Publishers Haven't Realized How Big a Deal GDPR Is
baekdal.com
baekdal.com
For a recent project I read (and translated to plain english) [1] every single article in the GDPR legislation and for our purposes it can be summed up as:
"Treat user data like names and emails as if they were credit card numbers"
AKA: be paranoid about keeping them, encrypt them, use SSL on your site, respond to requests from people if they ask if you have them, fix them if they're wrong, don't use them if they say you can't.
Obviously that's not the entirety of it, but as a working mental model I think it goes a long way.
1 - https://blog.varonis.com/gdpr-requirements-list-in-plain-eng...
The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the data even without explicitly given consent – according to GDPR in that case the user can reasonably expect the data to be necessary to provide the service. (This does not apply to sensitive personal data and biometric/genetic data – then you always need consent.)
Quoting GDPR:
"Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement." [1]
"Consent is presumed not to be freely given [...] if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance." [2]
[1] https://gdpr-info.eu/recitals/no-32/ [2] https://gdpr-info.eu/recitals/no-43/
IANAL.
This is more nuanced than it appears, as it is balanced against the firm's right to conduct business.
If you're generating leads by providing a whitepaper, then realistically you're not going to be penalised for saying "you need to consent to receive our newsletter to access this whitepaper".
On the other hand, an airline saying "you can only book a flight on our plane by consenting to us sharing everything we know about you with loads of third parties" would be frowned upon.
Our GDPR lawyer at least has advised not to ask for consent, since it is difficult to establish whether it was given, and has not been withdrawn. It's easier to rely on legitimate business use and NOT ask for consent, as long as it genuinely falls into that category.
Can such publisher claim that collecting data is strictly necessary to provide the service? With threefold difference in ad revenue, that could be actually the case.
* it must be reasonable from the user's perspective
* there must be alternative; you cannot achieve the goal (your "legitimate interest") without it
* it must be balanced with the rights of the user, and not infringe on their freedom or fundamental rights
* if your "legitimate interest" is direct marketing, the user can always object, and you are required to actively inform the user of this right
See also [1]
If you can provide a service strictly devoid of the PII it means there is no logical necessity for PII.
You can't provide a call-waiting service without a phone number, but you can provide a mail-redirection service without one even though it makes it easier to administer when you have a customer phone number, you can strictly provide (and bill/administer) the service when that information is absent.
you mean just create a checkbox somewhere that people click without thinking about it?
I have no idea what I am consenting to when I "agree" to all the EULAs.
Most sites' approach to credit card numbers is to not touch them with a barge pole, have a third party receive them instead and never let the business have any sight of them, so it's a bit of a stretch to expect the same treatment for a customer's name and email address.
Most sites are incapable of receiving, storing and handling credit card numbers. This is because the staff building the service either lacks the technical knowhow or the organizational wherewithal to deal with the problem in a successful way.
Why should it be any different for emails, names, usernames or passwords (because end users re-use those).
If everyone starts acting like this data is important (it is) and valuable (it is and that might decrease with the passage of this law) - we might just get to a better place. In the absence of regulation companies will get away with whatever they can - ethics be dammed.
Would filtering out EU IP ranges be sufficient, or does this also apply to EU citizens traveling outside of the EU?
The referenced page says that asking users to provide a birth date isn't sufficient proof that they're over 16 years of age, how should one verify age for something like an IRC bot?
---- begin quote ----
(1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
(2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
---- end quote ----
Based on this, it looks like for GDPR to apply to an establishment in regard to a particular person, at least one of those two parties must be in the Union. An EU citizen traveling outside the Union dealing with an establishment that is not in the Union appears to not be covered.
Are Dutch citizens in Oklahoma protected by Dutch narcotics laws? Of course not. They are subject to the jurisdiction in which they are physically present.
However, a US citizen can be subject to US laws overseas, however, that’s between the American and the US government — the intermediary country has no involvement unless it’s an extradition request.
This idea that EU citizens are protected worldwide is just ridiculous. EU jurisdiction doesn’t extend beyond the EU. The idea that GDPR requests have to be honored by some local ecommerce company in Idaho is just nonsense and not supported by any international legal precedent.
I used to think protectionism was stupid, but after seeing how The Great Firewall[1] is working out for China and their services, I’m not so sure anymore. The big problem with any inbound restrictions is retaliation, but if you can manage to make a country restrict exports themseleves, well, yes please!
I’m looking forward to seeing EU competitors flourish.
[1] Since visiting China I’m convinced TGF is about protectionism as much as it is about filtering. Internet to any non-China service is terrible and unreliable. The result is simply you can’t depend on it, so you choose a Chinese provider. This has clearly worked out very well for some of their companies!
Could you please block my IP address as well: 192.117.111.61
If you feel that being responsible with my personal information and metadata is not worth the trouble, then I don't want to accidentally ever use whatever service you maintain. Thanks.
That doesn’t mean that sites that haven’t gone to the expensive lengths required under it are going to expose or abuse your data. If you are this big of a fan of the GDPR, I imagine that you’ll have to limit your Internet browsing only to sites run by EU-based companies that are large enough to afford scores of attorneys to advise them on how to comply.
Ignore Europe if you like. Just be aware that you are allowing your competitors to gain an uncontested foothold without having to fight for it. Once they are the incumbent in the European market, they will be hard to unseat, even if you change your mind later.
