GDPR consent design: how granular must adtech opt-ins be?
pagefair.com
pagefair.com
That's the whole point. If you want to keep the whole existing model of many networked partners using all that data for all kinds of interesting purposes, you won't ever be able to explain all that to the users in a manner that somehow motivates them to agree instead of simply choosing not to consent. The question isn't how to get consent for the current practices (which isn't plausible), the question is how to run adtech that doesn't rely on protected personal data.
The cookie thing was poorly drafted, as a result advice on complying with it was poor, and it became something to be worked around rather than a meaningful improvement on privacy and an understanding for the general public of how and why tracking works. I have higher hopes for the GDPR, although I still think it is too much of a compromise, and worry about what that means for accomplishing its intent.
When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
So GDPR does not say its illegal, just that it will be determined on case by case basis.
For legal experts, is this facebook consent obtaining GDPR compliant ?
https://www.facebook.com/legal/terms/update
By using or accessing Facebook Services, you agree that we can collect and use such content and information in accordance with the Data Policy as amended from time to time.
Simply having a term in the general conditions fails the "a clear affirmative act" part.
Saying "use such content" fails the "informed and specific" part - it needs to detail exactly what uses (explicitly listing each) you're consenting to; and it doesn't list the purpose of the use, which is a key part ("When the processing has multiple purposes, consent should be given for all of them")
If facebook has obtained your consent for one (or hundred and one) use-case, it does not mean that it can use it for something else simply by amending ("from time to time") the Data Policy, it would need to get additional explicit, affirmative (opt-in), informed consent to the new processing need of your information.
The first question could be: are you in the EU?
yes -> no access
no -> access, but with tracking
So, basically training users to lie about their location.
Just to be clear - it's about EU citizens, not EU located-people, and your location can change. You have to ask if they're EU citizens.
This feels to me as not a lawyer as something that will only be clear after precedent is set.
I for one don’t want to be a test case.
And dont forget that the next regulation is ePrivacy regulative which might fix workarounds like you are proposing.
The idea of GDPR is about human rights and if you are having a problem with protecting them, than I think GDPR is not a problem, you are.
Most companies just moved the site to their non-eu parts and handled it with internal cost centers. The ones that couldn't do that or that had to show EU sold ads are the ones stuck with the cookie "OK-only" popups.
Showing targeted ads to EU people is only valuable because someone somewhere expects to sell stuff to EU people based on those ads; behavior data about EU people is only valuable because someone somewhere expects to use that data to get money from those people.
The end users (potential buyers) of that data will need to be GDPR compliant, because they'll be trading with EU and thus have a presence in EU - and they will have to show that they got all that data in a compliant manner and had consent for that. All the major advertisers with all their money won't be able to legally buy or use "tainted" data for which they have no GDPR-style consent, so they won't.
So if USAdCo has no presence in EU, and has been "paid with data", then it's been paid in a worthless currency - EU companies won't/can't buy that data, worldwide companies like CocaCola or Netflix or Amazon or other USA companies who have EU customers won't/can't buy that data since they have EU presence and will need to be compliant, and USA companies who don't have EU customers won't buy that data since it's not valuable to them.
What good is all that data if you can't really use or sell it? It's not enough for you to be out of GDPR reach, you also need your main partners to be out of GDPR reach; since if you're trading information that might contain private data, and they want to be compliant, guess what - they'll require you to be compliant as well, since they can't simply say "oh, they sold us that data, it's their problem", they're fully responsible.
The ePrivacy Directive (aka the cookie directive) also required you to be able to opt out. It was pretty explicit, too:
"Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller."
The problem was that some member states cooked up an "implied consent" interpretation, according to which visitors can be assumed to have consented.
The difference between the GDPR (and the new ePrivacy Regulation, which most likely is going to address the issue directly) is that they're regulations; they're directly applicable EU law, not law that has to be transposed into local law by the member states. The EU Commission is also given enforcement powers; and, if I read the upcoming ePrivacy Regulation correctly, can also go after the adtech companies directly rather than the site owners (because ignoring lack of consent is done at the adtech level rather than by site owners, as opposed to a failure of providing a consent mechanism).
I also wouldn't put too much emphasis on the GDPR; while it's likely to cause compliance trouble for adtech companies, the ePrivacy Regulation is more directly applicable.
