A small French privacy ruling could remake adtech
techcrunch.com
techcrunch.com
The more rulings we have like this, the better. Yes it may cause some business models to disappear, but I feel it's worth it to take back control of our privacy.
Good, hopefully we'll see some real innovation, with wide spread micropayments, rather than brainwashing which costs the viewer of the site far more than the recipient of the site gets.
I see this on HN a LOT, but I am really not sure it's a great model. The thing about ad-supported revenue is that you can still consume the content if you can't afford it.
I'm simplifying a little, but the people who convert on ads are basically subsidizing the content for the rest of us. In our society the people that fall into the conversion group are generally wealthy and the people who fall into the latter group may or not be.
But the point is that with micropayments only the rich have access, and with ad-supported revenue everyone has access. I think most people prefer the latter.
load_ads_unless(payment >= $0.0001)
Whether or not sites would suffer the added complexity probably depends on how much money is on the table.
Do they?
Or is it the people who buy the products, regardless of ad conversion?
I don't think there is a "physical" product here. Mostly Articles and Videos
[citation needed]. Telemarketing used to target people who could only barely afford it, and well educated, well earning folks from the younger generation tend to be tech savvy. The ones who don't know what's up are either old or uneducated (poor.)
That's at least a counter hypothesis if not outright refutation of your claim, since I don't actually know any of the numbers here myself.
Have you ever wanted to buy something small and literally didn't have the money in your account? This is how a huge number of people live, every day, day to day. Those people will never have access to micropayment content, because they can't afford it.
you did claim
> the people that fall into the conversion group are generally wealthy
now you say "yeah okay it sucks ethically", and shift the goal posts to something else entirely, from "wealth" to "they could buy it"? You're playing fast and loose with the exploitation, both financially and mentally, of others.
You can't just ignore the costs of exploitation of people who buy shit they can't afford because their life sucks, and the sheer pollution of minds by advertisement, all the needlessly created "needs", too, because they can't be easily quantified.
> Those people will never have access to micropayment content, because they can't afford it.
So, social services in a country could confirm that a person is actually on welfare. If they are, sites can make certain things free for them, and/or others can donate a small share (10%?) of their micropayments to those who have nothing. That's not a fleshed out suggestion, just the first thing from the top off my head. Allow people to sign up to get a few free articles per month. Before you say it can't be done, show us you thought about it at all. You're also implying that the best or all the essential content would be micropayment content, which is a huge assumption.
My feeling is that the opposite is true, so I'd be happy to see more evidence for one or the other.
A huge percentage of the people who don't buy are doing so not because the ads aren't effective, but because they don't have money to purchase. With a micropayment model those people just won't look at the content, because they don't have money in their account to do so.
These are definitely not the same thing.
Imagine people for whom a dollar is a lot, who have no credit card to link into your system, who have no money to buy your stuff and no way to buy it even if they had the money. Even a $0.01 charge would be impossible because they simply don't have the tool necessary to buy your stuff over the Internet.
I mourn the Internet that included people like them.
Why bother to educate people to donate money when you can just put ads on your content? Also, when 99.9% of content-makers use ads, it means you have a much smaller pool of potential donors, too. When most users on the internet can donate and are used to donating, it becomes much easier to receive donations for any random piece of content.
And second, there's great friction in the existing micro-tip model, because the payment companies take big portions out of the small tips. Plus, there's quite a bit of fragmentation as not everyone has a PayPal account, or Apple account, or Google Contributor account, or Amazon account, etc.
I think cryptocurrencies will eventually solve this issue, if what we've seen so far with Steemit.com, d.tube, and others like them is any indication of that. Once people get into any cryptocurrency at all, the liquidity of tips greatly increases, and it becomes much easier to tip someone with a cryptocurrency. It's still in the super-early stages, though. It could take another 10 years before this becomes more mainstream.
I don't really see any other way for this to work. The Google Contributor or even Flattr models will not work because they are not decentralized and interoperable enough with others like them. You'll never see the majority of people on the web use Google Contributor or Flattr. It needs to be an ecosystem of such services that all integrate and interoperate with no friction and content creators can be paid with any of them. The tipping model needs to be more like email than Apple iMessage, so that everyone can have one and use it with any other similar system.
As a a counter to that, I've been watching 3blue1brown's maths videos on Patreon. Payments get you early access to content, but everything gets posted up eventually and it seems preferable to having ads.
