GDPR Transparency and Consent Framework
github.com
github.com
It's the specifications for how the IAB (Internet Advertising Board), which consists of of every organization blocked by your ad blocker, would like publishers to gather consent from people landing on their site.
It's a very optimized setup as who they are targeting using this are the big sites that do Real Time Bidding (RTB) for ad slots on their pages. You land on a site and the js for ads loads, calls out to a real time ad marketplace with your info (IP, cookies) and then preset bids ("I'll pay 20c to serve this person an ad for cheese!") all are evaluated and the highest paying gets served on the site (and the marketplace takes a tiny cut).
What this framework does is help add user consent and GDPR readiness into the criteria that can be used in this process. So as a publisher if you're trying to meet GDPR requirements you can say: "Only give me ads from places that respect this".
As a consumer, this kind of paves the way to just consent to these things once and then use them all over the web (good for UX). If you're just trying to get to grips with GDPR try this Plain English Guide
https://blog.varonis.com/gdpr-requirements-list-in-plain-eng...
- How will this affect invoices that have to be kept for accounting purposes? Even if a customer wishes their data to be removed, we should not remove accounting information.
- How will this affect Internet archives and caches?
It seems removing all traces of a customer can be a very hard thing to do.
1. If you're legally obligated to keep information, you should keep it. This is one of the "legal bases" of handling personal data. Others are things like they consented to this, you have a legitimate business activity with it, they contracted you to do something with it, etc.
2. The GDPR makes a really clear distinction between personal information (email, name, religion, etc.) and everything else: you need to delete the personal information.
So it's not necessary to do a cascading delete of everything the user ever created if they ask for their _personal_ information to be removed.
This isn't really GDPR related, but you can see this on Reddit sometimes where comments that a user remain, but the user deleted their account.
If other laws exist that clash with GDPR, those laws take precedence. This question most often comes up specifically with regards to payments and finance. If a law requires you to retain payment/accounting information for three years, you must keep that info for three years, because this is addressed by a more specific law than GDPR.
https://www.cnil.fr/fr/loi-78-17-du-6-janvier-1978-modifiee
since 1978 and I didn't see anybody on HN panicking at the thought of doing business with french citizens, although these laws are tougher than GDPR. Remember than the latter is enforced at the country level, it's not Europe who is going to fine your business. Which means maybe Czechia will let you fly with whatever you are doing with personal data, and maybe Spain won't because they have tougher user data protection laws. My point is GDPR didn't create a new legal risk that wasn't there before. It's just that people here didn't care before for some reasons.
Now I see all these "GRPR compliant"(whatever that means) seals on different products, but where they even "CNIL compliant" before? Is that framework "CNIL compliant"? How many of you did a declaration to the CNIL before harvesting data from french citizens?
I'm sure someone once said "This is why we can't have nice things".
GDPR is scarier because the fines look higher and uniform across the EU, as far as I can tell.
[0] http://www.theregister.co.uk/2016/10/05/ico_finally_delivers...
they do have some good standards, that focused on user privacy, which are abandoned by now. mostly they spend the 2000s trying to standardise hit-the-monkey rich media banners and were widely ignored while google stole all Ad money by dictating the direction they wanted instead (and thanks to that period every site in the world snitch you to google analytics)
now iab is trying to lead how Ads will confirm the publisher secured gdpr consent. but again google is already on their own thing.
If the company follows standards or not, is another history.
On the other hand, one of my clients dropped the membership (cutting all expenses on the quarters pre-IPO/Sale so the numbers looked better) and was still leading one of the standards even without the name on this list.
which is? you left us hanging there