I asked an online tracking company for all of my data (2018)
privacyinternational.org
privacyinternational.org
On a related note: Since most US companies base their EU subsidiaries in Ireland for tax purposes, it's actually just up to the Irish regulator. There are... concerns.
They are somewhat under-staffed, but this is improving (did you know that they are also suing the Irish Government?)
I believe it's against the letter of the GDPR, but as it isn't being enforced, we can expect this kind of thing to continue.
edit: I looked it up and wwe.com uses TrustArc, which seems to be a shady org certifying privacy. Mired in controversy, they have even settled a case with FTC in 2014 for $200,000. I'm guessing when push comes to shove and EU actually decides to prosecute they will pay a similar amount. I bet that amount is already in there books, set aside as "future risk management" or something like that. Just the cost of doing business.
How desperate does one have to be to work as a developer on projects like this?
* just be a nihilist and not give a damn
* Think its fine because they are encouraging people to do something they see as good.
* Think its fine because 'its just ads'
* Think it's someone else's responsibility to make decisions about ethics (as an engineering prof, I see this all the time...students who say engineers' jobs are technology not ethics/morals)
The problem is that they're correct in a practical sense.
The company they work for might get fined, but all the engineers see is the performance review. This system encourages engineers to think of compliance and morality as someone else's problem because: it is.
Many will justify this as "if I don't do it, someone else will" and again: absolutely correct.
Pass a law where engineers themselves may face fines or jail time for implementing immoral code, and they will suddenly discover a keen interest in the ethics of what they do.
Now add to that the constant reminders that morality doesn't stop a lot of people at the top from immoral behavior. Banks, politicians, Wall-Street, celebrities, billionaires etc. are in the news all the time for pulling shady shit. When they get caught, they say OOPS! They hear: 'don't do that any more, where people can see you' and they're free for another round.
Many people tend to adopt behavior that's rewarded. It takes a strong moral compass; some people never got magnetized. Show people a society that rewards moral behavior (they exist) and they might go there. (Some countries have low recidivism rates because of how well they treat people in prison.) If people can afford to move, they might. Else they may just say screw it, XYZ throws toxins in the river, I'll do it too. Choice: track people or go shoot 'terrorists'. Hmmmm.
Also this whole argument is distracting from the fact that this is TrustArc we are talking about. Its an american company with 340 employees and over 20 million american dollars in annual revenue. When a company out of India does this same thing we can argue impact of means on morality then.
Didn't work so well for the VW guy: https://www.theregister.com/2017/08/25/vw_engineer_gets_3yrs...
> "if I don't do it, someone else will"
Maybe, but at the very least it raises the price for companies to buy unethical people.
1: https://privacyinternational.org/long-read/3196/no-bodys-bus...
Given that the accept is our default just send off the accepted token = ok and don't wait for the response.
Send array of opting out info and then wait for all responses are ok so you can tell the user that it worked to opt out, the user must see opting out worked! response before going on to next step, because for GDPR reasons we need to tell the if there is a problem so they can try again!
- but that means we will be stuck at 98% for about a minute!
- sorry developer bro, GDPR says.
- (small voice) ok, manager.
> This page transmits information using https protocol. Some vendors cannot receive opt-out requests via https protocols so the processing of your opt-out request is incomplete. To complete the opt-out process, please click here to resubmit your preferences.
Here sends you to the same loading popup
Proximus [0], the partially state-owned and largest telecom provider in Belgium, uses this pattern too.
Additionally, on mobile, scrolling through the cookie-usage options automatically selects the maximum invasive option. The 'scroll-touch' is registered as a regular touch selecting the option.
It's hard to believe this is by accident.
Looking at their Javascript code and Timeline in the inspector it is 100% fake. It is all implemented using setTimeout and there's no communication with the server in the meantime.
This one drives me nuts! It's just such a brazen and blatent piss-take - "you won't let us hoover up your data and sell it to everyone we can? Then we'll punish you".
Easily and without issues. Humans are very good at making sure they do not feel themselves to be evil. A mass murderer will blame everyone except themselves or rationalize their actions as just.
Things which come to mind in 30 seconds:
"The regulation is draconian and it is just to fight it in any way possible."
"Our business helps people and working around this helps our business and thus helps people."
"If people really wanted and weren't simply mindlessly clicking buttons this won't stop them so we're actually helping user's enact their will."
"We put all this effort into the business, it's evil for the government to interfere for wishy washy reasons."
You're better off finding a good cookie/GDPR banner blocker
[1] example: https://www.wp.pl/
Do you have tampermonkey or anything like that? Maybe you could make a JS snipped that get's rid of those elements...
