GDPR: noyb.eu filed four complaints against Google, FB, Whatsapp, Instagram
noyb.eu
noyb.eu
The EU is not the USA - the majority of small businesses will never need a lawyer at all!
To her, what does being "mindful of their user's privacy" even mean?
She probably has analytics installed. Maybe she collects some emails.
There is zero chance she is going to be abusing her user's privacy. All GDPR has done for her is cause stress -- and caused her to spend more money on basically useless "GDPR plugins" for Wordpress.
There are countless people like her, who are spending money effectively on nothing. Because of GDPR. It's horrible. In my opinion.
If her admin password is 'password123' and her database and analytics get dumped by someone, it doesn't matter if she wouldn't abuse users privacy, because others will.
I concede that chances are low, but I contend they are non-zero.
You can't legislate that online services be provided any more than you can legislate that Apple provide iPhones for everyone. The government can offer subsidies or refunds or some other consideration, but there must be something in return.
Then again: with re-targeting and other "very advanced" techniques, so are other ads I get.
I wish I'd get actually relevant ads. Perhaps a "universal" micro-payment system may make me actually give away money.
Perhaps data-banks will actually happen.
The days of the ad-rush seem to be coming to an end.
I don't think Gmail started out with heavy email content harvesting and integrated advertising but I could be misremembering.
Most other services today are no better than a pop/imap inbox as before, just with a bigger storage quota.
Everything is built upon them though.
Why can't things be built upon POP and IMAP?
Why are they crappy protocols?
That's a different question. 3 random examples don't really mean anything. IPv4 is old, HTTP/1 is old, SSLv1 is old. Sure they work, but we also have newer better stuff.
The old email protocols do not properly support modern features like syncing across multiple devices and servers with lightweight and efficient payloads, along with fast and safe attachment handling, consistent message ids, message threading, labels, contacts, push-based notifications, and many other things that people take for granted today. All modern email systems have built their own and don't use pop/imap because they're too outdated to even use as a foundation.
Here's JMAP from Fastmail if you want more details on a open-source email protocol: https://jmap.io/
Also my last comment already links to a new protocol. Perhaps you should look at that.
Everybody in the ad world knows it, too, and that's why so many companies are freaking out. They'll never get permission from people to spy on them like they have been. They whined about the "Do not track" header in the same way - they want to hide what they're doing as much as possible.
If asking "customers" to opt-in in to your business model is going to hurt your business, it was a shitty business model in the first place.
The rise of adblocking and the ongoing arms race from that would prompt innovation and change eventually.
I don't think we need to underestimate the advertising industry's ability to route and innovate around regulation and irritated consumers.
They are not free. Someone pays for them. If someone wants to pay for an internet service by giving advertisers access to their PII -- that's fine. But it doesn't mean that this monetization scheme should be applied to anyone using the service. Internet companies should provide a paid, tracking-free, and GDPR-compliant access mode, as an alternative to a free ad-based one.
Who knows, maybe brick & mortar companies would also accept this double-monetization model, so that when you come to Starbucks next time you would be able to get a free coffee in exchange for your PII and a non-removable tracking bracelet.
> The GDPR prohibits such forced consent and any form of bundling a service with the requirement to consent
> a penalty of 4% of global revenue
edit: On the first, if companies use (for example) personalized ads to pay for the service, why should they be forced to provide the service without the source of funding? If you disagree with that, you can just not use the service.
But why make this one illegal?
We can make wedding planners illegal if we don't like them and then just say "not all business models are legal.
But that doesn't explain why. Why stop people from engaging in a transaction that both sides consider to be a win?
https://edps.europa.eu/sites/edp/files/publication/16-09-23_...
I don't think not giving you services if you don't opt in violates your "enjoyment of the right to respect for private life..."
Are you saying that you shouldn't be allowed to trade use of your personal information for services?
If not, how does your quote tie in?
I think that's the crux.
That information is to be regarded as part of some inalienable rights, that those who have those rights cannot give up, even if they want to.
Not allowing people to waive their rights prevents a race to the bottom, in theory.
That's the principle behind the GDPR, yes.
For the same reason we disallow duels, even if both parties feel it would be a great way to settle a dispute.
What is that reason exactly? I don't see what the two have in common.
Is this the basis of our disagreement?