It was useless in the sense it was trying to play nice. It was a gentle call for the industry to self-regulate. The only problem with that law was how naïve it was.
Go ahead and block the whole European IP range. See if we care.
And then everyone put it up "just in case" or "because the law says all cookies". (Of course some smart people figured out that local storage is not a cookie and the law only covers cookies, atleast what they gather from hearsay instead of checking the actual text)
But tbh, I'd prefer US services IP blocking European users. It'll encourage EU startups to fill the gap and they will have the privacy regulation of the EU as marketing bullet point over any US company, eg "In the US privacy is a pinky-promise, for us privacy is law".
This privacy thing is, like, their option, man. Even if you and I agree with the EU.
A lot of us who admire what the EU has the courage to do - and wish that the US had half that courage - would rather disappear from everything but European websites. What many US corporates have done, and are doing, is rotten to the core. It is demonstrably destroying the internet that so many of us spent time bringing to life, and had so much hope for.
I suspect that if someone with some balls and power suggested corraling all US trackers and data brokers - along with companies trying to turn the net into a shopping mall - into a single domain outside of which they could not operate - most Americans would applaud. The EU has done some of what it could, and cheers to them for having the courage to serve their citizens. Wish I was among them.
So EU traffic means nothing to any of the above example sites, yet all of them will be massively exposed under the GDPR. If I ran a web hosting company, I’d offer EU IP blocking as an optional, free service.
You need to have new procedures for obtaining, storing, using, and delete customer data. This is known as a "code of conduct". You need sufficient logging to aid incident analysis too.
I also think a lot of companies are entering a bit of panic mode because there is no clear guideline on what is sensitive data. If you make a booking system, then everything you store is potentially sensitive if you have end user data in it. If you're making IoT devices for the home with cloud access, then you have sensitive data.
The conclusion we've reached is fairly simple. If there a even a remote chance that normal day to day use of our systems contains data that can be used to build a profile of a user, then the systems data is considered sensitive.
https://gdpr-info.eu/recitals/no-30/
which includes IP addresses and seems to extend to things like email addresses and usernames.
How this will end up affecting functionality and implementations of online services is not yet clear, at least to me.
Could you make it a git repo so we can field alterations, additions and discussion?
If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this. So it's hard to imagine how many readers of HN are getting their answers on HN (or similar). If you are small time nobody is going to come after you. Sure something could happen and you could also get a traffic ticket going 57 in a 55 zone and a host of other outlier events.
> AKA: be paranoid about keeping them, encrypt them, use SSL on your site, respond to requests from people if they ask if you have them, fix them if they're wrong, don't use them if they say you can't.
One size fits all advice doesn't make sense in this and in other similar cases. You will spend a great deal of time and effort dealing with 'maybe's' instead of the day to day.
You'd be surprised. GDPR is vague enough and just open to interpretation enough that there are many different companies interpreting it in many different ways. I'm a consultant and I talk to many multi-nationals and all of them have their own spin on it. Especially around the "except when necessary for security purposes" section. That right there is broad enough that "security purposes" can mean almost anything as long as you make sure your security team has access to that data.
Either way, you shouldn’t be doing it out of fear. You should be complying for practical business reason
1. This is how you should be treating personal data. 2. In exchange for complying with GDPR, you get access to a market of >700m people. If you’re a service provider, it’s illegal for any EU business to be your customer without GDPR compliance.
The EU and politcians are anti UX, they have no clue about the effect of their laws on people.
Fixed that for you.
Usually commas aren't important, but that specific sentence really suffers in readability without it.
No, it will basically make a newsmedia site unprofitable. I think it is the EU that has not fully thought this through. Most of the news industry is already sickly, financially, and they mostly have no model other than advertising (with a very few exceptions). The reason all this data got collected, was to try to make the advertising valuable enough that they could sell it. It may be that it never really worked, but it sure won't work without it. I think either the EU will backtrack on this once they see that Google and Facebook can easily force people to consent (because people consider those websites too valuable to do without), but most other advertising-supported media cannot; or they will see that the long-term impact of this is that it accelerates the current death spiral of newsmedia, as all ad spending goes to Google and Facebook and almost no one else.
I leave it as an open question as to whether this would be a good or bad thing.
We have publicly funded broadcasters in most EU countries. The ad-supported news sites, on the other hand, are generally doing more harm than good.
News outlets existed before the web, so they're not going to be threatened by breaking the ad-supported website model. If anything, the traditional newspapers will be saved by this, because if free online news disappears, people will start buying newspaper subscriptions again.
> I think either the EU will backtrack on this once they see that Google and Facebook can easily force people to consent
They can't. The consent has to be for a specific purpose.
You may be happy with the state sponsored options now, but will that always be the case? Would you feel the same if you living in the Soviet Union or Germany circa 1940?
I trust state paid media in the EU, way more than any US news media.
The reason why most EU countries have state paid media, is so that its non commercial, non partisan, and cant be bought. There are different principles in place, so government has no say, in what is broadcast/not broadcast. This also means that all political parties get the same amount of exposure etc.
I’m currently more concerned about private media having an agenda that promotes the right.
To get the most ad revenue they need to cater to the majority. See e.g. clickbait. For stable income, finding a group and catering to their opinions/narratives is also an option, and is also not independent news. See e.g. infowars. Finally, to get any ad revenue, they need ads. Unlikely many corporations will run ads on anything that is perceived even slightly controversial nowadays. See e.g. YouTube.