The hardest part of making a sale isn't the price--it's getting the customer to say yes. With micropayments you ask the customer to say yes every time they click a link. This imposes a cognitive/mood/whatever penalty every time they consider viewing your content. No wonder it hasn't taken off.
A better solution from a market psychology standpoint would be to sell an all access pass to the content on 10, 100, or 1000 websites. Monthly auto rebill. Just one purchase decision for life and with enough sites the perceived value is high. Not sure why we aren't seeing more of this -- if anyone works at a media conglomerate feel free to reply :)
Can't wait to buy my "Internet Pass"!
- Track how many sites a user visits, without knowing which sites the user visits. Call this number N.
- Charge the user for N visits.
- Distribute the money to the original websites, without anyone knowing (not even their banks?)
Sounds like a nice task for a cryptography researcher.
just spread a virus... or chrome extension which keep querying your websites
there is no way to implement this with technology in a reasonable manner unless you monitor every action every user does at any time. which would be (at least in my opinion) worse.
Yes, but by that logic a banking website could also be compromised.
And banks spend a lot of money to minimize that; less affluent business won’t be able to properly deal with that.
Any examples of that, relevant to a desktop bank website user?
Do they sell antivirus solutions, or work with browser vendors to improve security?
I suspect banks have some kind of money-back obligation when hacked, but curious how far that goes when a sizeable part of their customers is hacked.
Korean banks required an activex that scanned your computer.
These measures surely raise the bar though I don’t know how effective they actually are.
They can equally bid for the amount to charge from a customer directly. If your payment for not seeing an ad outbids ad networks, you don't see the ad.
E.g. imagine that you agree to pay up to 5¢ automatically for visiting a page is the site asks for it, up to 15¢ per session. If the required sum is above it, you get notified (pay or not). You can configure your browser according to your tastes: accept larger charges from particular sites, always decline any paid pages from some other sites, bid for removal of video ads more aggressively than for static text ads, etc.
A clearinghouse company should handle this the same way an ad network would. Viewers would put some money to their account, and that would be written off in larger transactions e.g. weekly (dollars, not cents).
I believe such solutions were tried in the past, but did not work too well. I suppose most people value their attention much lower than hard cash.
I hit "yes" or "no", and don't hear about it until I've read those 20 articles. Something built into my browser could act as the middle man, taking 10% of that fee and sending the rest to the article's creator. Firefox could put in an infrastructure to plug in easilly enough. You could even allow payment via bitcoin to get VCs happy.
I don't have the patience to be thinking about authorizing spend every time I click a link.
I know I am worth ~50$ a year to the Ad business. I'll gladly pay $60 a year for access to content. That $60 gets redistributed to content providers based on the share of my viewership they get.
Basically, cut the middle man (ad companies in this case).
If you really want to be socially inclusive, raise taxes on those that can afford to pay (wealthy pensioners are massively undertaxed in the UK for instance), and distribute it as "consumer tokens", or cash, that people can spend on consuming crap.
If you want to subsidise low income people, then be honest about it.
A friend of mine recently fell prey to a scam ad on Facebook and they got some money off her. I have yet to buy anything from an online ad in my entire life; so she is actually a much better investment than I am in terms of ad spend.
Sounds like the "marketing doesn't work on me cuz I'm so smart" fallacy, which usually means you're getting hacked by a different type of marketing.
Getting the eyes of wealthy target demographic -- and IT/CS/Dev/STEM folks qualifies -- is definitely worth $$$, the only question is if it's $500 or lower (or higher?). I used to have clients who existed to target the hyper-wealthy, and they made cash hand over fist schlepping details about those folks.
$500 bucks for semi-personalized deets about FAANG devs making $300k+ makes sense, and you can find those people on HN for sure.
Let stay conservative and say 3$ per 1000 views. I heard of plenty of people that make more and that's including what Google take out of it. There's no way you only see 20 000 pages a year. It's at least 5-6 times that amount of page.
Ads are also amazing by the fact that they still pay even though you are underage and can't get a credit card. My passion of software engineering wouldn't have been fulfilled if it wasn't from all the free resource. I learned from Site du Zéro, I was there pretty early when they started, I've seen the website owner going from nothing to building an amazing company. Now they no longer depends on ads, so that's good, but that's only because me seeing their ads at the being was enough for them to work full time on it.
Also note that this is in the context of the typically more valuable video ads. On eg YouTube if you say 1 ad per 10 minutes it would take 9 hours of video watching per day to rack up 54 ads.