American companies had a huge unfair advantage compared to their European competition. Now everyone has to deal with the same laws.
And to those who will complain: well, it's your greed and total lack of transparency that prompted EU legislators to actually do something about an issue that concerns their citizens in the firs place.
Now people will have to start delivering value instead of clicks and content will be worth what it's worth rather than the advertising leverage.
This should remove a lot of pointless mind consuming junk as economically not viable.
Maybe legal & product are wrong about the impact GDPR will have - that's certainly a possibility. But if I were a betting man, I wouldn't bet on GDPR upending the industry. If anything, I'd say it's partially seen as an opportunity: we could help other, less-technical customers, become assured that they are GDPR-compliant (while still continuing their - necessary! - digital marketing activity).
At least many of the shady players will be forced out. IMHO that alone will be a boost for general quality of ads.
> we could help other, less-technical customers, become assured that they are GDPR-compliant
I believe that a valid "you are compliant" statement can only be issued in a couple of years once there has been a solid foundation of court judgements which show how the stuff works out in practice.
For example: men receiving women care product ads, or advertising for baby products when I'm single etc.
Even if it's not related to ads, think recommendation sites for books or movies.
Basically this entire thing will at least for a while push us back in the Web 1.0 times. I guess that eventually someone will come with some way to obtain the same results as today (or even better) while completely skirting this regulation.
Edit: Also as all tech regulations, this one also completely ignores the human factor. Bounce rate will increase until people get accustomed to just clicking 'yes' especially if the 'no' button drawbacks are presented in a loss aversion way (imagine big red letters warning about big problems if the 'yes' button is not clicked)
Or maybe the industry will be shaken up so hard that people are forced to think of alternatives to ads. Some cities actually managed to ban billboards, I hope that GDPR will have a similar effect on the Web.
The greed of a couple bad apples has gone so out of hand that the web is basically unusable without adblockers - while I actually work for a creative agency, as a private person I say that the current state is no longer tolerable...
> imagine big red letters warning about big problems if the 'yes' button is not clicked
Oh I assume and hope the regulators will strike down any such measures. They did, for example, also strike out mandatory newsletter acceptances (i.e. those where you could not create an account without "consenting" into handing your data over to advertising).
Adblockers and ads actually are a vicious cycle. Adblockers block ads which then requires more ads to be shown to the people without adblockers in order to recoup revenue which forces those people to install more adblockers.
We are already seeing attempts (from shady sites) to mine cryptocurrency in the background. While this might work on desktop, it is killer for the phones and not very usable.
My best bet is for the Web to find their own model of micropayments with freemium content similar to how mobile games are doing it.
As long as banks make a fortune off of microtransactions despite having no real costs associated with them micropayments in the cent (or, worse, sub-cent) range won't happen. That needs to change.
So as a customer I do think that I rather have no ads at all (if they are ineffective on me) than tailored ones.
Maybe occasionally, but it's not like advertisers are going to completely lose their minds and forget how to target ads. They will just go back to targeting demographics instead of targeting specific people like they do in most forms of media.
I'm not naïve - there definitely will be problems, and various "entrepreneurs" will find creative ways to skirt it. But I am hopeful for a meaningful change for the better.
Let's say you search for cat food on Google, and then in Facebook you see a cat food ad, then how are you going to prove that they traded your data in an underhanded way?
If I were to take a stab at speculating what would happen it would go something like this. Facebook/Google just got a gift wrapped stick to beat both publishers and advertisers over the head with. The data they already collect is already very well groomed, they have tons of resources and savvy and they have enough explicit touch points with users that they can enable the GDPR requirements at the lowest costs and drive business to their platforms in droves, increasing network effects. Expect to see publishers requiring google/facebook logins to see content in the near future.
Second, the big publishers, the ones with content that people really want to see (sports) will be able to get over the high bar of consent fairly easily. They'll be able to leverage that with their other content. Some savvy big publisher is going to figure out how to leverage that into a publisher network. Also, consolidation of the publishers will happen again decreasing the costs to handle this asset, while increasing network effects.
There is room in that new world for some big adtech teams who are savvy enough and have resources enough to collect the data, simply because advertisers are unlikely to want to have to deal with further empowered Facebook/Google/Publisher networks, and at the end of the day advertisers are the ones funding this whole thing. But those adtech teams are going to get better at collecting data, not worse, in order to be viable.