None EU media would still exist.
Several UK media outlets use paywalls already, presumably they too would remain.
Strong emphasis that I'm not equating those to your examples. Rather, pointing out that even a subtle version of undesirable or extreme politics can lead to a similar concern.
Given the wild political swing going on in about half of Europe, it's a legitimate concern today, no need to look back 80 years. Not to mention persistently growing censorship and criminalization of speech in more liberal countries such as France.
They will thrive even more :(.
Fun fact: oligarchs in Greece have been doing this to their own country for financial gain for decades. Most Greek newspapers are mouthpieces for the interests of the great families.
We're also seeing very concerning trends in the readerships and profitability of print media (because of the Web, many think). So I don't think you can use the "News outlets existed before the web" line, without much more justification.
Why is it "very concerning" (assuming no financial interests) that a legacy form of media is struggly to dominate in terms of profitability?
That would be a terrible dependency for eastern europe, you wouldn't want putin-friendly government media teaching people what to vote next.
Why am I not surprised that a European is saying that the government-backed "broadcaster" are all so good, and evil private American new sites are bad.
this pretty much sums up the real agenda behind GDPR.
It would be better to call the bluff of these EUrocrats and see what they'll really do. Other countries can retaliate.
You are not surprised because you have a gigantic filter in your head that turns everything into exactly what you already expect regardless of what it is. The second part of that sentence makes it quite clear what your mindset is.
Nowhere in that comment I can find a reference to American (evil) news sites. There are more than enough private news sites based in Europe, so I wonder why you are so hell-bent on making this an EU vs US thing. Most EU residents will read news in their own language (which in most cases isn't English).
Every time the EU implements some law or regulation regarding control of personal data and privacy, someone (an American) has to dismiss all the problems those laws are intended to address entirely, and go on to post some defensive, nationalist spiel about it being an attack on US companies.
Perhaps the problem is that these companies make their money in an incredibly unethical way that an increasing number of people are very uncomfortable with?
Stop turning this into something it isn't. All you are doing is poisoning the debate.
Personally I'd live to have most media completely in the dark about visitors to solely speculate on the quality of their own content. Only metric they need is daily visitor count. Everything else can be shaped by type and quality of content. A great example is HN where we have a very targeted audience due to the content it serves. It obviously also has some sponsored articles but also the indirect benefits it has on new startups and so on. Just treat it as TV marketing and not a per person customized monetization strategy.
As someone who works in media: I'm sorry, what? Publishing is certainly not more lucrative than ever, and publishing online now is a far worse business than publishing a physical newspaper pre-cable TV. The proliferation of outlets is due to lower barriers to entry and less need for capex. Plus a little bit of VC optimism.
Everybody seems to be joining the race to the bottom by delivering more questionable content for 2 more clicks per day instead of relevant articles and real journalism. Also not to step on anyones toes, this obviously doesn't apply to every individual, however a large majority seems to be doing it. This also makes it hard for the good guys to prevail I guess.
Why do you think so? I don't see clickbait industry seriously affected. They churn out a ton of crappy content which costs almost nothing to produce (at least if compared with reputable journalistic work), monetize it with low quality ads for shitty CPM rates, but as long as part of their content goes viral, tons and tons of pageviews allow to balance everything.
GDPR changes nothing in this business.
GDPR in my mind influences this indirectly in the long run. It's not like it will kill fake news the week after.
The most simplest solution is that newspapers host the ad on their own server as a .png or .jpg that gets shown to all visitors. It's tracking free and GDPR compliant.
None of the hundreds of suppliers we use are truly ready, and how would they be? It took 45 years to build this tech, you can’t just replace the innards in a few years. Estonia is the only country that is close to ready, and that’s mostly because they’ve build their entire system with a focus on sharing and securing data. Nobody else has anything close to it.
It’ll be interesting to see how this plays out in the courts. I mean, keeping privacy data safe should be an important concern, but do we really want to close hospitals and schools because we can’t afford to pay the fines when it fails?
To add to this, the quote paints complying with the legislation as a simple redesign. It would require much more than a redesign. The technical, administrative and legal costs of implementing the new system from scratch would be magnitudes higher than implementing the current system from scratch. And add on changing requirements as the legislation is in its infancy.
Let's face it, despite social media being a great enabler for realtime news the quality of news is sub-par. The biggest bane of social media is the transfer of responsibility of filtering real news from a firehose of fake news, to the end user. Until that issue is solved people are going to probably pay for news. This is just my speculation of how things might go after GDPR.
What makes privacy-sensible internet newsmedia nonviable might very well be the much more profitable spying on the client. If regulation makes that competition illegal, and demand for news is unaffected by GDPR (and why wouldn't it be), then it becomes more difficult for advertising companies to find newsmedia that provide tht extra illegal profit-taking sugar, so they will go back to more traditional advertising plans. This, in turn, will make newsmedia's lives easier in regards to finding advertiser's that do not demand spying on their readers.
At the end, sellers still need to advertise, providing ads supply, and readers still demand free newsreading, providing ad demand. The market still exists.
> No, it will basically make a newsmedia site unprofitable.
Good. We don't need that much "news" anyway. And I think my need would be more than covered by national TV which is sponsored by taxpayers money and BBC, which also has no advertising.
