Edit: or at least consider that their rules are ridiculous.
Edit: or at least consider that their rules are ridiculous.
But the important question is, do the countries pay their fines?
You can think what you like about the Euro, its implementation, the Maastricht treat in general. But let's not downvote actual data.
That depends on how the GDPR is implemented within the country. E.g. above is factual for Belgium, but _not_ factual for The Netherlands. "Autoriteit Persoonsgegevens" has been notifying everyone to comply, government website or not. It's a steep learning curve though, there's also an multi-year effort to have government websites make use of TLS/certificates.
Edit: A reference: https://www.rijksoverheid.nl/onderwerpen/privacy-en-persoons...: "Sinds 25 mei 2018 moeten overheden, bedrijfsleven en verenigingen voldoen aan de Algemene Verordening Gegevensbescherming (AVG)."
meaning: "Since 25 May 2018, governments, businesses and associations must comply with the General Data Protection Regulation (AVG)."
Overheid.nl is the official government site.
[1] https://www.techdirt.com/articles/20180605/22253339978/eu-co...
Funny, considering that there already are cases going on and not a single one is close to those maximums.
> Everyone I know takes GDPR seriously
Wow, what people do you know? Considering that the vast majority of sites doesn't even have opt-in into tracking but opt-out after they started tracking, I think the people you know are some weird exception.
Though I did have to do a bit of clicking around until Privacy Badger found something so it looks like they at least are trying.
Facebook is an example they seem to just fine, but a big Dutch media company (RTL) having a cookie wall that quite clearly explains what you are consenting to by clicking "continue" but doesn't strictly fall within the correct opt-in mechanism? They send a warning for that, not a fine.
Yes, it's rather embarrassing that even the government itself doesn't follow the law. But then screaming the 2019 equivalent of "get your pitchforks!" shows how misunderstood the GDPR is. It's supposed to help, not collect extra money.
>It's supposed to help, not collect extra money.
It's supposed to give more leverage over foreign companies to EU countries, because we have somehow managed to create an environment that's very hostile to building tech companies.
on edit: I see someone has already addressed the issue several comments lower and in depth https://news.ycombinator.com/item?id=19426066
Let me put it another way: the European Union is not like the federal government in the US; it's mainly an economic union.
Or another way: European countries are independent, not states in a federation, and the European Union is a separate entity.
Of course, this is ridiculous so what I'm really suggesting is that they look at their laws and reconsider how crazy they are.
Businesses that only make sense financially if they can gobble up user data without their consent and sell it to third parties should not exist, just as businesses that can only work financially by not paying their workers should not exist.
What of this is crazy?
Their cookie disclosure regulation IMO has collectively wasted perhaps millions of hours of users' and website designers' time.
So really, users should be angry with websites for intentionally working around the spirit of the cookie law (and creating the annoying pop-up which basically requires you to consent to cookie tracking if you want to continue to use the website). The EU's mistake was not making the cookie law far more strict.
This continent still remembers when Nazi Germany and the Eastern Bloc tracked people to abuse and even kill them. That was never a direct concern in the UK, but people there are still strongly against government databases (see: UK national id card trial, NHS database trial) and in favour of the right to privacy.
Filling the coffers is just a nice bonus on top of dispensing some much-needed slap-downs.
No Microsoft (for two years now), no Google (for 6 years now), no Facebook (for two years), no Amazon (for a year) services here.
The reason I don't use their services is that I don't want to support shitty companies that have no respect for the people of the countries in which they operate, and I believe these companies are primarily responsible for turning the web into the ad-infested walled-garden shitscape it currently is.
There are alternatives for everything, and some are far better than what the big tech players offer.
The difference is I'm willing to pay for a quality service. Most aren't.
Besides, those companies would never leave the single largest trading bloc on Earth. Their shareholders would crucify them for it.
In that sense, the EU is doing these companies the favour, because they make so much money doing business in the EU that they'll never leave. They'll adapt and fall in line, like everyone else.
Trust me, nothing of what Facebook, Google, Amazon or Microsfot offer is irreplaceable.
Let's not forget this same company also promised to "don't be evil", and then changed their mind. What's backing up this "binding statement" and how do we know they won't change their mind again?
I've heard this ridiculous statement so many times. Do you think a company needs to put "don't be evil" to stop itself from doing evil things and then needs to go ahead and remove that phrase because otherwise it simply cannot proceed with evil? Sounds like a joke. We're talking about humans not robots here.
That said, I don't get why Google gets singled out all the time while all other players often play a dirtier game.
My point was that Google has a history of making public statements that make themselves look good, and then backing down on them later. Maybe 5 years ago they didn't data mine Google Analytics, but who knows what their policy is now or when they may change it? I'm not saying the OP is wrong, just that I'd like more evidence than "they said so."
> That said, I don't get why Google gets singled out all the time while all other players often play a dirtier game.
Because Google went out of their way to tell everybody they were going to be different.
Google's approach to GDPR compliance is entirely based around the idea that they're a Processor and it's not really their data, they're just the middleman. I would believe them because they have a lot riding on that.
If you agree with them then it’s an issue. Google clearly tracks data that is GDPR personal.
Why?
Mind you I don't even want to know how much information browser addons have access to. Are there any APIs that forbid any addon from accessing the page? Probably not, that would thwart adblockers.
I think GDPR is a great law, but if there's one critique of it'd I'd level without hesitation, god damn is it hypocritical.
===
Article 6.1.e "in the exercise of official authority vested in the controller;" - Wide open door.
Article 9.2.d - exception to prohibition on racial profiling for political parties on their own membership.
Article 9.2.g "processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued" - The "anything we declare acceptable" biometrics exception.
Article 9.2.h - The "no opting out of online medical records" clause.
Article 17.3.b "or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller" - The "if we say it's in the public interest not to delete it then we don't have to delete it" clause.
Article 23.1 - The laundry list of cases where any EU government can throw out all rights the GDPR establishes. Includes the following: "other important objectives of general public interest of the Union or of a Member State" as if that's not a goalpost a mile wide.
Article 49.1.d - Allows transfers of data to countries with inadequate data protections to take place if they are declared to be "in the public interest".
===
Pretty much everything in the GDPR document is untested at this point, and whether government or corporation, quite a lot of cases are going to have to be argued before the courts.
However, this document leaves open many arguments for governments that are not open for others. There is no definition for what might be "in the public interest" in GDPR, nor are there guidelines for interpreting when someone is "exercising official authority". One could argue that police departments are doing that 24/7 and thus large chunks of GDPR don't apply to them at all because processing is always lawful as a result.
By leaving themselves so many fruitful avenues of arguments to present to courts that have not been granted to others, the collective EU governments have created a law that holds others to a higher standard than themselves. Hence, hypocritical.
Why would a law be needed to be argued in court? There's been various improvements related to privacy already. Various big (national) companies have been ignoring the GDPR (disallow visitors unless they agree); this practice is now being investigated. Simplified: Netherlands asked the EU to clarify if the practice is ok according to the GDPR or not. There's been no court case. There has been discussions between companies, government as well as the EU.
See https://tweakers.net/nieuws/146391/privacywaakhond-onderzoek...
The purpose is improved privacy, not fines.
By the grace of living in a democratic society and not a despotic dictatorship, it is in essentially every western nation the right of any legal person who is accused of breaking a law to request judgement on the matter by the courts.
What you are implying would make judges politicians.