Shows a popup, saying "we collect your data yadda yadda yadda". Then there were two buttons. One to agree to that. One to manage it. But clicking on the manage button just took a user to screens and screens of garbage information mainly listing the companies that used the information. Without any option to opt out (you could contact them to opt out, I assume individually). There was a button (if you drilled through the screens) which seemed to imply that it would link to a page that allowed opting out, but all it did was take you back to the first screen of the popup. Unreal. Somebody has thought about that; absolute cretins.
They've changed that so that now there is opt out toggles (which are obviously all split into groups and are all on by default and so on), I assume because of someone in legal tapping them on the shoulder?
Everyone is obsessed with improving page loading time but what does worth that the page loads instantly if I have to navigate a maze of banner consent screens before I can see the content behind it
Why can't everyone at least agree on the same banner format / ui or have it delegated to the browser behind some native browser functionality like autocomplete
The reason is that if it's done in the browser then a person's preferences will apply to every website they use with that browser. Publishers will not want that as they hope that users will give them more consent than other web sites (I certainly do give some websites full permissions if I like them, others are a 'reject all' and 'object all')
Also, your consent preferences are stored under that website's cookie. There is the option of a global cookie but nobody uses it. This cookie data is then sent to everyone involved in the adtech chain (which is causing issues since it can be multiple KB's in size). It's format is described in [0]
[0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...
It's only the unnecessary tracking that needs explicit consent. So it's a good thing if such sites are slow to load and have to present irritating banners for legal reasons. This will hopefully put them at a competitive disadvantage compared to sites that don't insist on tracking their customers.
They want to track you to death, and put the burden of tiptoeing the law on you.
* sorry I meant strongly advising using legalese
P.s. I'll throw an internet party when Hotjar go out of business. Creepy fucks ruin the load time of every site they tarnish.
> It's essentially them hoping that when fines get handed out, they just get a warning because they tried.
Tried to deny some google apps access to fine location, and it would ask at every single opportunity, it was so easy to accidentally enable it as well, which I guess is the point, wear you down until you press the wrong thing or just give in.
Surely the GDPR has to have the foresight of dictating that my choice to accept or decline has to be valid for an equal amount of time, doesn't it? If I'm confronted with that popup as long as I'm declining the regulations are worthless.
I have to wonder whether it was an intentional effort by Microsoft to discredit DNT and to stop people from respecting it... On one hand, the same outcome (almost ignored everywhere) is likely to occur regardless of whether Microsoft made its move, on the other hand, it may have gave it a greater push.
[0] I have my cynical Fundamental Law of Privacy - it must not be enabled by default, so that the industry will continue profiting from it, while giving the user the illusion of choice. But at least those who enabled it enjoyed privacy, although only to a very limited extent.
Browsers could still provide a consent API but without strict enforcement it would be pointless - and with proper enforcement you don't need it.
You're 100% correct in your assumption. Der Spiegel is treading on thin ice here, or at least I hope they are.
Here's the relevant GDPR text:
Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment [1]
Sucks to be them I guess, as I pay for news (and run Ublock) but won't reward this mendacious behaviour.
If you don't accept, but click on "cookie settings" instead, a page will tell you that you can't choose to block 3rd party cookies unless you accept their 3rd party cookie, because they need to save your setting of not accepting 3rd party cookies in a 3rd party cookie. It's not a Monty Python episode, it's real: https://ibb.co/6YFpGWK
alternatively, if you click on the next link, you will be taken to a page that explains how to disable cookies in all latest-gen browsers such as Netscape 3 or IE 4.0:
http://www.allaboutcookies.org/manage-cookies/
Needless to say, I now exclusively use Sherdog's competitor, Tapology.com
Under GDPR (Europe), if you send a request, the company must honor it unless they have reason to doubt your identity, in which case they must ask for follow-up. Under CCPA (California), they are only obligated to honor "verified" requests. There's a range of what counts as verifying, from just being able to log in to your account on the low end, up to providing 3 pieces of matching data on the high end.
The company is obligated to tell you what data they have. They are not obligated to go out of their way to make connections, though, so you're better served by providing as many identifiers as possible (like account numbers).
What do you think they'll do with a cookie id associated to a few events?
Source: I worked on these products at Quantcast.
Many people (especially on HN) think that this kind of data collection is unethical. How do you feel about that and did you like working on it?
I did enjoy my time at Quantcast. The dataset is used for more than targeting advertising. For example, Quantcast's offers a free analytics product that uses the same dataset.
I am conflicted, and my view on data collection more broadly is more nuanced than what's in this comment. For this kind of data collection specifically: On one hand, it's how the entire publishing industry has built their revenue model. And I like news, sports, content, etc. On the other hand, it's creepy for a 3rd-party service that I've never heard of or interacted with being able to infer traits about me based on my browsing patterns, and then sell targeted advertising to yet another company I've never interacted with. I use an adblocker specifically for this reason, despite running an analytics startup.