There really won't be much of the value lost if we won't have sensationalized and invented news any more.Another point to consider is that need for news or just for some brain filler: I am puzzled by appareant inability of many today to be alone and in silence. As if then some thought that they cannot be comfortable with start to be loud enough to be heard.
The "we" is where you have a problem.
Is there any evidence for this at all?
Telling a person "if you install this they'll stop tracking you in some abstract way" is way less effective than "install this and you wont have to wait to watch youtube videos."
Exactly the reason I installed an ad blocker. If YouTube had released their Red subscription in the UK I might never have installed the blocker (actually probably would have eventually, but later than I did)
uBlock origin is 2nd and rising in popularity and it blocks trackers by default.
Both they (and others) depend upon the EasyList collection of urls/regexes, etc. to block out sites and includes
An example of this mindset: http://www.zdnet.com/article/how-to-speed-up-browsing-by-usi...
In fact, I want to white list certain websites (a dozen or so) to continue seeing ads, but I don’t want to because I know that they are likely using Google for their ads and I don’t want Google’s little grabbling hands tracking me.
For users I deal with, I do it as a preventive measure - I worry about phishing/spearphishing and other email vectored attacks, compromised websites, and the risk of a compromised ad network where even if something malicious is killed in minutes it could still reach tens of thousands of people.
And I still get AV alerts at least a couple times a month where the AV has blocked access to something that's recognizably part of a remote access scam.
No, outside of a few echo chambers, no one cares about privacy or knows what GDPR is. Until GDPR shows everyday on the evening news for weeks it will not be well-known, and there are many things more important to most people than online privacy. Heck, Cambridge Analytica was only a scandal because the "bad guy won".
I think we've crossed that point few months ago in Europe. Last year I felt I was probably the only one of my real-life friends who even knew what GDPR was. These days, I see streams of articles about it on social media, aimed at non-technical people. Hell, last week my SO told me she started receiving GDPR-related e-mails at work from companies that are in business with her place.
I feel people do know. Unfortunately, I also fear they only think of it as yet another random EU regulation thing, and not realize the benefits it'll bring.
Not only do the site owners not even know that the site contains these things, if they do, they don't even realize the extent of data collection going on. I had a chat this morning with an owner like that. The site runs GA (they didn't know), the site runs ShareAholic (which they said wouldn't be a problem as they only use it to see in aggregate where their site visitors come from).
They never made a distinction between what data their site provides to these services through scripts or cookies, and what they themselves then get/use through the service provider.
This is not a special case. There are probably millions of these little business sites out there.
Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases.
a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store.
b. Additionally, please advise me in which countries my personal data is stored, or accessible from....
c. Please provide me with a copy of, or access to, my personal data that you have or are processing.
2. Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data.
3. Please provide a list of all third parties with whom you have (or may have) shared my personal data.
Then, once you've replied, they can request deletion of any or all of that.
[1] https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
If you send that letter, expect to receive a standard response/report of data with a form response that politely & legally amounts to “piss off”.
Large organizations have considerable resources set aside to make sure their “piss off” letter is legally defensible & GDPR compliant.
That letter is likely only a problem when selectively used by a malicious actor against a small organization. Frankly not the kind of org that is systematically tracking personal data.
Which is what is so annoying and economically destructive about regulations like these that are broadly applied to all companies, especially on the internet where single person companies are very popular. They are designed in a vindictive way against large companies like Facebook or major online retailers who burned customera due to minimal information security investment.
But they so often ignore the reality of the burden it places on small firms who account for 90% of businesses and 50% of employment, who cant afford lawyers or the legal risks of a 'piss off' letter.
The western economic environment countinually gets more and more structured favouring large firms, encouraging large scale merging, which usually generates the type of large oligopoly companies who most often does the things that cause regulations to get created, then imposed on smaller firms.
If Japan's economy is any indication we do not want to state heavy economy where big companies are the only sanctioned winners and smaller companies are heavily disincentived by the state (whether indirectly, by side effect, or overtly).
If not having these laws created isnt an option (seemingly impossible in an administrative heavy org like EU), I then hope someday these regulation start being structures like progressive income tax using size minimums or are contained to specific industries where it's clearly a problem (both of which would apply well to minimum wage laws for example). So laws are pinned directly to a specific problem area justifying the heavy-handed state intervention, not just blanket laws on everyone.
Basically you need to make sure you 100% know what data you collect (including any third parties) and make sure you have a good reason to collect it.
Honestly most of GDPR should be considered "common sense". It's just that many corporations actively act against the interest of individuals they collect data on, and it's precisely these practices that GDPR tries to correct.
This is where socialism differs from communism - in socialism you have big privately owned companies, whereas in communism these are state owned. Everything else is more or less the same. Europe is currently under transition from group of mostly free mostly capitalist countries into full retard socialist authoritarian regime. Regardless of that, GDPR is a very good thing, shame it has only been introduced now and not 10 years ago.
These rights include:
* the right to be informed about what data is processed
* the right to access all data gathered about them
* the right to rectification of incorrect data
* the right to receive an export of the data in a common format
* the right to object, to have all data removed, and to restrict processing until further notice
GDPR also requires a data controller to respond within a month, and not charge any fee for this unless the requests are excessive (because they are repetitive). [2]
In that sense it’s a great way to rattle someone without specific GDPR guidance. But all things being equal, the large orgs that are capable of systematic data collection, are not at all troubled by it & certainly won’t be answering it with direct point by point answers.
What's the process for authenticating who sent the letter? Seems like a potential new attack vector.
