Not legal from the perspective of GDPR, sure, but it seems that everyone is doing it.
/edit: downvoted for stating basic facts, amazing.
Not legal from the perspective of GDPR, sure, but it seems that everyone is doing it.
/edit: downvoted for stating basic facts, amazing.
I get that everyone is super excited about GDPR, but sorry to say most websites can safely ignore it.
Only sites with a presence in the EU are paying attention. The LA Times is a counter-example of a site that hasn't bothered with GDPR because they didn't feel EU users were worthwhile keeping.
However, collecting data on the 0.5 billion people in the EU evidently seemed worthwhile for most sites.
And similar arguments could be made for why American companies would play nice to the EU.
If your company was unable to comply with GDPR, many wouldn't want business with your company anyway, especially other companies who are trying to comply with it.
Except for military force and incarcerations per capita, the US is lagging behind in almost every statistic compared to China or the EU.
> "The fine is really a last resort," she told Computing. "Even to get to the fine we have to go through a lengthy investigation that might take several months, then we have to take it though the courts. So fines are not our go-to tool."
However. I think with egregious cases like selling data. I am happy that the ICO fined a company for doing that. [1].
[0]: https://www.computing.co.uk/ctg/news/3027593/ico-theres-so-m...
[1]: https://www.theregister.co.uk/2018/08/09/ico_fines_data_brok...
Whether this actually works, only time can tell. But the fact that similar previous legislations went unenforced was a specific concern that the designers of the GDPR intended to address.
But for version 2 of GDPR I'd like to see something like: No landing pages. Content must be served on the first request. And no Captchas for Tor users.
The short-term effect of GDPR is ugly interstitial pages and mandatory consent, but that's not the point of GDPR. The point is to make legally collecting user data difficult, annoying, and onerous in the hope that going forward more companies will eventually decide it's more trouble than it's worth. That'll only work if complying actually is a chore.
Call your local news site and complain if they aren't honoring GDPR to the letter. Call your country's ICO and complain to them too. Talk your friends and family into doing the same. Be a pest; the more annoying the better.
As a matter of fact, I do complain a lot, and I do file complaints about GDPR violations, but convincing my friends and family to even care about this stuff is science fiction (I've tried for over a decade now without success).
Business and engineering culture around website construction is horribly broken with regards to user privacy. Changing that culture is going to take years of consistent pressure which existing interests are going to fight every step of the way.
In my opinion the ugly consent forms are the best thing about GDPR. A problem that techies have known about for years is now visible (and annoying) to the general public. Of course that doesn't restructure the entire internet overnight, but dragging the problem out of the shadows seems like a pretty good opening salvo.
Most people who complain about this just don't want to admit that they're not actually stating basic facts.