Europe is drawing fresh battle lines around the ethics of big data
techcrunch.com
techcrunch.com
Particularly with upcoming legislation regarding 'link taxes' etc. , we're already seeing hints of problematic issues.
Moreover, I think the end result will be just problems for Europeans and frankly very little improvement in material identity protection and basically no improvement in terms of quality of life for Europeans.
What's needed is another model for all of this, but it's way beyond the EU commission to come up with that, as exemplified by the odd 'link tax' rules, which hopefully will be amended.
Do they force European ISP's to blackhole traffic to your website's DNS / IP if you don't comply? If you're hosted on AWS, do the European authorities make Amazon an offer they can't refuse: Either Amazon takes down your GDPR-violating site, or every Amazon package everywhere in Europe becomes illegal? Can they force your bank to disgorge the fine directly from your bank account without your consent (e.g. by threatening to cut the bank off from any ability to legally transact with anyone anywhere in Europe)? Can they get an extradition warrant and have US police arrest you and send you to stand trial in Europe? If your company's CEO travels to Europe on vacation, does he risk having European police waiting to handcuff him as soon as he steps off the plane?
Sometimes a bit of well-placed regulation, which pretty clearly separates the ethical from the unethical in general and understandable terms can go a long way in getting action rather than just hand-wringing.
Those unethical things you are doing? Guess what, they're now illegal. So go figure out a different business model. It's not optional.
"big data" != "privacy sensitive data"
by definition.
What if the data becomes privacy sensitive after big data methods are applied to it? Does your comment say it isn't possible or it's not big data when that happens?
Whether they have enough operations in the EU for the EU to enforce it is another matter.
https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...
> The organization would have to target a data subject in an EU country. Generic marketing doesn’t count. For example, a Dutch user who Googles and finds an English-language webpage written for U.S. consumers or B2B customers would not be covered under the GDPR. However, if the marketing is in the language of that country and there are references to EU users and customers, then the webpage would be considered targeted marketing and the GDPR will apply.
If Techcrunch has offices or business partners in the EU, or targets EU users for example by having a Dutch-based version of their site, then they would need to comply with GDPR. But if they don't have any of that, then they don't need to comply.
According to the GDPR, you can't do that.
Consent is totally different from contract - and both are part of reasons under the GDPR to use private data.
True, consent requires necessity, but contract is wide open. When you click accept you aren't consenting, you are (theoretically) forming a contract, not consenting.
How is forming a contract different from consenting? Do you mean to imply that a contract can be formed without consenting to the contract terms?
The GDPR does allow processing if "[it] is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract" ( https://gdpr-info.eu/art-6-gdpr/ ), but if you want to argue that tracking is necessary to fulfill the contractual obligation to display personalized ads, then first you'd need to get consent for that contract.
How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/ , which says e.g.: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
So is the contract with TechCrunch about reading articles or about looking at ads? And is the reading of articles conditional on the ads?
While I applaud you going to the source, your reference: "How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/" does not mean what you think it means. It is simply a specific callout to emphasize the "freely given" aspect of consent (and NOT contracts) and remind enforcers that refusing to perform or taking some out from performing a contract should be considered undue pressure to get consent and therefore not "freely given". For instance, an extreme example would be if, after you ordered and paid for a pizza, and after I agreed to make and deliver you that pizza, I subsequently threaten to breach that pizza delivery contract if you don't "consent" to give me a complete list of movies you've watched this week. ALthough we do have a contract, we're not forming a new movie-history contract because I'm not offering anything for it or agreeing to do anything. I'm just using that pre-existing contractual relationship between us to threaten you into something that you may not want to do. They're completely separate concepts.
Note the phrase "inter alia" which means "among other things", which is a signal from the authors that this is not the only consideration on "freely giving" consent. It has nothing to do with consenting to form a contract. Note also the word "performance" as it relates to a contract, which is completely distinct from "formation" of a contract.
