GDPR watchdog: tracking and consent popups unlawful
iccl.ie
iccl.ie
>ast month the Irish Council for Civil Liberties revealed that RTB data was used to profile LGBT+ people to influence a national election, and that RTB data had been used to profile victims of incest and sexual abuse.
Excuse me? This is awful. This is worse than target figuring out a personally identifiable female minor was pregnant before her parents, which is despicable behavior.[0]
From 0:
>But even if you’re following the law, you can do things where people get queasy.”
I haven't advocated prison for companies malvertising before. That changes today. We all have a responsibility to do right by each and these tactics are inhumane, predatory, and cause measurable harm in the real world. If any of you are doing this type of work I strongly urge you to quit in protest and blow the whistle.
I was queasy until I read this report. Now I'm completely outraged.
I'm going to stop ranting now because even having to say these things is absolutely ridiculous. I can't even.
0. https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
GDPR exists, and so do national privacy laws.
While this example is especially vile, let us not forget that vileness is the modus operandi for these firms, generally.
The issue I have is the general lack of enforcement. Selective enforcement of standing laws is ripe for abuse, and creates a situation where every rational actor assumes they'll never be first to be hit, as everyone else does it too...
It seems to me right now what we need is high throughput bulk and even prosecution of each and every violator, one by one. After the first few take place, and the pace of enforcement is made clear, this will become a higher priority to the rest of the sector (who will subsequently be prosecuted for their misconduct in any case, to ensure even handedness).
Clearly there are practical issues around trying so many cases, but this is where regulators need to innovate in the same way tech companies innovate to defeat regulations. Perhaps we need hearings to establish illegality of a set of actions, and simpler fact finding hearings to merely determine that given conduct fit into that illegal set of actions. Strict liability offences (prove it was done, no need to prove fault or intent) could also help (where appropriate).
An advertiser targets their ads to profile characteristics and then they know that anyone who clicks the ad is a match. (Any maybe some ad systems don't require a click?)
As an example, I found a site with a walkthrough of a game I was playing. The typical site that many kids and teenagers will use to get unstuck in a game. The pop-up listed over 1,500 companies that would get my data. And many of that companies seem aggregators that would share my data further. 1,500!
I have mixed feelings of the government accessing my data. There is a balance to be found between privacy and security.
But that 1,500 companies from around the world would start tracking me, or anyone that visit what seems an innocuous page, is gruesome.
Targeted advertisement is creepy as hell.
It is mind-disturbing to know that each step I do is tracked by thousands of companies, to know that tens or hundreds of thousands of employees have access to my data.
That each time I search for a video game, a place to go on vacations or a an answer to a job related question, I will be evaluated by algorithms that are creating a profile of me, as a human being, to predict what I want or need.
Advertisement has its value. But, that level of intrusion is humiliating and attempts against everybody dignity.
I hope that GDPR watchdogs get more founding and fines start punishing hard these criminal behavior.
The full title: GDPR watchdog’s investigation finds that tracking and consent pop-ups used by Google and other major websites and apps are unlawful.
GDPR is mental, just block the EU, it's the only way to be sure of compliance and no risk with a law that massive, with penalties that high.
That seems to me to be a cornerstone principle for individual liberty in a digital age. I'm surprised so many Americans are against it.
No, it turns out they don't want to.
The problem here is they just don't give a crap. The fine is a cost of doing business. Someone needs to stick some bollocks on the GDPR and start issuing fines in the billions. Big billions.
The problem is not that companies with large legal departments can't follow the law, but rather that some of such companies are pathological choosing to break the law. They think they can get away with it because few breaches are prosecuted, and based on highly dubious legal interpretations concocted by their large legal departments.
GDPR is not difficult to follow (or indeed "mental"), and is a huge boon for consumers. In a way it's even a boon for businesses - it can reduce their legal risk by encouraging them to only collect PII when they have a good reason to do so.
It's only hard to follow the gdpr if you are wanting to track people, which is because that is the whole point of the gdpr.