"Authentication" for this is provided by harsh penalties on signature forgeries. Also, you'd only get one single data point and everything really sensitive has address data and they will* send their response to a known address.
ok -- hidden in their database -- (date_deleted = now()) fixed.
This line severely damages the credibility of the article. I found the article interesting up until I read it. I stopped reading once I read it because I couldn't trust anything else the author says.
I highly doubt this statement is true. It may be true in very privacy-focused circles and amongst some circles of IT professionals, but I highly doubt it is true for the population.
If you make a statement this left-field, you've got to back that up with credible research and I highly doubt that statement was based on any credible research.
If you are an asshole that's trying to get as much data off your users in order to resell them to the highest bidder, share it with "partners" (partners in crime that is), or to advertise/spam them with shit they don't need, then frankly you (or your industry) asked for this themselves.
The only downside I see to GDPR is that we've now opened the gates for a new breed of "GDPR consultant" that's gonna charge hundreds an hour just to rehash what the law says in a slightly different way and defraud businesses that way by pretending to be a valuable service (and no doubt there will be clueless execs that'll actually believe it and pay for that).
Remembering laws that haven’t worked as intended, and failing to recall anything particular about these lawmakers, I find your stance optimistic.
Are you hoping that nobody notices that you aren’t complying?
You just do what google does and ask for consent before providing access to the site. The user doesn’t need to log in to consent. Once consented, the site can set a cookie. Then that user becomes part of your “Full interaction users” bucket.
As long as you have a valid reason to collect the data for the benefit of the user experience, you can make that a requirement to use the site.
It's not fun seeing a popup on every site you visit. This should have been a brower-based implementation globally that every site must adhere to.
Even worse for me, I browse exclusively in private/incognito mode and this is going to make that unusable with consent popups on sites on every visit.
This. if EU actually cared enough, they 'd go to the browser vendors to enforce some basic prompts on tracking and forms, and it would be better than gdpr because it would work for everyone from day 1. This law will bring a few more prompts and not much else (because most services can be provided with slight changes like hashed ips).
Cookie prompts on every site you visit on your slow-ass phone connection are really really annoying and should go away. But americans don't protest about them because they don't see them and europeans are , well, sheepish.
How to do that in a satisfactory manner... leading practices might take a few months to crystalize.
I’m pretty sure the reason for this is that they know that the day they switch over to GDPR compliance, their ad revenue from EU will take a nosedive, and they don’t want to throw away that revenue for the sake of being early.
That is one weird claim. Let's count "one-time user" as someone completely anonymous -- no cookie, no login name, nothing. Let's say someone browsing in incognito mode from the freshly installed PC.
By definition publisher has no personal data about this person, so GDPR doesn't apply here, IMHO, and it's quite fair. Why can't publisher load some 3rd party tool?
Why can't I load some 3rd party tools?
What author is claiming, essentially, that in a mere 2 month from now, you can sue almost any European publisher for data privacy breach. Outrageous claim require outrageous proof.
You can, you just need assurance that they're also GDPR compliant if you want to be GDPR compliant.
If the third-party violates GDPR, but requires your website to run on (e.g. third-party JS, other types of beacons), I think judges are going to have a dim view on that, and so you can't simply claim that it's them, not you. (There may be mitigations, e.g. if you have a contract with them that spells out GDPR compliance, but then they break that - but how many people have contracts for the JS they embed?)
Edit: One way this argument could be laid out is that by including such third-parties in your website, you're instructing the browser to load them, and therefore effectively forwarding GDPR-related data to them. Technically, this isn't really too different from a REST API call you'd perform on the server, or an AJAX call (although the server call doesn't necessarily forward e.g. the IP).
Seems like it's machine-identifying information. You can't tie it to a real-world name and email (which the top voted comment claims is the essence of GDPR).
The GDPR definition of personal data is VERY broad, and it explicitly includes things like:
* name, email, date of birth, etc (probably no surprise here)
* any user behaviour (what you look at, what you click on)
* uploaded content (what you write, your uploaded avatar etc)
* ip addresses, device ids
* beliefs, ethnicity, sexuality, health data (additional restrictions apply here)
* biometric data, genetic data (additional restrictions apply here)
Not sure that really accomplishes the intent... seems like it'll just be an annoyance to all non-cookied users.
Nobody seems to care that government organizations sit outside of regulation and tell us we need to regulate everyone else. It's simply a power play.
Government organisations don't sit outside of regulations. The regulations are designed around their needs and they make sure their regulatory needs are met.
For ex. you can track anon visitors fine if you generate an ID identifiable ONLY on your DB. So if you store only an ID in the DB(awaiting to be matched when a conversion is made with consent given) is totally fine because even if someone hacks your DB can't be able to match that ID to any person, even if they have other data from Facebook, Google etc.
In case of an IP it's a different thing. If you get an IP, you can actually identify a person if you have a DB with the IP+other personal information about it.
a little exaggerated for fun here https://www.brandexpublishing.co.uk/the-new-procedure-for-ex...
[1] See definition of personal data: https://ico.org.uk/for-organisations/guide-to-the-general-da...
Given the whole Cambridge Analytica thing this seems good.
A good example for this is the Cookie under GDPR. The original plan was for both the GDPR and the ePrivacy Regulation [2] (not to be confused with the ePrivacy Direcive) to come into effect on 25 May 2018. The ePrivacy Regulation would have had given the justification for using analytics Cookies without consent. Now that ePrivacy Regulation is delayed some argue that national laws can provide that justification until we have a EU-Regulation.