It's enough to email from the address thats associated with the account. Generally speaking.
Requests for information should only be fulfilled with a notarized identification verification. The potential for security breaches here is massive.
Her answer was that she provided her cookie ID to Quantcast and then asked for any data associated with that ID. She also promised me to include that information in the article to prevent confusion, but she never did.
Ironically, Quantcast only knew her real identity after the request.
To Quantcast she was just a cookie with some events that ultimately indicated she might like x and has shown interest in buying y.
[1]: https://www.quantcast.com/privacy/data-subject-rights/ [2]: https://www.quantcast.com/privacy/
This is probably a dark pattern disguised as a mistake.
They will almost certainly satisfy your request (even if you don't truly live in California or the EU) because there are significant regulatory repercussions for not responding to legitimate requests. Or at least that's how it works at the big company I work for.
I can't speak to Atlassian specifically, but at sufficiently large companies, privacy@ emails tend to get routed directly to internal compliance teams, which may be operating under/within the legal org or just using a playbook legal has previously signed off on.
Legal@ has a good chance of being monitored by someone else. Worst case they route it back to the appropriate team and you continue getting stonewalled. Best case, the new set of eyeballs on the conversation has a very different view of the legal risk of your stonewalling experience, and you get what you want.
I haven't tried the above for compliance requests (as I'm not in a jurisdiction covered by GDPR or CCPA), but general BigCo experience has taught me just how variable responses from legal can be depending on which particular lawyer covers it[1]. Every lawyer evaluates risk in their own way, based on their experience, understanding, and conservative (or not) predilections. Simply having your correspondence seen by a different set of (legal) eyes could be enough to get a more satisfactory outcome for you.
[1] Or in this case, if the legal team sees it at all. Which may not be the case for privacy/compliance requests, if they've been delegated to a purpose-specific team that's operating off of a playbook.
I've only done this for deletion of data by the way.
Sorry if I'm being a daft punk.
[0] https://www.privicy.com [1] https://www.privicy.com/legal/privacy-policy
Please consider referring to it as spying over theft and PII about you, as opposed to your PII?
Part of the server logs may be about you but are not yours per say.
Better to assume all PII and PI even if not identifying, belongs to the user. GDPR is explicit on some of this and not on others. Shared information, or that deemed necessary, won’t be deleted on request for say Uber/Lyft. There is a financial transaction and a driver etc, they won’t delete. They could sever the link to your profile though. Facebook offers something like this, but don’t do it. You will never be able to authenticate yourself again, and they will keep building the “anonymous” profile. It’s complicated for users out there...
I agree from a liability standpoint, from a company's perspective. From a user perspective, better to assume all information that can be captured will be, it will eventually be available to all humanity and it doesn't belong to you.
'server logs' fails to account for how that data is used which should explicitly defined. Failures to do so is misappropriation. A good litigation firm couls retire by challenging reckless companies on these grounds.
I guess this is where our opinions differ. In order for them to be absent the right to collect it you must force them to forget. That's where it doesn't seem like your information, after all they need to erase it. I'm all for legislation to regulate it's use.
Not sarcasm, we issue GDPR requests from an app on device, and you can request data (back to your device and not through us unless stated). Deletion requests are done as well. Data brokers, as a group, are obviously very anti-consumer, and getting them to comply in CA has been a huge headache (most simply do not). Prop 24 should help, so it’s going to be a long burn for consumers to take control. CCPA made hiring an agent (like us) explicit, but almost no one accepts that at the moment.
Alright, that's good, because I would really love for there to be a service that would streamline the way I request data from service providers or request the deletion of data connected to my account, as well as the account itself.
However, your site says:
>> We import and analyze all of your data across your online accounts and give you an audit and a plan of action.
Doesn't that mean that apart from all the, possibly bad, actors out there that have gotten their hands on my activities _you_ are now also in possession of PII connected to me? How does that improve things for me?
And yeah, we don't want to become a honeypot for what is the largest profile on you -- the combination of all the others.
I submitted a formal request under California's "Right to Delete" legislation (CCPA section 1798.105).
The response was a formal letter from the parent company denying my request. It's a template letter with legalese bullshit that's totally inapplicable (e.g. they argue there's still a "business relationship", even though we haven't done any business in 7 years).
NET10 is owned by TracFone Wireless, which in turn is 100% owned by América Móvil (NYSE:AMX, $41B market cap). I believe they had my address, email address, phone number, date of birth, etc.
It's disgusting what these giant telco bastards get away with. Why don't US laws have the same "teeth" as GDPR, and any advice to force them to delete my data? (e.g. If anyone here advocates for this sort of thing on social media and wants a slightly-redacted copy of the letter to publicly shame them I'd be happy to deliver that).
