IAB Europe cookie consent pop-ups to be found in breach of GDPR
techcrunch.com
techcrunch.com
So I finally asked the IAB how one could potentially implement their framework as an open-source framework. Their answer was basically that it's not possible. You have to register as a CMP provider and ensure that your users are using your software in their compliant (ha ha) way, which is of course impossible to enforce with an open-source software that everyone can self-host. In general, in my opinion the IAB is mostly a framework to shift liability from the advertisers who steal the users' data to the publishers and CMP providers. Therefore I'm quite happy we never got around to implement this "feature" in our CMP, and I hope the IAB will quickly die and takes all those alibi CMP providers down with them.
A lot of consent management solutions appear to load the third-party scripts regardless and only focus on cookies, even though the real danger is IP-based tracking and browser fingerprinting which doesn't depend on cookies or any persistent data being stored (they've adapted as modern browsers heavily restrict cookies).
One question, that arose though is how one would fulfill the requirements of GDPR regarding the logging of consent as a kind of 'paper trail'. As I understand the requirements one would need to store some Form of identification (like an arbitrary ID, the time and scope of consent and also store this for the user or on their machine). I understand how this could work for email opt ins. But consent on a web page?
I always wonder.
Storing consent server-side only makes sense for identified users (e.g. those that are logged in on your site) as there you actually have something that you can link the consent to. For an anonymous user that e.g. has a Google Analytics ID stored in the browser you'd have to store a link to that ID on the server-side as well in order to link it to the consent, and that is not privacy-friendly. Storing IP addresses also isn't a good idea as you're again creating more privacy risks for the user than necessary.
The key is that the data controller be able to demonstrate AND RECORD that consent was received. If I clear my cookies, how does data controller prove consent?
“keep a record of consent statements received, so [the controller] can show how consent was obtained, when consent was obtained and the information provided to the data subject at the time ... [and] also be able to show that the data subject was informed and the controller’s workflow met all relevant criteria for a valid consent.”
With that guidance in mind, and from a practical standpoint, consider keeping records of the following:
The name or other identifier of the data subject that consented; The dated document, a timestamp, or note of when an oral consent was made; The version of the consent request and privacy policy existing at the time of the consent; and, The document or data capture form by which the data subject submitted his or her data."
Just seems like some huge liability here if you didn't record the required elements in a manner that allowed you to produce them. Does GDPR allow me to requisition my users devices if I'm investigated?
Of course, we are told GDPR is "easy".
For pseudonymous users, e.g. those you track via a Google Analytics cookie you don't know who the user is and you (hopefully) can't reidentify them without the Google Analytics cookie. Since the cookie is stored in the users' browser it makes sense to also store the consent record there. If you would store that consent record on the server-side you'd still need a cookie in the users' browser to link the consent record to them.
Yup, this is why a lot of websites try to lure you into logging in to the website to enjoy the full content (they won't tell you this is the reason, of course).
The user has the consent documentation on their device. But I can't provide the documentation myself.
I actually don't think the risk is very high. And I agree that storing this information on my side is additional data privacy risk.
But I don't feel GDPR is easy here.
But we get expert advice here that it is fine.
One of the claims I saw was that google hadn't said something about information being used to advertise - but when I read the related disclosure (they have all the versions) it seemed clear enough to me. I'm not saying ruling was wrong, but they in some cases hinge on issues just like this.
And we are just scratching the surface of things here.
It's still preying on the psychology of users that have been taught for years that green = good, accept, happy path, things will work
If you look at something like Apple's consent which as "Ask app not to track" and "Allow tracking" (can't remember exact phrasing), the binary choice is presented in a fair and equal way which makes you actually think about what you're pressing, because there's no clear "right" choice they want to you to press unconsciously
Edit: I understand though, you have a paid product, you boast about your acceptance rates as part of your marketing strategy, and no company is going to pay for something that decreases their ability to track users.
I've been in the same position as a developer where I'm asked to implement the maximum amount of obtrusiveness to coerce people to accept tracking, like overlays with the famous 'body { overflow: hidden }', because our marketing departments start to go ballistic when they can't track every single users every move. It just makes me sad sometimes that this is what we're dedicating our time to.
Since all the other consent forms are like this it makes sense to not change the established standard. I would for sure misclick, since I've by now gotten this dark pattern ingrained (I automatically go for the grey button).
Personally I often click on the wrong choice when e.g. asked about giving a website access to my location on iOS, as there's no color difference between them and the texts are quite similar as well.
BTW Klaro is full customizable so users can change the styling, and some users choose to display the buttons in the same size and style, though I don't think this influences acceptance rates too much.
So the leeches at IAB, OneTrust and everyone else employ a variety of dark patterns to make the user just click "Accept".