I don’t know what rate of ads one can expect from a mobile game but maybe it would be more. I think you would still likely need several hours to get so many. And presumably you want to play less if there are more frequent ads.
Anyone on Hacker News read much more than 250-300 pages a day. Just casually browsing on Hacker News would give a few dozens (multiple pages, looking at comments, going to the actual page). Any software engineer will look at reference on the web. I regularly reach 1000 pages a day myself at works (verified using a Chrome extension) and it doesn't take into account my usage over my phone.
> On eg YouTube if you say 1 ad per 10 minutes it would take 9 hours of video watching per day to rack up 54 ads.
Video ads pay much more, as I said, they can go up to 10$ for 1000 views and that's not included the ad provider part.
It's $5/mo even for the limited list of sites participating (already $60/mo). I suppose removing ads everywhere by paying web sites the amount advertisers from all networks pay them would cost several times as much.
What's worked for me is a combination of aggressive ad-and-tracker-blocking and subscribing to the print versions of content I enjoy.
Internet has given power to people to issue veiled threats that one has to give content to users at price they deem sufficient else users would simply pirate and pay nothing.
It doesn't seem to be growing much though, only having roughly 20 sites it looks like.
But assuming they are promising that paying for Contributor would remove you from all tracking (whatever that means), wouldn't it be a pretty big deal (both legally and ethically) if it was found that they are still tracking you while saying they explicitly won't?
Obviously tracking required to run the service would be excluded (they need to know who you are to take money from you in the US, and they need to "track" your identity to tell that you are the person paying for that service), but don't they already have plenty of controls over how they use your personal information, regardless of whether you are paying for Contributor or not?
Sure, they could stand to make them more obvious, but I get asked all the time to double-check my privacy settings with google, I get asked if I want to enable personalized ads when I'm setting up a new Android phone, and the page where you go to turn it off is a single toggle switch.
Yes. That's how capitalism works. You have to compete in the market.
> With micropayments you ask the customer to say yes every time they click a link.
Yes - do you think you should be able to sell them additional products without getting the buy's permission? That "conative penalty" is the difference between an ethical transaction approved by both sides, and a scam, fraud, or strong-arm tactic such as bundling or abusive contracts of adhesion.
> This imposes a cognitive/mood/whatever penalty every time they consider viewing your content
Yes, consumers are empowered to more buy specifically what they want, and nothing more.
Or, you could try a new business model that avoids some of this penalty in new, innovative ways.
> sell an all access pass to the content on 10, 100, or 1000 websites
That bundles together products that someone does not want into the same payment for the products they do want. This is the same market distortion that the cable companies use, which people have been walking away from over the last ~decade.
When buyers are empowered to bypass market distortions like bundling, product prices are able to move closer to their actual value. For some products that value is zero. That's a signal that it's time to find a better product to sell, not a reason to undermine the core mechanism of capitalism by removing consumer choice.
In fact, what I want I already have. The WSJ will bundle (yes, bundle) all its articles into a single monthly fee. The Economist happily does the same.
If, for some reason, these guys decided to switch me to pay-per-article I just wouldn't read them. That's too much of a cost. I can't afford it. Time is too precious for this nonsense.
This is a federated subscription. It tends to be a precursor to media mergers, though. (For example, Bloomberg buying BusinessWeek.)
Toll gating inherently adds friction to a process whose whole damn point is being low friction - marginal costs per person and free to reference around.
A rational solution would be to pay for what you like but people really aren't trained that way or lack the resources relatively. I suspect "microwork" could work better for viewers with little money and even then it is still a friction akin to annoying ads that drives people away.
Usually, in most of the business models, your most heavy users tend to subsidize/bear the cost of not so heavy but casual users. At the very core that is. For adverts it fails, since the heavy users are of less value than the casual ones. (how many times you can show the same ad to a user? Also, they are well trained on how to look past the ads).
With gold-like concept, great content is rewarded, and incentivized as well. Also, given the scale of reddit, it works really well (along with ads) but not too sure how well it will work with ad dependent publications.
The problem with one player covering costs for all publishers is the monopoly it brings. Also, sounds more like cable, where there is a cost to access 100s of sites on the internet. Moreover, the users are not convinced to pay for one site they use, do you think they will be convinced to pay/donate for 100s of sites they have not even heard of? If it is forced as a package, then it is exactly like cable.