So I'd predict less fragmentation of your personal data. It will be in the hands of less people, but the people that do have it, will have more of it, will be more savvy about its use and value, and will be more powerful than they were before.
So, again, I think you'll see the big guys get bigger and have more data about more people. I think small players and innovative upstarts will be hurt, both in the adtech space (which we may all feel fine losing out on) but also in the content generation space (which troubles me at least).
Personally, I'm not sure where I land on this. Generally speaking, I think anything that gives google more insight into my life is a bad thing and I think GDPR is going to be a disaster when it comes to privacy around what those big companies have on me, but I can see it going the other way. Maybe all that happens is that people move to content based advertising networks and the listicle farms go away. If so it will be a win, but I wouldn't bet on that outcome.
[disclosure] - I work in adtech, and am actively involved in GDPR efforts currently. - These are my thoughts/opinions not my employers.
In my experience, the buzz around this is much more serious compared to previous efforts, "the cookie law" for example, though I have no idea on the actual impact.
In our company, we've decided to implement the necessary changes, because a lot of them just make sense (be clear with the user on tracking, don't store personal data you don't need...). It could turn out to be a competitive advantage, but only if the rules really are enforced.
Otherwise it will be the same as the cookie law, the companies following it had a shittier user experience, and the ones that didn't were never penalized (the cookie law was absurdly bad legislation in my opinion to be clear).
So any insight from the HN crowd would be much appreciated!
The cookie law was an email from compliance with something like. 'Oh, and by the way we need a cookie warning. Please fix it.' GDPR begun with mandatory briefings for all employees (not just IT) a year ago and the projects spawned have been going full steam since then.
So, while I do work in academic environment, I do have contact with people from industry, and they are taking this seriously. (Of topic, this actually created a new business opportunity, for compliance with the GDPR). However, GDPR is not that different from the Directive, if you were compliant with the Directive, chances are, you're probably (mostly) compliant with the GDPR. Yes, the conditions for consent are strengthened, and since now we have a Regulation, it is valid in all countries. There are other differences, and it is more stringent now, but it is not drastically different from the Directive. BTW, this link[1] have a nice overview (I'm completely unaffiliated with that firm, I just like how they structured it...):
[1] https://www.whitecase.com/publications/article/gdpr-handbook...
One thing that people lost sight of, at least in my opinion, that GDPR is not just about punishment, or stopping the processing of personal data, it is also about transparency. People should not be coy/evasive/unclear about what kind of data one is collecting and for which purpose. This is one of the most important things (again, in my opinion). Processing of personal data has a valid and important purpose, and the GDPR is not there to stop it.
And for the question will the GDPR be enforced, I think it will. For the moment, though, all data protection authorities (DPAs) are a bit overloaded, and I suspect that will be the case in the near future. But obviously, EU and EC are taking GDPR quite seriously.
Hope this answers your question.
(Edited for grammar...)
But doesn't that make the GDPR just another "Cookie Law" (albeit with more effort to implement it)? The average person will not reflect on the permissions they give I am afraid. They'll mechanically accept them like they do with EULAs.
I don't think that the GDPR is bad it's just that before launching it they should have made sure that people (especially kids in school) really understand what kind of madness they're currently engaging in.
CTO of a video service platform that caters to webshops here. We take it very seriously; we had discussions with our lawyers about this about 1.5 years ago, and have been preparing our data warehouse in the meantime to be able to fall under the "analytics exempt". On a weekly basis, there is at least one customer whose legal team is asking for some documentation / proof on how we handle this.
We have had a compliance audit, which effectively tested whether
- we were not doing third-party tracking, but only first-party
- all our customers' data is segregated / separated from each other (which effectively means a different database per customer), so that data cannot be combined
Perhaps this is a bit different in the ecommerce space than industry-wide, so YMMV.
Others have a "fuck it" attitude, self-author a 1-page PDF declaring GDPR compliance and documenting the "process", and wait for how the enforcement will pan out in reality.
Most do the absolute bare minimum, hoping to claim "good faith" when (if) shit hits the fan [0].