If you deal with, or store, information about users why shouldn't you be held to reasonable standards for protecting that data? Why should you be allowed to keep that data for however long you want to?
Businesses used to run without stalking people, just because it's become the norm doesn't mean that it is required, or even just ethical.
The GDPR does not put any strain on us - I'd love some more detail on what you believe these "slow and expensive process burdens" are?
All the GDPR does is hold companies to follow a reasonable standard about PII and consent. We only need something like the GDPR in the first place because so many companies hoover up PII and tracking information without consent, using and selling it as they want, and not even taking sane measures to secure it.
If you want to capture and process PII, you should legally have to first gain consent, and you should have to take care to secure it. If you can't comply with that, you're not responsible enough to hold such information.
>managed to completely obliterate whatever was left of european advertising agencies
That's a huge win in my books. I take the stance that advertising is a cancer on society wasting: lives,talent, and finite resources while doing what good for society exactly?
For every campaign that does measurable good I can usually argue that either the campaign wouldn't be necessary without advertisings infectious tendrils everywhere, or the effect is virtually worthless in the face of the overwhelming scaleof resources wasted on useless advertisement campaigns.
If it was yours, you would be able to sell it in exchange for something else. The EU's rules forbid this, basically giving ownership to the state
Also, let's be clear, it's not only YOUR information since you didn't collect it yourself, there could be an explicit formula about how much of it is yours. Just because GDPR says so doesn't mean it s correct.
also
> I take the stance that advertising is a cancer on society wasting: lives,talen
half the "articles" you read here is advertising
Which rules? GDPR is all about being explicit about how the data is used and the right to choose. What is the rule preventing you from offering a service explicitly allowing people to sell their information?
> “Freely given” consent essentially means you have not cornered the data subject into agreeing to you using their data. For one thing, that means you cannot require consent to data processing as a condition of using the service. They need to be able to say no. According to Recital 42, “Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.”
> 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
If your business explicitly deals in user information:
> In order for processing to be lawful, personal data should be processed on the basis of the consent of the data subject concerned or some other legitimate basis
> ... these are the other legal bases:
> 1. Processing is necessary to satisfy a contract to which the data subject is a party.
In that business it's necessary to share the data which is being sold. It's part of the contract. As long as you comply with notification, listing 3rd parties, and other relevant points, you can require and sell that data.
That's the gist of the matter. Private information is not tradeable, therefore it's not really property, and certainly not owned by the users since they can't sell it for goods they readily want to acquire.
The clause you quote only applies if the private info is necessary for the service rendered. GDPR considers advertising optional, despite the fact that it's crucial for the survival of websites.
So you're free to say "this access costs $x, you can sell your data for that much on this other service". If you learn through that that people actually are not prepared to sell their data, then GDPR achieved its purpose.
If you work on the other side, it may seem hard to handle. But if websites can't survive without trading user data, I'm happy for them to die and get replaced by something with better business model. Global data abuse is not worth it.
I guess you could also start a business explicitly selling user data to get access to 3rd party services as a replacement of payment. As long as it's a separate entity, it could work?
Let alone, you cant demand consent even with self hosted ads. You are obliged to give the content for free even if they dont consent
I dont understand why you keep changing the subject
If you run a data trading business, I can sell you my data, and GDPR will be ok with that.
Where can I sell my information in the US? Oh wait, I can't, tech companies see it as a harvestable resource that they expect to get for free.
With GDPR's consent framework, I now could genuinely sell my data if I wanted to do so.
You are right. But i could see a market forming if e.g. chinese companies were allowed to compete and offered direct monetary incentive to acquire users (would be cheaper than the ad spending they do)
>GDPR's consent framework, I now could genuinely sell my data
you couldn't because they are used for advertising, which is notnecessary for the provision of the service: https://gdpr.eu/gdpr-consent-requirements/
I think that there are benefits for us the people so far and more to come when the regulations will be enforced, like:
- more transparency, now you can see exactly that your data is shared with 100+ companies and you can see what is collected and decide for yourself if you want to visit or not, or maybe you want to use a VPN or private mode on this dubious website
- you can request you data back and ask to be deleted.