I am not saying it cant work, but would require a lot of work to convince the users to pay. Also you are covering for not just the server costs, but publication's staff costs, business costs, which vary over time. With just one time lifetime payment, they are in a bound themselves.
[1] https://www.theguardian.com/cities/2018/nov/21/is-indias-big...
Micropayments raise difficult tax issues, especially for small sites.
In the United States, for example, if I've counted correctly 34 states require or will require by early 2019 out of state sellers of goods or services into the state to collect, report, and remit that state's sales tax. Another 13 states could do so, but have not yet amended their laws to require it [1]. 4 have no sales tax at all. (I'm counting DC as a state here).
Whether or not a state actually can force this on a given seller depends on whether or not the seller has a "nexus" with the state. 24 states' laws say you have a nexus if you have 200 sales a year in the state or sales in a year totaling $100k.
With micropayments, a site could hit 200 sales in a state easily and have to deal with sales tax, while only earning a small amount of revenue. For example, suppose your site accepted micropayments for reading articles. Say you did $0.05 per article. If 200 people in a "200 or $100k state" bought articles, that would $10 revenue.
Congratulations...you have to collect tax on that! Worse, tax depends on exactly where the person lives in the state. You have to get their address, and lookup the tax based on that. Going just by state, or even just by zip code within the state, is not sufficient as you might collect too little [2]. You also have to file quarterly tax reports, which have a filing fee in most states, which will almost certainly swamp your $10 revenue.
There are services you can use to do this for you. 24 states have banded together and formed a Streamlines Sales Tax group (SST), letting you register and file and remit taxes for all 24 through a single entity, and they have agreed to provide tax data (rates and tax district boundaries) in a common file format. Even better, if you agree to collect tax for all 24 of those states, then the states will pay the costs of you using any of several third party tax services companies (Avalara, TaxCloud, TaxJar, and a few others), including the costs of using those company's APIs to handle all the lookups up and calculation, and the costs of preparing and filing the reports.
Unfortunately, there are some big states that are not part of SST. California, Texas, Pennsylvania, Illinois, Colorado, New York for example. CA, TX, and NY don't collect on out of state sellers (yet), but those others do.
Avalara, TaxCloud, TaxJar, etc., can handle those states for you too, but that won't be free. TaxCloud, for example, if you use their "automatic compliance" plan, which requires collecting tax in all the SST states (so that the SST states pay TaxCloud), you can add non-SST states for 0.5% (less for large volume sellers) of your revenue in each such state, and that will cover address verification, tax lookups, reports, and filing. (No affiliation with TaxCloud. I just happen to be using them for my first attempt to get our site at work to handle out of state US sales taxes--before we had just been collecting for sales in our own state and collecting VAT for EU sales. VAT is vastly simpler since it is per country, and the EU has something equivalent to the US Streamlined Sales Tax called VAT MOSS, so VAT was pretty trivial to deal with without needing an outside service).
Anyway, all of the above probably will dampen interest at a lot of sites. Especially having to collect address information to calculate the tax. That raises privacy issues that I think many will find more troubling than the current ad site privacy issues.
[1] It was only in the middle of this year that it became legal for states to require out of state sellers to collect. In 1992, the Supreme Court had ruled that it was unconstitutional for states to do so, unless Congress specifically authorized them to do so. Congress never did so. But this year, the Supreme Court revisited that issue and decided that it is OK, after all.
[2] Realistically, the state probably won't come after you for the difference or penalties, but it is a risk you need to evaluate.
Instead, the end result should be less abuse and hoarding of data. In other words, ad services should be held accountable for what they collect, not just inform users that they collect your data. Cookies are actually the one thing you can control, it's in your browser, it's not the problem, you can block or delete the data. What should be regulated are what companies store server-side and how they connect that data and that should be done between the government and the companies, not between the company and its users who might not have the expertise and, in many cases, are stuck with some quasi-monopoly like Google or Facebook.
GDPR is not about cookies and it’s not about mere informing of users, but about getting consent for data processing. Publishers and service providers are required to ask for consent, with clear language and the default is opt-out.
Also from what I understand you can’t block users from using your service when they opt out of any data purpose that isn’t legitimate and the definition of legitimate data purposes is very narrow. For example it doesn’t really matter that ads profiling is how the company makes revenue, making more money is not a legitimate interest.
Some companies, like Facebook, are of course trying to resist this. But I’m pretty sure they’ll end up with big fines.