The funny thing is, the larger enterprises have no idea what data they even have. Or where it is (never mind whether there's PII in it, or if it's compliant, or how to find out). They've acquired smaller companies left and right over the decades, each with their own databases, data shared in the cloud, forgotten backups, archives… A complete mess.
The "discovery cost" for doing things by the book there is significant.
We built some AI-enabled software to help with GDPR discovery (pii-tools.com), and the responses are varied, across the board. It's really interesting to watch the whole field progress and evolve through the imposed chaos.
[0] "Having larger fines is useful but I think fundamentally what I'm saying is it's scaremongering to suggest that we're going to be making early examples of organisations that breach the law or that fining a top whack is going to become the norm. Our office will be more lenient on companies that have shown awareness of the GDPR and tried to implement it, when compared to those that haven't made any effort."
- Elizabeth Denham, UK's information commissioner (in charge of data protection enforcement)If your tool has broader application than PII, you might want to rethink the name. If it doesn't, you might want to rethink your target market.
I agree that the response is varied.
Disclosure: My employer sells tools for unstrctured data discovery and classification.
I know people in the charities sector, and they seem to have taken or are taking pro-active action too - even people close to being "on the ground" have been given introductory training in some instances.
Initially at least fear of enforcement will drive purchasing decisions, it already is doing: you won't sell as much of your solution if you can't slap a "GDPR compliant" sticker on it. It will affect existing contracts less but if your clients haven't started asking about it yet they may do in a mad panic over the next few months. How things go from 2019 onwards will depend on how sharp the teeth end up being and how often/effectively they are applied, but the general feeling I get is that this is not going to be a damp squib or quietly fade away after for first big bang.
Personally, for our kind of business (saas for other companies who uses our software with other companies and organizations), I find this a competitive advantage as well. Well done GDPR -> makes buying easier.
We stopped selling online training in the EU because of it: https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...
I actually love the idea behind GDPR, but as a small company, the cost of compliance (and heaven forbid, responding to an EU inquiry) is just too high relative to the low amount of revenue we get from EU citizens.
I'm looking forward to revisiting that in 2019 as WordPress, WooCommerce, Gravity Forms, etc make it easier to be compliant, but right now there's just no way.
As an EU citizen, I can say your decision is totally understandable, and I sincerely hope that after the dust settles, you'll get your chance again to sell to EU customers. You might have more competitors by then, though - I fully expect that as various companies retreat from European markets and/or shut down the "products which were on the backburner anyway", we'll have local companies popping up to fill the void.
I rather enjoyed http://nocookielaw.com/
Facebook's stance so far can be summarized as "Meh, we don't care, it's you who should comply to local laws, not us".
I really really really which the EU actually delivers on its GDPR promise and hits them with a fine of 4% of global revenue[1]
[1] https://medium.facilelogin.com/understanding-gdpr-9201e13564...
"4% of the annual global turnover or €20 Million (whichever is greater)."
We are somewhat hampered by a large amount of legacy systems (think COBOL on mainframes, in some cases), so we are taking this very seriously, and are fully expecting the EU to wield the full force of their ability to fine, should we be shown to be non-compliant after the deadline. There will probably be a grace period, but we're taking a "better safe than sorry" approach.
As a private citizen, I hope the EU chooses to wield the GDPR Hammer of Doom swiftly and mercilessly against any company found to be noncompliant.
If for example data is stored in an inappropriate way but you've not yet had time to migrate it you will not be fined if you can show how you are working towards correcting the problem.
IANAL and that.
Oh wait, I think I know why.
If I click "off" does that turn it off, or does that turn it on?
And this example is even worse: am I turning on GDPR protection or turning on invasive tracking?
It is required to be off by default, so you'll be turning it on by clicking.
> am I turning on GDPR protection or turning on invasive tracking?
You'll be protected by default unless you explicitly opt-in to tracking.
It's not a good sign when knowledge of data protection law is required to understand the UI.
Just because you don't have a business presence (in the form of an office and employees) doesn't mean you don't have a presence: collecting data from, and making a profit on, users and customers in the EU is a presence. The alternative would be to surrender the obligation to regulate business practice and the protection of citizens to other countries, with no political accountability.
The EU is trying to imposing a huge regulatory burden on companies over which it has no authority. Why do I or any other non-EU company have to put up with this? What happens when the laws in my country conflict with the laws the EU imposes on me from afar?