[1]
>In order for processing to be lawful, personal data should be processed on the basis of the consent of the data subject concerned or some other legitimate basis, laid down by law, either in this Regulation or in other Union or Member State law [..]
http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=146243980...
[2] https://en.wikipedia.org/wiki/EPrivacy_Regulation_(European_...
No, it's the other way around.
I don't have an overview of all steps required but provided you do this then GA should still be allowed to be used without explicit user permission.
https://support.google.com/analytics/answer/2763052?hl=en
Of course, that doesn't stop that IP address becoming aware to the GA servers, but they should stop it being used further down the line.
I suspect it's similar to using a CDN where the IP address again is passed to a third party.
The original plan was for both the GDPR and the ePrivacy Regulation [1] (not to be confused with the ePrivacy Direcive) to come into effect on 25 May 2018. The ePrivacy Regulation would have had a special exemption for analytics cookies. If that would have been enough to not require consent for Google Analytics I do not know.
Now the ePrivacy Regulation is delayed but the GDPR is not. I didn't find a lot of information about what that means for the time after 25 May 2018. The following is from German sources (primarily e-recht24.de [2]) and is only from a German perspective.
Google's terms [3] in accordance with German law currently require consent in the case of AdSense but not for Google Analytics. According to [2] this is in obvious conflict with current EU law but the EU Commission denies that.
e-recht24.de [2] is careful to avoid a clear statement about the situation after 25 May but from my understanding they hint that the situation will not change. German law is already in conflict with EU law and this fact is ignored by all parties. The GDPR will not change that situation.
[1] https://en.wikipedia.org/wiki/EPrivacy_Regulation_(European_...
[2] https://www.e-recht24.de/artikel/datenschutz/8451-hinweispfl...
[3] https://www.google.com/about/company/user-consent-policy.htm...
One of the caveats though, is that you shouldn't be able to identify a specific user. So, you would need to anonymize the IP addresses you're tracking [1]. My understanding is that you should not be tracking or storing information that can be used to identify a single user. So cookies are ok, but you have to ask permission for any cookie that can be used to personally identify a user.
[1] https://developers.google.com/analytics/devguides/collection...
For example we use Auth0 for our authentication service. Auth0 doesn't support storing everything. So we use the auth0 user id in a db table, which contains some user preferences.
Does that mean i need to get consent from the user to use their user id? In our database even though they are paying for this service, and we are paying for their auth0 user account?
Also if someone were to submit a GDPR request, how am i supposed to verify this person is who they claim to be?
That said, GDPR is ridiculous and in many countries, contradictory. This leads to litigation spaghetti code. It will be exploited in ways we can't yet imagine.
It is dangerous to assume GDPR applies to YOU if you are based in the US. As the world (thankfully) doesn't operate under a one-world government, let the EU live in their ignorant "This site contains cookies" world.
About time too, I really really hope this has an incredible profound impact on privacy and the EU will demonstrate this is a law people _must_ abide by.
Such sweeping laws require a lot of thought and debate. It is unfair to say, “hey they had 2yrs so it is their problem”. We need to do better than, “must abide by law” and push for just and fair laws.
Omg. Yes. This is better than the stuff in my wildest dreams.
Fining people for bad opsec is a tremendous idea!
Obviously, as with every law in Turkey, the enforcement is very subjective (for example, Twitter does not respond to most requests and nothing goes wrong for them. But say, if you're a non-Twitter scale website, you deny a couple requests or probably only one and you're getting blocked), and you might be able to get away with the "we don't store them/store them anonymized because GDPR" defence once.
Yes there' a 'justice' loophole in GDPR but I don't think "we're still saving the IP addresses anyway in case a court requests it" argument would fly. In the end, to be perfectly legal in both jurisdictions, you'll probably need to differentiate based on IP address ranges or something.
GDPR does have specific exemptions for holding/processing data per legal requirements.
E.g. an analytics product does not have to collect IPs. I've seen one company in the field requiring customers to explicitly mark form fields as safe for tracking the contents of in session replay (so they don't accidentally end up with your customer addresses, while still allowing you to see how far people went with the signup process, which product options they had selected), ...
Wouldn't Google be the data-controller in that case?
Google might still be allowed to do the personal tracking if they ever obtained consent from that user. Another reason why the AMP caching is bad for the web, I guess.
And from the user's perspective AMP articles would become even more appealing because they would never be bothered with consent popups.
Sadly, I feel this will hurt the ones without a proper IT force the most.
Give the user complete access to the raw data and give them the opportunity to delete all records of that data if they choose to.
one nice problem that popped up is we have mysql tables that can’t handle the delete traffic fast enough. gdpr is not a project you want to leave till the last few weeks
And yes, many IP addresses can be linked to a specific person. I don't doubt that, by being logged in to Google, Facebook, and a bunch of other services, and by having an ISP that provides a unique IP address per subscriber, that the majority of sites out there that use 3rd party tracking know who I am just by my IP address at any given time.
The article made it sound like IP addresses are always personal data. My point is that, if I run a website and keep generic nginx log files, is it really personable data with regards to my website?
Yes, the ISP can link that IP address back to a person, but if that person came to me as the website administrator and asked for all data held for that person, I would actually not be able to make the connection.