So, how can we use the scanner?
Not issuing a fine would send a signal that simply ignoring the law until you're told to follow it pays off, since the companies involved certainly made much more profit in that time than they would have made had they followed the law.
Also, the fines should be issued to everyone involved in this mess - middlemen and library providers like IAB, the ad companies actually collecting the data, and most importantly the publishers that sent their visitor's data to them.
That’s how capitalism works. For better or worse. If as a person you break the law, you are prosecuted and punished, without consideration who you are and what you contribute to the society. It's very easy to be erased from society (lifetime sentence) and/or lose lifetime earnings (via huge fines, compared to your income potential).
For corporations it's totally different. Consideration of who they are is a huge part of punishment. Countries don’t want to kill/severely injure companies, especially big ones, as they worry about fallout effects to their whole economy. As a corporation you can commit much much bigger crimes and get and equivalent of a parking ticket in terms of impact.
Consent is used when processing is not required to provide the service, no other basis applies, the processor still wants the data anyway, and the subject agrees. Legitimate interest applies when data isn't needed to provide the service but is necessary for related business functions (like fraud detection) not covered by another basis.
No basis except 6(1)(a) requires the subject's consent because the rest all cover processing required for the service to work.
https://gdpr-info.eu/art-6-gdpr/
===
Edit: I read "They're not" as "the bases aren't separate." On rereading, it could also be the interests aren't 6(1)(f) legitimate. Which, agreed, they're usually not. I'll leave this up in case it's useful to someone.
That was the point. Then to force your users to consent adds insult to injury and is in contravention to the GDPR.
Now say John travels to another town, and the proprietor of a similar establishment in that town, wanting to provide John with the best level of service, calls you to ask "Hey, what does John like?", and you tell them.
Now we just supplement your eyes and notepad with technology, and replace phone calls with packet exchanges. What has changed exactly? Don't you have a right to record who transacts with you? Isn't that information yours, to do with as you please? Can "John" command us to forget we ever saw him? Where in this sequence are anyone's rights violated? How is any of this reasonable?
Why exactly? Which laws would I be violating if I did?
Before we didn't have these laws because this wasn't a problem in practice - nobody was calling other businesses at scale to tell them who was buying fungus cream. If they were, we would've had a law equivalent to the GDPR to prevent that.
Actually, there was one incident in the US where a politician's video rental history was disclosed against his wishes and as a result a law was drafted to prevent this practice in the future: https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act
As a customer, I have no interest in you advertising for me, so it's not comparable. Any information that you spread around about me is likely to give other "shopkeepers" greater leverage over me (which is why vendors don't do this in the real world unless they have some sort of financial relationship with each other.)
Our government shouldn't be in the business of policing modesty or decency. Only administering the basic peace.
If you employed an army of people to be able to take photographs and remember or write down what every customer looks like, what time they come in, what they typically wear, how long they spend looking at each product, etc... most people will find that creepy and will take offense at that.
What if the data collection was done in such a way that most non-technical people aren't even aware what data is being collected and how it is used? In my hypothetical example about a business employing an army of workers to follow, photograph & take notes about every customer the behavior would at least be visible by the customers (and so they could choose to go elsewhere), which is not the case with modern technology - data is being collected silently in the background.
> why should it be illegal or regulated by the government in any way
There are plenty of other unlawful things you could apply this question to. Society enacts laws to dissuade & punish behaviors that the majority finds reprehensible.
Because that society has decided that it wants no creepy restaurants at all. Same with unclean ones, discriminatory ones, etc.
And yet I see every single supermarket offer their own membership card "to get discounts" and everybody is happy with it. The only purpose of that card is precisely to track your purchases.
It seems to me that some people in society decided that websites aren't allowed to sell ads based on what you view, but all the other tracking in our society is just a-okay. I've not seen a single campaign or push against predatory membership cards or credit card info being sold.
Depends if you're in the EU but I guess you could've lobbied against the GDPR when it was being drafted. You could also lobby against restaurant food safety regulations, or discrimination laws. The reason these laws are there and stick around is because a majority decided that these behaviors were noxious and should be outlawed and the current majority appears to be happy enough with the current situation to not demand laws to be changed.
> every single supermarket offer their own membership card "to get discounts" and everybody is happy with it
It is opt-in (you can decide to not swipe it when buying the aforementioned fungus cream if you don't want it associated with you), the data collection is relatively common knowledge and is disclosed when you sign up for the card (and if it isn't then that's a breach of the GDPR and should be rectified).
In comparison, online data collection is at best opt-out and at worst mandatory and often invisible (and even if you could see what data is collected from your browser, you have no visibility on what further processing is done on it or to whom it gets transferred or sold).
> but all the other tracking in our society is just a-okay
Source?