On popups, IAB’s specification uses the consensu.org domain for the cookie, so that consent can be shared between multiple domains. A publisher cannot share that consent with other publishers in case the list of partners used is custom of course, but you can still share it between your own domains. The purpose being to minimize the popups.
Given that publishers have a legal obligation to get the user’s consent, I strongly believe that ad-blockers blocking GDPR popups is legal trouble for both publishers and ad-blockers.
Blocking ads wasn’t deemed illegal thus far and it wasn’t for a lack of trying. Blocking GDPR pop-ups on the other hand will imo not have that same fate.
Also some users will legitimately want to have their data used for personalization and you can’t regulate against that.
This might be an unpopular opinion however given the choice between personalized ads and a paywall, I predict that most people will choose personalized ads.
How many examples do we need to recognize that legislation like this on the internet, well intended it may be, doesn't solve the problem? Why do we watch an approach continually fail and tell ourselves that we must continue that approach? Insanity and foolishness. One day I hope people can separate what they want and what they can get, but in the meantime, I guess smaller businesses will just continually fret over regional compliance with unnecessary and unbeneficial societal costs. This ruling isn't going to change much except increase internet balkanization against EU. You shouldn't decry the workarounds, you should accept responsibility for them.
(I've talked about it on this board ad nauseam so I won't make a long rant here, but in general there are other approaches or even more practical ones with legislation you can take if government interference in this medium is absolutely required which is debatable. You can't just look at other regulated sectors and magically apply that logic everywhere.)
That many sites isn't yet compliant is expected but I actually notice that sites do improve the UX (as in, won't try to force you to consent as strongly).
Though I didn't opt to read this article because it is behind oath.
Disagree, has done little and costed lots. It is a massive loss and has hurt tremendously, especially with the mandate/precedent it gives for passing other ridiculously large scoped internet regulation henceforth.
It has forced countless companies to review what they collect and how the process user data. The effects are seen everywhere even in the offline world.
The changes are absolutely monumental and it has successfully planted the notion that handling user data comes with a risk. The benefits can not possibly be overstated. We still have long ways to go but with GDPR there is hope.
Planting notions is[n't] really doing much?!
The idea that more tracking and more data collection has no downsides is how we got here in the first place.
Disagree
> Planting notions is[n't] really doing much?!
No, especially considering the scope, cost of compliance, and downsides of government interference.
> The idea that more tracking and more data collection has no downsides is how we got here in the first place.
This is why I originally wrote "One day I hope people can separate what they want and what they can get". We have to separate intent/reason from reality, and we have to stop assuming all attempts to curb a problem are righteous and justified. There are downsides to collection as FB and others are seeing in countries without these laws. The downsides grow with education. How is that even possible if there are no downsides? And, pretending that false statement was true, I'll take the company tracking and data collection over government interference any day. The former has very minimal, often only theoretical harms, whereas the latter has very known and already realized consequences to business compliance costs, freedom of information costs, and difficulty to roll back when misused.
Agree, thing is, GDPR isn't something unreasonable. You should already be doing something similar. You should already care about your users.
If you have trouble implementing GDPR chances are pretty good that your company are a net loss to society.
> The former has very minimal, often only theoretical harms
Wow... Yeah, I'm just gonna stop now. Continuing this isn't worth the bandwidth.
It's also mainly common sense. Take care of your customers and don't abuse them and you are 90% done.
But isn't that what people want to do?
Why can't I sell my personal data in exchange for services? It's mine isn't it?
I'm about to have skin in the game as I'm working on an alternative (https://www.adsfromsource.com). Goal is to make advertising more respectful, both in regards to data privacy and in disallowing abusive/misdirecting/etc. ads.
You’re talking about ~95% of Internet publishers and platform providers. Fortunately GDPR doesn’t apply to US sites that don’t “envisage” serving EU customers (see Recital 23). So those of us in the US will have the resources to keep publishing and innovating. But most companies/entrepreneurs that have to actually comply and aren’t big enough to essentially force users to do our bidding (Google, Facebook, etc) are going to have to close up shop.
Now, I guess it's obvious to complain about the idiotic, user-hostile and down-right evil Oath consent pop-over that I got when I visited TC. I'm gonna do it anyway.
Here's hoping this ruling stands.
Also pretty sure they named the company Oath so that people would think "oh this is another OAuth permission box, OK".
I think that's just developer bias. "OAuth" is not a thing non-developers know, even by name.
Here's the script: https://pastebin.com/NfCyDLw8
It says "Select 'OK' to authorise 'Oath' and our partners to use your data."