To give you one idea of how things will change in a post-GDPR world, I can tell you a story about how things are going in my industry: Most PII is going to be removed from domain WHOIS information.
The GDPR definition of personal data is VERY broad, and it includes things like:
* name, email, date of birth, etc (probably no surprise here)
* any user behaviour (what you look at, what you click on)
* uploaded content (what you write, your uploaded avatar etc)
* ip addresses, device ids
* beliefs, ethnicity, sexuality, health data (additional restrictions apply here)
* biometric data, genetic data (additional restrictions apply here)
Or are they granted an expection for being trustworthy good guys unlike these unscrupulous businesses?
Or do I have to actually _live_ in the EU to be protected?
[0] https://web.archive.org/web/20180409002346/https://e-residen...
PS : Ask for English version, they can do an English version, they did one for us.
> 12. In jurisdictions that require informed consent for the storing and accessing of cookies or other information on an end user’s device (such as the European Union), ensure, in a verifiable manner, that an end user provides the necessary consent before you use Facebook technologies that enable us to store and access cookies or other information on the end user’s device. For suggestions on implementing consent mechanisms, visit Facebook’s Cookie Consent Guide for Sites and Apps.
13. Obtain consent from people before you give us information that you independently collected from them.
People are already used to accept these cookie policies, so why not just widen it to GDPR related stuff?
Also how much can be caught with "security" reasons?
Most cookie policies in practice are all or nothing: you either accept and continue, or you decline and cannot use the service/website. That is not allowed under GDPR.
Only things you only use for security purposes. You can't say "we need X for anti-fraud" and then use it for marketing purposes without consent.
"You cannot use any personal identifying data from any visitor who is a one-time visitor."
If an IP address is "personal identifying data" (as the author subsequently states), then every visitor is a one-time visitor. You can try tracking unique visitors by something else, like some user agent data, but it's less accurate. Ignoring IP means optimizing a site for click-to-sales becomes a lot more vague.
If a site converts each unique IP to a hash, then that's one way to get a unique visitor, but then which hash method do you use? MD5 is hackable to anyone having a list of hashes to IP addresses, and anything else can be more complicated and less standardized, so therefore more prone to bugs and bad coding, and therefore more costly to the business.
"You cannot load any 3rd party service, because by doing that you would be sending personally identifying data to those services (like people's IP address)."
If you can't even load 3rd-party software because they can see IP addresses, then you can't have any tracking, including aggregate, unless you build your own, which can be highly costly and is inherently inefficient with many pre-built solutions already existing and refined, even if they're open-source.
This restriction seems just as unreasonable as the first, also based on IP, and I'm not sure the politicians who made this restriction understand the web.
"You cannot even do personally identifying internal analytics."
If this is true, then you're cutting out a lot of site optimization and sales navigation because you're not always going to be right about what people want or how they will click things on the site. Without IP tracking, you can't follow where someone is going or tie that user to a bug, just get an aggregate of many, which can be vague.
"The reason is that a first time visitor hasn't done anything that could be considered consent, so you have nothing to work with."
This is incorrect, the user has given consent to make available any info the browser provides, which has to include IP address so the server knows where to send the response. If a politician doesn't understand this, then someone hasn't explained it to them.
It is a natural right of a website and publisher to use IP addresses, because they are required for web communication and identifying abusers. How they use it beyond that is what should be regulated, not just the visibility or collection of it.
"I don't think publishers realize just what this means."
I don't think the politicians understand just what this means either.
For example, I'd be quite happy to let my local supermarket sell my personal data to Google in exchange for a 3% discount on my grocery prices. Everone would benefit: (1) The supermarket gets an additional source of revenue; (2) Google can charge more for ads; (3) The toothpaste company gets better return on it's advertising; (4) I pay less for my groceries.
GDPR prohibits this kind of win-win agreement, doesn't it?
Of course it's completely impractical to get cashiers to do this every time someone buys something, so it will likely just be applicable to store reward cards. They're doing this already, and all GDPR will introduce is moving the paragraph in the TOC you sign which says "we might sell your data to third parties" to the top in big letters and make sure you explicitly agree to it (or similar to achieve informed consent). As well as adding some safeguards in place.
A point on your example, stores already do sell your personal data to third parties as an additional source of revenue, but instead of giving you a 3% discount they usually just analyse your purchasing habits and throw discounts on other goods which they think you'll be susceptible to buying, so usually instead of you spending less you actually spend more on things you didn't really want before being offered.
2. GDPR does not prohibit this agreement, but it requires the company to get consent from you before selling your personal data.
Advertising doesn’t help manufacturers make more or better goods. It just helps them sell them at the expense of others. Advertising is a deadweight loss, a competition between sellers that leaves them all worse off.
> It seems to me that GDPR restricts economic growth.
It does, but fortunately economic growth is not the central point of human existence.
It plainly does. It trades profit and economic potential for privacy, there's no question about that. I've seen near universal agreement from EU persons that that's a desirable trade in this case.
It gives US startups an immense advantage. They can grow far more profitably in the very large homogeneous US market, unhindered by GDPR-style restrictions & compliance, and then take their scale/resources and project into the rest of the world and comply with local requirements.
That US advantage will get larger by the year, as the globe perpetually fractures more and more on compliance requirements. It's going to become more difficult to operate in all foreign markets, as regulations for online services grow nearly everywhere. Most nations will put up barriers of compliance that will have a tangible cost. Europe will have numerous different GDPR-like regulations among its nations. There are 50 countries in Europe and only 27 are in the EU, that guarantees a messy, fractured compliance zone overall.
