onto the session as soon as the script has been loaded.

Re: Google's widespread tracking across the web

#100
post #31

Earlier quoted context omitted.

It took a while, but is starting to work. Many "cookie banners" have finally started to work in the EU. Once you deny PII processing many sites don't load GA etc... The time of malicious compliance is starting to pass. Some sites have figured it out and realized they really don't need personalized analytics and have replaced implementations with privacy respecting ones(ex, plausible). This lets them remove the dark-p…

Enforcing sites not calling out to third party data processors via client-side JavaScript is detectable and enforceable, but taking such actions server-side is undetectable (and therefore unenforceable).

yes, that's a possibility, but we're far from server-side GA implementations and we do have an option to make a data request to figure out what companies are doing.

If they get caught lying (and that tends to happen in the end) that's another violation that is taken seriously nowadays.

For example, my e-mail server started picking up messages from DELETEDmyname@mydomain.org. Making it pretty clear a company did not respect my wishes to completely delete all data and user account references. They simply changed my email in the DB.

Post reply on HN