Is there a more general, less specific, way to phrase this? It's basically "please let anyone use your data for anything".
Other dark patterns I've seen are -
A page attempts to put you off by making you manually deactivate hundreds of different services if you object to them (though they of course have a handy 'enable all' button).
A page gives you a big green "Accept All" button, and a 'reject all' option which looks greyed out and is smaller. When pressed it takes you to another dialog with a big green "Go Back" button and another, smaller, dimmer link for "Leave". The "Leave" link is the one that gets you back to the page, rejection preference intact.
These seem contrary to the spirit of the GDPR, I guess we'll see in time if they are deemed to contravene the law. The TC/Oath one definitely seems to be over the line.
--edit-- Missed one - A page allows you to set various controls and sliders to reject its data sharing, but then sits for several minutes "processing" your lack of consent. When it eventually completes you get a message saying that they don't have a version of the page they can show you without the data sharing cookies, so sorry, please check again in a few months.
I see this often too. Doesn't this directly contravene the text of the GDPR, much less the spirit of it?
Some of which are marked as "opt-out through partner", with no link or other details about how one would do that.
While the trackers are making it a faf to opt out (rather than as the legislation actually required: making it an opt-in situation) I'll just keep on with my side of the arms war that is ad-blocking. Their loss, not mine. I can't say I feel I've missed out on anything by sites failing/refusing to display with ads blocked, links that redirect through trackers not working at all, or just plain backing out of sites that are obnoxious (and in breach) with "by continuing or closing this banner..." and other such.
no fine, but CNIL ordered the firm to delete all data it had
not already deleted (having judged collection illegal given
consent was not valid); and to stop processing data without
consent.
So this is a warning shot to them and the ad industry: If they change the way they do business, they were almost not hurt (There is probably the court costs to pay, plus their defence, plus opportunity costs).For now, the maximum fines seem to be just that, at least in France: Maxima, only for those who really do not want to mend their ways
Since there is still a lot of moving part regarding RGPD, the CNIL is just laying the foundation for futur cases.
At the same time, the protections that the GDPR seeks to provide are very important and it's absolutely right to protect them in law.
But what value is there in constant boxes that users become accustomed to clicking through like trained monkeys? It devalues the whole point of the GDPR because no sane person would actually read the policies for every single website to see if their data is being used reasonably or not.
I personally think that there should be a limited, well-defined set of data that can be transmitted to ad exchanges under an assumed consent. Fully anonymised and broad demographic data (eg: age range, sex, city, etc) for example. Anything beyond that should require an explicit consent.
This should encourage most publishers to do the right thing, because if you're doing something that requires a consent pop-up, it probably means you're up to no good.
The design of the wall of buttons is another topic. There is a design opportunity for a good solution there. Unfortunately what I see is the opposite. Pages that try to trick you into consent, pages who seem to link to other pages "checking something", "loading", "I'm sorry, try later", plainly not working buttons or no way to check all to "do not allow" but one button to "allow all". I really hope people who install those will pay and disappear when someone has finally enough of this crap.
There is none, however it seems to me that a lot of these are going to be considered illegal after a while, particularly the ones that default-enable a ton of stuff under the cover of a single OK button.
What would be really, really nice to see would be the web industry engaging with this properly, and changing their attitudes to private data, instead of effectively trying to hide behind multiple levels of disclaimer and implementing dark patterns to try to work around it.
> This should encourage most publishers to do the right thing, because if you're doing something that requires a consent pop-up, it probably means you're up to no good.
This is already the case, as far as a lot of privacy campaigners are concerned. If you're not planning on using my data in nefarious ways (sharing it with commercial interests for money), but only use it in ways that support providing me the service (technically, not financially) we're golden, and you don't need any consent.
The GDPR requires all tracking to be opt-in and to be completely optional. Blocking access to a page by requiring the users to tick one or more permission boxes is not opt-in. The same is true for many other GDPR permission forms (like Tumblr's) where all uses and parties were/are enabled by default and one needs to disable each one individually.
It's a matter of time before one of these big firms gets investigated for these practices and a fine is dropped. Publishers will learn to stick to the rules soon enough.
"But how can we monetise our service if we can't get paid via exploitation of personal data of our users?"
Don't know, don't care, not my problem. The ad industry has proven itself incapable of self-regulation, so the GDPR explicitly destroys this entire business model. Figuring out a new that works is the industry's problem.