- some website will open in text only mode for EU users, you no longer need to waste a click to press the Reader Mode button.
If you disagree then explain how the listed benefits are "zero benefits"
I do hate when inane legislation like GDPR makes websites downgrade my UX to protect some information I don't give a crap about. But it's for my own good, of course.
Anyway when you live in a society you have to respect the society rules even if you don't like them or you can move outside of EU(or use a VPN) to get the full experience advertisers intended it for you.
Google has only gotten mightier and greedier post-GDRP. So whatever defense is mounted on GDPR, the empirical fact is that it failed in its purpose.
It was a missed opportunity. It could truly hurt google if (a) it declared private information as private property that can be sold in exchange for services or if (b) it provisioned a "PI" tax that should be mandatorily paid back to users similar to the link tax required to be paid to newspapers.
GDPR should not dictate how you implement ads, if you want targeted ads then maybe the industry needs to implement them respectfully, the user would opt=in, connect his browser with FB,Google,Twitter and then he will get targeted stuff. They could make a browser, DRM-it to shit and if you use that browser you get less ads but all of them are targeted and ever click in that browser is tracked, it would be an opt-in stuff where you sell your browsing activity for ad-points that you can spend on different websites to read articles.
We need strong laws because the industry is fucking the users, they sell you products like a TV or an OS but they still want to make a few more cents so they continue to track you and sell your data to advertisers.
IMO advertising is mostly manipulation, make people buy expensive diamonds or expensive clothing or phones when they don't have too, I would be curious if we could create a economy simulator and ban all advertising like it was done for cigarettes and see what happens.
Google instead thinks they are above the law and offers a pop-up that can only be dismissed by accepting. Forced consent is not consent so that’s against the law.
Don’t complain if companies get into trouble because they break the law. Don’t complain Europe keeps telling companies like Google they need to follow the law until they actually start following the law.
Textbook illegal under the ePrivacy Directive implementations, but many (most?) sites still do it...
It’s probably not against the law and the situation you have described is a valid method to establishing lawful basis under the GDPR. It’s really not all about “consent” - we hear that too much.
Ultimately the courts will decide who is right. We’ll see.
Various data protection authorities have concurred that forced consent isn't consent. For consent to be valid, it needs to be freely given, informed, and not tied to the provision of a service, such that provision is dependent on unrelated consent.
There's also restrictions on consent being used where there are imbalances of bargaining power (so for example, consent isn't a valid legal basis for processing data at all in an employer/employee scenario due to the imbalance. Another legal basis is needed).
One area of interest in future would be how the imbalance of power could be interpreted - consumers generally can't negotiate anything with any internet company (unlike negotiation with small businesses), and in many cases companies can hold them hostage until they consent (if Google won't let you into your email until you consent to something, that's clearly coercive and abuse of power). When regulators finally learn to move faster, it will be interesting to see how widely this can be applied - could it even extent to a company which holds a monopoly status in a market, due to lack of meaningful choice? I think it could.
In any case, the smart money is on not relying on consent as a legal basis unless you have no other option - it's the least durable basis, and can be revoked at any time.
The reason EU agencies went bust was because they were competing against the likes of google and Facebook, because those companies could arguably target better (or were perceived to), and they could only do that because they were breaking the law.
they managed to completely obliterate whatever was left of european advertising agencies
But seriously… I fucking love the GDPR.
Frankly the amount of misinformation circulating about GDPR of in particular from US techbros is astonishing. Nobody should be having a serious issue complying.
Other than that, we've had to a) ensure we honour user consent b) ensure that only directly relevant PII is held in our systems c) for only as long as needed and d) is handled securely - so ensure encryption at rest and in transit is properly applied.
Was maybe about 2 months work for 3 people to put in place, and we had plenty of time to do so.
Oh, and an initial early change we made at the behest of our lawyers was to drop the last quartet of any stored IPs. Not sure if that was GDPR or another EU directive though.