This is only the beginning of what will be a dramatic reshaping of the way you could formerly build once in almost any nation and easily go global with a service, that will become impossible without considerable financial resources.
It won't be: comply with GDPR and you're good. It'll be: build 50 different compliance systems to reach into 100 countries. Only very rich tech companies will be able to do it, something the US particularly specializes in building.
(Morpheus photo)
1. Social websites don’t have to be giant, centralized communities too big to police themselves.
2. People need more tools to help them achieve things in the real world, rather than spending hours a day chatting about the real world online.
3. There are ways to make money online without ads begging you to click on them, and they involve real-world goods and services that your website can help connect people for?
What kind of world would it be that one minute spent online would result in hours of enjoyment out of the house?
Would you NEED to collect data on people in order to tailor ads to them, when the interface would enable them to express their own INTENT to spend money, which you can then help facilitate?
EDIT: downvoted heavily, what else is new. Yeah, clearly saying people want to achieve things in the real world deserves condemnation and scorn from anonymous downvoters, but no counterpoint is given.
Put another way, you can argue as much as you want that people want to eat salad and steamed vegetables for every meal, because it will make them thinner and healthier. And yet, McDonalds is still doing well (maybe not quite as well as before, but still very well).
Regulation will curtail the edge cases where people are acting to their own detriment to a degree that society deems unacceptable. Beyond that, it’s up to the invisible hand of capitalism to dictate what customers want.
Not every website is in a position to sell something directly. That's how ads work in the first place.
I run a collaborative writing forum that is predominantly used by teens. I make so little money off it that I'm running it as a charity because forums like it were a valuable part of my youth. And there's very little I can do to make money from my userbase these days, though it used to make a couple thousand bucks per month and got me through uni.
People on HN and the like love to scoff and go "if you can't make money, then you don't deserve to exist" which is awfully short sighted. Like the only consequence they can think of as they Mr Burns their hands together is The Verge, operated by a billion dollar company, shutting down.
Ads service the middle of the bellcurve of sites that aren't 100% charity but also not in a position to peddle you merchandise. The internet is going to lose out if society doesn't find an alternative. Just more centralization.
Yeah, I could even imagine a scenario where you help connect people to real-world goods and services for free; the provider of those goods and services would be more than happy to help keep your bills paid, assuming there was some kind of mechanism that would drive people to their goods and services and not a competitor.
What would such a mechanism look like?
There's the benefit of being able to trivially connect with friends, family and acquaintances by a few degrees. But since that applies to those users too, and the overlap is partial, the user graph grows unbounded. If you limit it in some way, then you necessarily will have some users at an edge with a restricted experience. That's likely very bad for business.
With point 2 there's the general overall argument of whether these concrete, codified social networks should exist at all - whether they are healthy to society or people compared to the more limited gossip circles they would be in otherwise. I don't think it's clear cut to call it worse and I don't know if we can put that cat back in the bag even if we wanted to.
Tracking makes markets more efficient.
1. Advertisers can tune their ads/targeting to get higher conversions and sales. They pay higher PPMs and PPCs.
2. Publishers get higher PPMs and PPCs. This motivates them to invest more in their content and website because each new user will yield more money with higher PPMs.
3. Users get more relevant and safer ads. Remember the shady banner ads of the late 90's and 2000's? That's the type of low conversion rate / click through rate ads that will run when advertisers can't target their audience efficiently and PPMs are very low. Relevant ads also save users (the segment that buys stuff from ads) time from researching for products and services.
4. Users get personalized content from publishers. This has a few negatives but I would argue that it greatly improves user experience.
The technical and administrative complexity required for the legislation effectively shuts off tracking for all websites that aren't owned by a megacorp. Small and medium sized publishers now have less motivation to get good content out and improve their websites from the lower PPMs.
That is specifically not wanted.
Several European governments are subsidizing projects to provide consistent and exhaustive comparison tests between many products instead, so customers can for each category of product they may need find massive comparison tables, find which products fulfill their needs, and can buy the cheapest one.
This makes the market more efficient, because the best product for the lowest price wins, instead of the best marketed product.
One such example is the Stiftung Warentest: https://en.wikipedia.org/wiki/Stiftung_Warentest
I do not see any.
> They pay higher PPMs and PPCs.
As a user, I do not care.
> Publishers get higher PPMs and PPCs.
Don't care either.
> Users get more relevant and safer ads
Sorry but that's outright bullshit. In practice, targeted ads feel absolutely worse (at least for me), as an example I remember buying an umbrella a year ago on Amazon... guess what do I still get recommended to me on there? F'ing umbrellas... I know I'm in the UK but come on, one is enough.
> Remember the shady banner ads of the late 90's and 2000's?
I still see that garbage all over the place, including from supposedly "reputable" ad providers with apparently top-notch tracking like Google. Fake antivirus software or tech support scams are still common on there.
> Users get personalized content from publishers. This has a few negatives but I would argue that it greatly improves user experience.
That's my other problem with tracking-based ads, as it creates an echo chamber. I'd much prefer getting "irrelevant" ads as it makes me discover products I would've never otherwise thought about. I prefer print & real-world billboard ads for this reason as they're generic and expose me to stuff I wouldn't see otherwise.