What everyone forgets is that one of the biggest debacles with adtech was their inability to even guarantee that no malware was being fed with the ads. That's how bad it had gotten. It will take a long, long time before I have any sympathy for digital advertising.
I note that some of the EU's own websites have them.
So the onus is completely on ad firms and publishers to stop trying to find tricks and loopholes, and actually follow the regulation as it's intended.
Ideally, it adds a cost to including third-party cookies and tracking users. Editors of websites could choose to be more respectful of their visitors's data, and then they would be able to provide a more seamless experience without annoying popups.
In practice, apparently they are not willing to do that, either because money brought in by privacy-violating ads offsets the cost of losing users, or because they have not given much thought to it and are already used to showing lots of popups anyway, and think that one more will not change much.
> I personally think that there should be a limited, well-defined set of data that can be transmitted to ad exchanges under an assumed consent. Fully anonymised and broad demographic data (eg: age range, sex, city, etc) for example. Anything beyond that should require an explicit consent.
Fully anonymised and broad demographic data does not require consent, since it does not allow identifying users. As far as I know you could store the age range of users in a cookie and give just that to your ad exchange, although you should tell them at the time you ask for their age.
If the consent boxes all have sharing options disabled by default, which they should, and only appear once for each site then I don't really mind all that much. click
Setting aside if it's in line with GDPR, the interesting effect for me is that it adds a whole lot more friction to sites like TechCrunch for instance.
Up until now the cookies banner was annoying, but at this point I'll never go to a site with heavy GDPR screens except if I really really want to read an article that is heavily discussed. Put it another way, I'm not sure we get trained to click these disclaimer, just opting out of the site becomes a simple option.
In comparison arstechnica for instance is frictionless, and I hope it brings them a boost in visits comparatively.
The truth is that on the privacy advocacy side of this issue there is an understanding that those boxes are not meaningful, informed consent. On the programmatic advertising, suck up all the data side of the issue there is an understanding that an intrusive pop up with psychological nudges towards acceptance is meaningful, informed consent.
The GDPR was drafted in the way it was because of the industry's poor reaction to the tracking cookie law. They added hefty fines and a necessity of informed, meaningful consent because the industry reacted with a wink and a nudge by implementing loop holes. This ruling seems to confirm that the commission was not joking, that it wasn't just political posturing, that they want the industry to cease and desist.
Given that I have edited the html of any form ever given to me to change "I agree" to some form of "I don't agree and waive no rights", in what way have they diligently acquired meaningful, informed consent from me and therefore from anyone?
> The requirement based on the article 7 above-mentioned isn’t fulfilled with a contractual clause that guarantees validly collected initial consent. The company VECTAURY should be able to show, for all data that it is processing, the validity of the expressed consent.
Google hasn't first-party consented through each of the publishing contracts. They may be able to turn it around.
However, the industry would now favour someone who had no need to collect consent, if we're just talking about the base ability. The ad-world's dependency on personalised data is a problem, and may continue having issues with the GDPR.
Furthermore I personally don't use Facebook and only rarely Google so I don't really care about that, everybody is free to decide the first parties they use or don't use. If people find value in these services and use them over the competition is it really unfair that they benefit from it?
Meanwhile third party trackers are on most websites these days so I actually benefit from regulation in that sector because otherwise I simply cannot opt-out of that tracking (unless I manage to block them all with extensions but it's virtually impossible to catch them all).
So IMO this regulation puts the power back into the hands of the users, they decide who gets access to their personal data. That's valuable.
Blocking a few big players is easier than blocking many small ones, so from the point of view of blocking ads until the advertisers stop being shady this might no tbe a bad thing.
If the ad/tracking industry wants me to play the game their way instead of not at all, they need to start playing by decent rules which includes following GDPR's various stipulations.
Doesn't exactly seem like you got context-based ads but rather completely pointless ads?
It seems Russian bride distributors and few others pay best.
And media houses seems to don't care that this is intellectually and emotionally insulting to their readers.
Had they put slightly more effort into this they might have had a nice income from non-spammy ads like they have in print.
It's also NOT just the big corps. Companies that use public records (and public records in and of themselves needs a LOT of additional laws in the digital age) so you can find your ex-girlfriends, etc... Can you imagine these ASSHAT websites being sued for 100k by people in Portland? Then New York, etc.. I would love to see that happen.