> I've not seen a single campaign or push against predatory membership cards
Those are opt-in.
> or credit card info being sold.
Every time the selling of credit card info comes up on HN people speak out against it just like they do against ad tracking, and the only reason nobody else talks about it is because they most likely don't know (would a reasonable person expect their bank to be sharing their purchase info with third-parties?).
Both of these issues are addressed by the GDPR by the way; it covers much more than just ad tracking on the web.
No, quite clearly I've opted-in to the site's content. No body has ever knowingly navigated to a website to enjoy its advertising and tracking. (except for maybe 3-5 individuals)
>You're the one that starts the chain of events in both cases.
This is victim blaming. I started the chain of events leading to the rendering of the website content, not the ads or tracking behavior to which I would otherwise be oblivious. This is akin to saying I asked for a computer virus by purchasing this computer.
So I actually like your analogy, it shows how insane the ad businesses and tracking is.
(Except for the part where you say the other business owner does it to give great service. Ads aren't used to help people, no one likes them)
With this definition, you do in fact have a right to breach any contract as there are no criminal penalties for doing so. That's why most contracts specify what happens if they are breached under various conditions. There's a major distinction between civil and criminal law.
That was already way too invasive, yes. You could probably get away with it before, because the scale was so small that it wasn't quite as horrible. There is after all a difference between occasionally violating one person's privacy and violating the privacy of thousands of people a minute. Not an actual ethical difference, but there are finite legal resources to go around.
Also, I object to this idea that because the pieces of behavior are acceptable the combined effect is automatically okay. It's perfectly legal to own and use a camera. It's perfectly legal to own an use a telephoto lens. It's even legal to look at your neighbor's house. Nonetheless, taking a camera and pointing it through a telephoto lens at a neighbor's house and recording 24/7 is an excellent way to get arrested.
You could just as equally declare copyright law or property law to be a religion and insist you don't want to subscribe to it, but society as a whole does, and so if you want to participate you just have to lump it.
If the majority of society was in favour of tracking everything then the opponents of that would have the same options of lobbying to change people's minds. As seen in the difference between end user reactions to GDPR vs ACTA, that seems like it would be much easier.
One thing you want to keep an eye on that is actually harmful to business (and economic freedom) is if some part of the economy gets caught up in a race-to-the-bottom. This is a situation where everyone's best move is to defect, and then defect again, all the way down until no one is free/making a profit/happy/etc anymore.
In this case there is a clear race to the bottom situation where everyone ends up having to track everything about everyone, just to keep up with the competition. As this would be pretty much truly be a panopticon-like tyranny by any other name, that's clearly not desirable.
In this case the EU is trying to make legislation that stops the race from going all the way down, by leveling the playing field so that everyone can conveniently say "see, we can't go further because it's actually illegal now".
So the net (long-term) freedom is actually increased by this measure.
Would it surprise you that it is in fact Germany that now has very strong privacy protections these days?
Laws conform with societal ethics and those ethics absolutely change over time and are never uniformly agreed to by all individuals.
Lastly - scale absolutely does matter when it comes to laws we want to enforce. We don't want to enforce a no-gossip law because the invasiveness of enforcement would be unbelievably deep, so decency is there to tell you that while you won't get arrested for doing a thing you should feel guilty about it - most members of society get equipped with this guilt during their upbringing and so criminally malicious gossip is a problem we mostly ignore at a societal level.
Laws are absolutely BS in their inherent nature and a construct of society that could easily shift radically with large political shifts - but that doesn't mean they're invalid.
To me that's where the right of one group (the government) to legitimately use force ends. The sledgehammer that is the legal system should only be used to administrate the peace.
Beyond that, the only concept that can really be impartially measured is liberty. How free are you? In the graph of all possible actions, which are legitimately available to you? Everything else is an attempt to define good or evil, or right and wrong, and is therefore some form of religion. In a world where we are all equal, have no oracle to discern good from evil, and disagree diametrically, the only reasonable thing to do is optimize for liberty, and let everyone figure it out for themselves.
Scale does matter, but not in regards to rights. If you have the right to do a thing, you have the right to do it a million times. If you have the right to write something down, you have the right to keep it in a database. If you can publish your letters, you can do so over HTTP as well. This isn't a new conversation. People have been publishing memoirs of their private correspondence since the printing press. What disturbs me is how we seem to be shifting our consensus that they have the right to do so.
This theory utterly fails to explain laws against murder from the millennia when there was no such thing as a state that claimed monopoly on violence. In the feudal system there was no such thing as a unified state entity, it was just a bunch of people invested with certain rights organised into nested hierarchy of fealty, no monopolies there, but still they had no problem ruling people guilty of committing murder.