Furthermore, you've (theoretically) been forming contracts with these websites every time you visit them and accept their ToS and privacy policies and whatever else you click "OK" on - just go read them. They restrict you from many things that you could possibly do (reverse engineering, automated scraping, etc) in consideration for serving you up the content. GDPR is just another line item to add into that list for you to accept in the (theoretical) contract.
Lastly, I keep saying "theoretical" because at least in the US, I'm not aware of a direct case on the topic of whether website ToS are actually enforceable. There's a click-wrap case that is close, but other than that....
It'd be different if there was a cookie they didn't warn you about and isn't needed to view the content.
> It forces you to accept cookies that aren't necessary for the functioning of the site to view the content.
So, no. That's not what's happening here.
That doesn't seem right. Shouldn't I, the creator, be able to say "consent to having cookies or don't use my site?"
"Fill out this survey and you can have a candy bar"
"Nope, I won't fill out the survey but I'll still take the candy bar"
Don't mind you noting down I stopped by, or these product posters you have up, but I'd rather not have that embedded tracker, thanks.
Don't track you? Already jabbed you, LOL...
And so the law stepped in.
Me: Let me serve you targeted ads and you can stream this video you want to watch, deal?
You: Nope, I'm just going to stream your video without the ads, LOL
Me: That's stealing my bandwidth
You: Nope, the EU made it legal so it's not stealing, LOL
Me: withdraws from EU
The fair thing to do would be:
"I don't consent to targeted ads, so I'm clicking the back button and using an alternative"
Not:
"I don't consent to targeted ads, so I'm opting out of them and by the way, you get to foot the bill for whatever I decide to do next"
What you can't use is targeted advertisement where the targeting is based on tracking.
If your business model absolutely must resort to tracking users to be successful, it's probably best and easiest to withdraw from the EU market.
No, especially not if you're a monolopoly like Facebook or Google. For non - monopolistic sites the GDPR encourages other monetization business models such as subscriptions instead of collecting and then profiling user data.
At any rate, seems like GPDR punishes the freemium model which in turn punishes the poor. If I make my site subscription only then I either have to have the subscribers subsidize the free users, or bar non-paying users from my site...
If you want to say that they need the ads to function then they should not provide the convoluted way to decline tracking from 30+ trackers but just block us.
What we want is put a big Decline button near the Accept button, or put the full list of trackers directly on the popup and not send me to a Privacy Policy or a settings/configuration page. But this sites want it all, they want the EU readers and also their data and user the bad UX to make you just accept.
I just close the tab, I do not bother with workarounds.
I guess TechCrunch would argue the tracking is required to enable the ad rates that pay the writers who write the content.
There are twenty-eight countries whose regulators and courts will interpret this law differently. I don’t think we can say “we can all agree” about anything at this point.
>Processing shall be lawful only if and to the extent that at least one of the following applies:
>(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Since they're not doing that, either they haven't read the law, or they have and don't agree with your interpretation.
Wait a minute. I am thinking of a webserver that would make each visitor/client pay a fee to maintain the connection (or the socket). The server would be connected to a feedback infrastructure (a service provided by another company) that would only allow individual connections to be maintained if it's fed with data from tracking.
So the tracking would actually technically be needed to provide the service (the connection) if the company hosting the content chooses to use that web server service from that other company. Eh.
I think once the different data authorities kick into action in Europe, many companies will get a nasty surprise.
Without defenses like these, for example, reuters.com is intolerably spammy. But with them it's a delight. Same goes for TechCrunch.
Aren't they required to do this by European law?
But we seriously need a browser standard header that says no to that, along with a requirement that the only necessary cookie to read a website is GDPR with the value 0.
I think tc is at more than 50.
The EU is too focused on figuring out what's wrong with the technology that was invented 10-15 years ago to be the birth place of the next big alternative.
Take all of this with a huge grain of salt since I learned it from comments on HN. I'd love it if anyone can lend a more experienced take on this to either confirm or definitely what I've said here.