If you pay enough via that ad provider, it will claim the ad space on that page for you and leave it empty or puts some todolist or whatever you want there. Ask a monthly fee of a euro for computer costs.
As this is the raison d'aitre of this pseudo ad company, all its GDPR troubles are resolved at once. If it gains traction, publishers can use it as a preferred ad provider and resolve their GDPR troubles too.
Only question: Who would want to pay for this. It might prove people prefer ads to micropayments.
I don't think it ever caught on.
You could try to form a coalition to do group purchases, but it's a hard thing to start, since the individual benefits would be small until you got a large number of members, whereas an adblocker is free and more effective.
Plus, the ad network could still track you, which is one of the problems people have with ads.
Here are people living in a civilized world with rules and regulations and posture as civilized human beings who function in an ethical society.
But at work they seem to be operating in neolitic wild lands engaging in increasingly invasive predatory behavior that systematically reduces the entirety of the human population going about their daily lives into objects of profit lacking agency, merely tools to be stalked and analyzed for revenue, to be prodded for value in any way possible. There is a dehumanization here with no respect of personal space, privacy and basic human dignity.
This would not be as bad if there was explicit consent and self declared transparency of the all processes in play, and commitments to ethical frameworks of operation. It's the surreptitious, misleading and often deceptive communication and behavior that betrays their willful complicity that is troubling.
I'm a bit worried that the interface of old Windows installers might make a comeback in the internet, but with "I agree" instead of "Next" written on that button that you have to click a dozen times.
In apparent contravention of the GDPR, various parts of the page say that I must agree to their use of my data for third party advertising or I cannot access the site.
They can say that they have a legitimate interest exemption - and they do. Sites must be able to earn money from their content, or they cannot operate. Therefore, they have a "legitimate interest" exemption for this practice (allowed under GDPR) - they cannot provide you with the service you requested because you are unwilling to help pay for it by allowing third party ads.
Edit: By the way, none of this addresses the other elephant in the room. TechCrunch is US based, and to my knowledge they do not offer foreign language translations of their site, at least on the .com version of the site. This meets the test under Recital 23, which says that if it doesn’t “envisage” serving EU users, it isn’t even subject to the GDPR. Any privacy notices on TechCrunch.com are essentially a courtesy.
They don't. That's not a legitimate interest. Making money from the data is not covered and if it was then the entire law would be moot.
> they cannot provide you with the service you requested because you are unwilling to help pay for it by allowing ads.
You missed the word targeted there. And the massive background dissemination of data that accompanies them. That's the issue.
While I live in the US, I used an EU VPN for a few weeks just to see what would actually happen under GDPR as an EU user. I couldn't stand the popups after a while - GDPR has ruined the user experience of the web for 500 million people. But through that experience I saw that most sites based in the EU are either a) ignoring GDPR entirely, or b) taking the position that showing ads from third party ad networks without specific consent is a "legitimate interest" - whether you agree with that position or not. I also witnessed countless sites that required user consent in order to view content.
No, that would be tracking and targeted advertising. No data processing - no need for popups or consent. If you want to sell me out to the highest bidder then you need to ask, and ruin the look of your site. Your problem, not mine.
> I saw that most sites based in the EU are either a) ignoring GDPR entirely, or b) taking the position that showing ads from third party ad networks without specific consent is a "legitimate interest" - whether you agree with that position or not. I also witnessed countless sites that required user consent in order to view content.
The law hasn't been in place for that long, and it will take a while for things to catch up. Your last two types of site there are specifically disallowed, and the first just naive.
Showing third party ads without consent is perfectly fine. IFF you don't gather, share, or process any personal data in doing so. If they serve static non-personalised ads, that's perfectly GDPR compliant.
Even when data processing is necessary to the controller, such legitimate interests must be weighed against “the interests or fundamental rights and freedoms of the data subject”. Should data controllers justify processing without consent based on this subparagraph, they will need to be prepared to prove legitimate interests (a higher burden) relative to the implied general interests of data subjects.
So businesses will need to argue that their interest (income) outweighs the interests of their users (not to be sold out).
Specifically, when it comes to advertising itself as a legimate interest:
Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge. That right should be explicitly brought to the attention of the data subject and presented clearly and separately from any other information.
Which is funny. Because they clearly don't care about personal data if you're in the U.S.
Hopefully in a few years (and hopefully a few multi-million dollar lawsuits later) the industry will learn to actually value my personal data and choices.
Strange then that "techcrunch.co.uk" redirects to techcrunch.com/europe