You don't have to. Just don't do business in the EU / with EU citizens.
> What happens when the laws in my country conflict with the laws the EU imposes on me from afar?
You have a choice - either break the laws or your country, or... just don't do business in the EU.
(I do hope GDPR doesn't affect your company much; it seems to be doing God's good work, unlike most of the companies GDPR is targeted at.)
As for not doing any business with EU citizens this is impossible to comply with even if it was an option as there is no way of knowing if a person is an EU citizen or not.
Besides, this situation only came about because companies did nothing, especially US companies w.r.t. EU data protection laws. It's a bit like the loot box thing, they thought they could get away with it, pushed it too far, and now they're dealing with the backlash of being huge, amoral scumbags.
Anyway this is the sort of argument children use - “john did it too”.
This does not make sense on web.
EU resident streaming a movie from netflix. Is netflix doing business in EU ? Or Is it the customer doing business in USA ? For example, it can be argued that its as if the customer went to USA, bought the dvd.
> For example, it can be argued that its as if the customer went to USA, bought the dvd.
A DVD does not collect your personal information and send them to the producer for processing.
Are you saying if I sell to EU tourists visiting USA, I have to follow EU laws ?
> A DVD does not collect your personal information and send them to the producer for processing.
Thats come after when we determine whos doing business where. Or replace dvd with a survilliance device disguised as a toy.
Yes. Furthermore they have licensed content for this purpose.
If you have zero establishment in EU whatsoever, fines could be taken from all your EU sales revenue (i.e. any funds en route from EU customers to you), and it could be expected that (after they smooth out the process) they also might get a local (e.g. USA) court ruling to enforce that debt on you, there's a lot of international cooperation between the authorities in regards to enforcing trade law. That will take time, though, so until that you're safe unless you want to take money from EU customers or sell the user/advertisement information to EU (or compliant) businesses - in which case, you'll rather want to be compliant.
I suspect that without global jurisdiction we would end up with data laundering jurisdictions, just as we have tax laundering ones today.
And GDPR is not about the laws. It is about crooked people breaking basic human rights for their profit, every normal person should be glad that he has a straight (well almost :) ) directions how to respect and show respect for his customers. The attitude of "you cant force me" is fundamentally wrong.
One more thing, as a non european cityzen, I would be carefully monitor what the sites are doing with basic human rights (as now it will become evident) and protect myself from those who show their disrespect by not using their sites, services etc. Whole world will profit from this legislation and you can bet a lot of other countries will adopt it.
I suspect that has happened before. The tool to resolve these disputes is called diplomacy.
If we think of this as import/export it suddenly becomes more obvious - when importing or exporting physical goods from the EU, you have to follow EU law even if you're a non-national with no say in it.
(The example of US extraterritorialism I have is the other way round: https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd. ; as it says there, "it involved an individual being prosecuted for activities that were fully legal in the country where they occurred")
And why would I block EU ? Connection is intiated by user. So its user importing/exporting data from/to server jurisdiction. Why does not EU force their own citizens to not do business with those companies ?
This line of reasoning didn't work for the poker companies: https://en.wikipedia.org/wiki/United_States_v._Scheinberg
The US very definitely started the idea that it has global jurisdiction over the internet; why should it be the only such country?
Do you think it is fine for countries to apply their laws as they want on people outside of their country? What would happen if Fiji (just picking a random country here) applied a 10% income tax on all citizens of the EU. Would you think this was reasonable?
Anyway it is not the data collection, or even removing data that I don’t even collect that I am concerned about, but the the EU applying its laws on me even though I am not in the EU and have no connection with the EU beyond visiting the place a few times.
It's a joke that the same government will go ahead and collect info for "protect the public from terrorists" purposes, yet try to constrain a company outside of their jurisdiction from collecting simmilar information with no real mechanism of enforcement.
People really think these technologies are just going to crawl in a ditch somewhere because some eurocrats (and those who've accepted the bread and circus they provide to the public) want to put pen to paper and act as if these are laws of phyisics... next we'll hear madates that all companies around the world must offer affordable privacy in a can™ for the EU chattel.
The more deep packet inspection/filtering of non complient sites, the more resilient the web will become, so I look forward to the continued escalation.