Of course, I don't mean to say the GDPR is useless. There's a lot of good work being done, and an Italian telecom was fined ~EUR28 mn for violations similar to what you had to face. I just think GDPR enforcement needs to step it up and hit the usual suspects with fines that go beyond a slap on the wrist for it to really change the world. You can track major fines using an enforcement tracker, I check on [1], but you can also just google it every now and then to stay up to date.
By which point FB will no longer exist in Europe (as they recently claimed that the Privacy Shield ruling would require them to do).
Google and Facebook operate with impunity in Europe, as do even sketchier data brokers and ad networks.
The end result of the GDPR was end user annoyance, protectionism for EU companies and the protection of monopolies.
It is incredible that this industry is allowed to operate like it does. If it vanished over night nothing would happen. The EU just had its strategy changed and pronounced that it is everyone's civic duty to share even more.
Doubtful it would be able to handle advertisers. Although I don't think many countries would be.
What do you mean? I don’t really understand what that would mean, or what you’re referencing. Was that part of the State of the Union, or is it another announcement?
Edit: I found it. It’s an information based on EU strategy document from February.
“The EU is launching a market for personal data”
https://www.technologyreview.com/2020/08/11/1006555/eu-data-...
That doesn’t look good...
Corporation block lists (e.g. Facebook, Google) https://github.com/jmdugan/blocklists/tree/master/corporatio...
"Someone Who Cares" list http://someonewhocares.org/hosts/
Ultimate Hosts Blacklist: 1 million blocked domains (once in a while you might need to unblock something) and also a bonus known hacking IP blocklist (prevents common hacking sources). https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist
If you have iOS device install an ad blocker app like AdBlock Fast, this plugs to practically all web sessions in the phone.
I use it in combination with uBlock Origin: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
* Firefox with third party cookies blocked * uBlock Origin with the usual blocklists * PiHole
There's no extra benefit beyond uBlock Origin, which already blocks requests before they are made.
Basically like being a hacker in the 1980s and 90s, or even part of early rave culture, where the sort of people who work in marketing would be afraid or uncomfortable with being associated with you before the culture is gentrified by people preoccupied by their reputations, and you can be free to create and innovate without being co-opted.
No doubt they still have a category for you, but it's marked as a minefield, which is as good a moat as any.
I also add the Annoyances lists to uBlock and I have the "I don't care about cookies" extension to ignore cookie popups.
I highly recommend AdAway if you use Android.
Name a more iconic duo.
https://duo.com/labs/research/data-companies-are-watching-me
That's not to say these laws are bad, just that the giant additional privacy risk they pose is kind of funny to think about.
This reminds me of Grapes of Wrath.
GDPR is a decent example. The minimum level of privacy required by GDPR is now the standard required whenever standards are required. EG banks, regulators and such now expect you to have as little privacy as GDPR allows. Everything allowable under GDPR is now semi-mandatory for KYC.
Privacy/data related regs really have this kind of tendency. If you must destroy records after X years, this often develops into a mandate to keep records for x years.
This is what I've found so far on the privacy policy page.
It sounds like it may be available only for california residents.
> In addition to the information, controls and rights detailed in this privacy policy, California law provides for specific rights for California residents. California residents may request access to Personal Information, request a copy of their Personal Information, or request that their Personal Information be deleted. You may submit a verifiable request through Quantcast’s Data Subject Rights page, which can be found here. California residents may also submit verifiable requests by contacting Quantcast via email
Here's a big list of the various companies that track you and your data and the methods for which to opt-out of their lists.
It takes an afternoon to go through, but it's not all that bad.
If anyone knows how often you need to go through this list, I'd love to know.
https://www.quantcast.com/opt-out/
It doesn't work if you have trackers blocked.
This sounds like the kind of person I want to go on a night out with.
How would they pick the right age, gender and location for you? Do they just pick the latest they have?
Do they assume federal sources are accurate?
How do they deal with multiple values?
does anybody know whether this already exists?
In terms of data flow, it mostly goes the other way. It allows the shops to sell this data about you to others. Your credit card company does this, of course, but the only "direct" visibility they get is to the establishment. "In an average month, _trampeltier spends $x at grocery stores, $y at liquor stores, $z at tobacco shops", etc. They don't learn the actual itemized purchases without cooperation from shops (who of course have this data). Though I wouldn't be surprised if that was built into credit card processing agreements at this point, who knows.
The commercial surveillance industry is a real threat. It exploits citizens' data and in doing so serves the dictatorial interests of government and the amoral activities of capitalism. The surveillance industry is also inept, and cybercriminals and state actors will get the data eventually.
Pleas reconsider where you work and what you enable.
Let flood them with never ending, millions of requests and make sure they comply with the each of these according to regulation.