You want to sell my purchase/demographics data? No problem. Just let me know how much or what i'll get for it and i'll decide if it worth to opt-in.
By default - no one should be able to share my data with anyone.
You want to sell my purchase/demographics data? No problem. Just let me know how much or what i'll get for it and i'll decide if it worth to opt-in.
By default - no one should be able to share my data with anyone.
It should be allowed to be the cost of admission to the site. If you don't like that the advertising and your own metadata allows you to view the site for free, you could just not visit (or when you click no to consent, they would block you).
Websites shouldn't be required to provide you content for free.
You may say that credit and debit cards do this already (and they do), but you can still pay cash in public stores. Of course they can track you with your phone's bluetooth identifiers, facial recognition, etc., but why as a society should we allow public businesses to require this? Once we permit one place to do it, others will follow.
What about Costco, BJ's, etc who require a membership to enter the store and (probably) are selling the data they get from your membership?
If I make an unauthenticated HTTP GET request to a server, and it responds with a 200, it can't claim after the fact that receiving that request means I agreed to something.
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/402
But none of the websites should be allowed to pull the fast one on their visitors by stealing and sharing visitor data to other entities.
If you going to give me a free kiss, please ask my concent to be infected by personal-data-stealing disease. Of course if you like kissing and don't give a shit about others - government should step in to protect their citizens.
[yes] [leave]
Hi! The E.U. makes us put up warnings for cookies. These are silly things that every service on the WWW uses: don't worry, little user, we're just doing what everyone else does! [accept] [go away]
By Visiting This Website, You Agree to Have Cookies Placed on Your Device. [MORE INFORMATION]It's very easy to extend to whatever you'd like. Consent on the internet is a farce.
EU added a hell of an inefficiency to the WWW by making user education the responsibility of every site with no way for a user to pre-emptively signal "Yeah, I get it, and I don't care."
The EU didn't add any inefficiencies, rather, it's forcing the data abuse by websites to come to light.
If you use cookies only for login/session tracking then guess what, no popup is needed.
Also if the user expressed their consent (or lack of) once, then the popup is not needed anymore (google/fb/etc do exactly that).
Because if the answer is "per-site signaling," that's soft encouragement to keep using the same sites so I don't need to see that tedious notification and it rewards big players over small players (and defeats some of the benefit of the WWW as a hyperlinked network of data that's fairly location-agnostic).
That's on the website unfortunately
> that's soft encouragement to keep using the same sites so I don't need to see that tedious notification and it rewards big players over small players
I agree, I would want the same option (since I use privacy browser extensions I don't care), it's not the users fault the small sites are playing it dumb and using some generic annoying "we value your privacy" popup BS.
The GDPR does not require continuous confirmation of consent, only that they're allowed to withdraw consent at any time
> The GDPR does not indicate a shelf life for consent. Theoretically, a person’s consent is indefinite,
https://gdpr.eu/gdpr-consent-requirements/
> since the penalties are significant if small sites
This is FUD, proportionality is used when calculating penalties
Can you point to where in the law that guarantee is given? Furthermore, given the previous penalty was "none," any penalty can probably be considered significant for website operators who were previously assuming nearly zero risk in running their sites.
Paragraph 1. > Each supervisory authority shall ensure... in each individual case be effective, proportionate and dissuasive.
Paragraph 2. a) > the nature, gravity and duration of the infringement... as well as the number of data subjects affected and the level of damage suffered by them
Also, as we are discussing this, a lot of this will now apply to CCPA and (in some cases) COPPA
Yes, and COPPA has terrified YouTube content creators.
Wiggle language like "proportionate" (especially when paired with "dissuasive") doesn't assuage the fears of website admins, because it isn't a dollars-and-cents (or, in this case, euros) amount. It's at the behest of a judge, which is not a risk space an admin (particularly one running a site as a secondary function, not as core to their business model) wants to take on. So the law, as structured, encourages those popups everywhere forever. Annoying, to say the least.
I don't think I'm spreading the FUD; I think the FUD comes from the ambiguity in the penalties described in the law itself.
By Clicking Here you Agree to give us your personal information and we may share and monetise it with without compensating you in any way.
[yes, i'm sucker(or VPN user)] [no, GTFO]
Fortunately he's back at it again with a new ballot initiative, which he's funding himself, to improve on CCPA [1]:
>Mr. Mactaggart said his 2020 state ballot initiative, among other things, would create a state enforcement agency, limit targeted advertisements based on geolocation and add items covered by the “negligent data breach” section, which would allow consumers to pursue legal action in more instances of a hack.
>Most significantly, Mr. Mactaggart said, his new effort would make it harder to adjust the current law any further. The initiative includes a “purpose and intent” section that requires any amendment to the law to be in the service of protecting consumers’ rights to privacy, a legally binding clause that Mr. Mactaggart said would prevent industry from chipping away at the measure.
...
>The lobbying against Mr. Mactaggart’s earlier initiative kept it from the ballot in 2018, and legislators instead passed the privacy law. “It was the right thing to do because there was no guarantee at the ballot box,” Mr. Mactaggart said of his agreement to drop his measure. “Now, it’s different because we have the law.”
>Mr. Mactaggart said he would do whatever it takes to pass his initiative next year, including spending millions of his own money. He bankrolled his last campaign almost entirely himself, spending more than $3 million. Mr. Mactaggart will have to collect more than 623,000 signatures for his new initiative to qualify for the ballot. A survey in October by Goodwin Simon Strategic Research of 777 registered voters in California found that most supported Mr. Mactaggart’s initiative.
[1] https://www.wsj.com/articles/activist-behind-californias-new...
What's his motif for this?
https://www.nytimes.com/2018/08/14/magazine/facebook-google-...
>What's his motif for this?
Making a dent in the universe.
There's no reason a government like California couldn't require honoring DNT (within their jurisdiction, of course, as with the CCPA) and provide penalties for violations.
Instead, the rules weren’t tight enough to stop the current shitshow we now have. Your explicit opt in is a nice single button click, on a modal that fills the entire screen. It tells you nothing about what happens, it’s just easy.
Meanwhile, the rest is hidden away. And you still don’t know if those changes have any effect, especially if the tracking is also done server side. You’ll still get opted into all the emails by default, the needy ones that have to remind you every day that you made an account, and make you log in to disable them (to update their active monthly user count I’m sure).
Of course, it’s working that way because companies share your data with so many random third parties that opting in for each one would scare you away. And most of them do similar things, it’s probably different teams or departments insisting on using their own tools.
I don’t blame advertising for this per-se, I blame growth hacking too.
I wouldn't blame GDPR for any company's deficient consent process. That's just what they believe to be in compliance with GDPR, it may not actually be. Many of these questions are being litigated by privacy activists like Max Schrems.