Unlike some Internet and Silicon Valley types (who always seem to lean ultra-libertarian), I like living in a society. And society has a fabric.
This discussion is a bit like the one about minimum wage. You probably don't like it. Many people ("society") do.
The GDPR does not outlaw ads. It only makes using the worst types of ads difficult or maybe even impossible.
And that‘s unequivocally good!
Perhaps a middle-ground will be centralized batch opt-in services that opt you into collecting for most ad networks and sites.
The requirement not to deny service for people who don't opt-in should prevent that from being used as an end-run around the regulations, but we'll see.
I'm seeing targeted ads so where did I opt in? I'm not saying I didn't but the fact that I can't recall doing so is a bit of puzzle?
EDIT: typo.
It simply doesn‘t allow you to decide for me that I would really love targetted ads.
Hence, „consent“.
Searching for mechanisms to limit these models seems fair. I hope it is carried forth on good faith and gets good results.
It remains to be seen if that ideal is upheld, and what kind of creative workarounds and ideals companies will try to explore.
As with any regulation or law, it has potential to be overbearing, favor incumbents and/or end up doing the opposite of its initial intentions.
That's the nature of anything society tries to do, though. If it doesn't work right, change it later.
The second... I don‘t care whether it‘s 3, 4 or 5 percent. But the big idea is „global“ and „revenue“, which again is excellent.
1) These services have no interest in actually providing you with truthful, complete or comprehensible information about what they do with your data. You actually cannot form an opinion that would allow you to judge the situation.
2) Even as someone in IT, who frequently reads about information being correlated or used in creative ways to cause damage, I do not feel like I could fully judge the impact of giving any piece of information about me to a company, even when I'm fully informed about the things they do with my data. The way they anonymize data might get proven to be deanonymizable. We might have crazy advances in technology, leading to modern cryptography being a joke and criminals decrypting the information that I produce right now. We might have some change in government, which for whatever fuck kind of reason feels like anyone who can be proven to have smiled at a Jew in their life, should be executed.
And if I am in no position to judge something like that, the layperson is certainly not either and does need the law to help them out.
3) It's not anymore possible to live life by just not using services that violate your privacy.
Most webpages have Google Analytics on them. Or Google Ads. Google anything.
The prevailing desktop operating system is Windows, which is headed towards Windows 10.
The prevailing mobile operating system is Android.
The prevailing social network is Facebook.
The prevailing messenger is WhatsApp.
The prevailing video platform is YouTube.
And far too many people see no problem sharing your e-mail conversations with Google.
Even the bloomin train that I take to work has a surveillance cam in it, like it was the most normal of things. Which hadn't been legal prior to the GDPR either, they just didn't give a shit, because punishment was basically nonexistent.
And no, I don't consider setting up a farm in the middle of buttfuck nowhere to be "living life". I cannot afford to be a social outcast, to not use the internet etc..
What's stopping anyone from randomly filing GDPR claims against every other website? How many such claims can the system handle at any given time before succumbing to years-long queues?
In these 4 cases they have been reported to the regulator. For 3 of them the reports will be passed to the regulator in Eire as that's where they have an EU presence.
So if it is "dismissed" that essentially means the regulator decides no action is required. Or the regulator might decide a phone call or letter will suffice for a first offence.
Max Schrems could take a case to court against Facebook or whoever, with all the usual costs, penalties and potential for appeals etc.
They just wrote a letter to the data protection agencies that – in their opinion – someons is doind something wrong.
Facebook/Google et al. have no quarrel with Max Schrems, but with the data protection agency, if it decides to act on this.
Therefore it's obvious that Max Schrems cannot be liable for anything.
If one can argue the personal data is still necessary, e.g. for the purpose of attribution in a repo, then the controller is not obliged to erase it.
Paragraph 3 is all about exceptions including ones for freedom of expression and "establishment, exercise or defence of legal claims," e.g. copyright or other IP.
About “defense of legal claims”, removing people from the history will only strengthen your claim as the owner of the repo?
I’m not convinced that paragraph 3 actually applies here, not sure what exact claims can be done for keeping that information as it is. And can github “hide” behind such vague exceptions?
[0] https://www.git-tower.com/learn/git/faq/change-author-name-e...
In practice, companies will continue to assume the opposite, and we'll see how things shake out with the regulators and courts.
It's the cornerstone behind any teeth in the GDPR.
Exciting times.