> If you have the right to do a thing, you have the right to do it a million times.
You've never seen those signs that say you get only one free cup of coffee have you?
> You've never seen those signs that say you get only one free cup of coffee have you?
Indeed I've seen the signs. I would very much object to similar laws.
As an aside, I'm slightly curious how you explain the legality of said sign using your absolutist libertarian framework.
The legality of the sign is derived from the fact that it's on private property, from which the owner has a right to expel anyone for any reason. Violating the rules of the sign is simply grounds for expulsion from said property, not criminal consequences. That's the difference between a rule and a law.
Voting is an obvious exception.
So, you’re using Max Weber’s theory of the state in a contradictory way in my reading. Weber’s theory of the state as being the society which derives its authority from a legitimate monopoly on violence was contrasted _against_ the very “natural liberties” that you seem to espouse (e.g. the rights of peeping toms, the rights of private shopkeepers, and the limitation of the government). Either you argue that the legitimacy of the state stems from its legitimate monopoly on violence as a community (thus allowing it to dictate “decency” as you say) or you argue that the legitimacy of the state derives from the citizenry’s own natural rights to self governance and liberty.
In general it seems like you're just asserting that value judgements should be scale free, while ignoring qualitative criticisms.
I myself am a libertarian. A government is merely a large corporation that is impractical to opt out of. Conversely, corporations that are impractical to opt out of constitute de facto government. Data protection laws like the GDPR attempt to constrain the power of corporations so they don't rise to that level, which ultimately constrains the amount of government.
This fully depends on what you include in your definitions.
Imagine this: A company owns a vast area of land. You agree to contract with this company in order to be on their land. This contract includes things like using physical force against you if you violate other terms spelled out in the contract (just as you can contract to have violence done to you at a BDSM club). The contract defines a technical term "right", the definition of which spells out some things you're positively allowed to do, and is somewhat harder to amend but not impossible. The terms allow you to sublease a bit of their land for your exclusive use. Your sole way to terminate this contract is to completely leave the company's land and pay off any balance you owe. Call this company USG and it is indistinguishable from the United States Government.
> Find me one person who doesn't pay taxes and doesn't go to jail
Most people who have under the table income and don't report it. Same as how it's often possible to get around breach of contract when your counterparty doesn't find out. Model vs reality. And note how similar the requirements for keeping your income unreported mirror the requirements for avoiding transitive association with a given corporation.
> I know plenty of people who don't interact with FAANG at all
1. There are likely still surveillance profiles being kept on them. 2. It's hard to believe said people use the web for anything, given the prevalence of Google Tag Manager and CAPTCHAs. 3. More entrenched than FAANG are Equifax and LexisNexis, which are even harder to distance yourself from. I'd say it's easier to renounce your citizenship of most countries than it is to avoid the worst of the surveillance companies.
> Corporations will never rise to the legitimate use of force
You keep using this word legitimate, which entirely depends on perspective. I would say that it is plainly illegitimate to throw someone in a cage for smoking a plant, and so calling government inherently legitimate is a bit dubious.
Jus because that's how things are now doesn't mean it has always been that way or always will be.
The earliest Corporations originally did use force and in fact at times maintained armies and /or navies.
Corporations, as creatures of law, are an apparatus of government. And they’ve participate in the legitimate use of force from the very dawn of corporations as a thing.
...your right to swing your arm leaves off where my right not to have my nose struck begins. -John B. Finch
That's not how it works in the real world though. Why would a restaurant answer someone random calling them and asking what one of their regulars is typically ordering? I see no possible benefit in answering that question.
This only works in the online advertising world because whenever John enters a shop, restaurant or other establishment his photo is taken and sent to a central authority. That central authority can then sell space in some of those shops to push a product or service to him based on the history of shops he's entered.
To answer your specific scenario, it would be pretty creepy (and possibly illegal) if shopkeepers in different towns were calling each other and discussing my specific purchasing preferences.
I could equally ask "Isn't that information John's, to do with as he pleases?".
Property is a legal fiction, and "intellectual property" doubly so; but it seems perfectly reasonable that society should decide that information about a human person should be controlled by them, rather than by the artificial person of a corporation.
If John asks you to make his drink preference available to every competitor of yours, and you for some reason agree to provide that service to him, then of course John can get the benefit of that information sharing, but this should only happen if he specifically opts in to it.
(In reality you wouldn't provide this service helping your competitors, and the information sharing could be managed by another service, which John would probably have to pay for, and service providers would compete based on the security, speed, ease of use, and accuracy of their service).
Consumer privacy regulations don't control your brain and mouth, they control the incentives of companies, who are not humans, and do not have mouths or brains. Those companies then control the incentives of their employees who can choose whether or not to work for them.
Someone else can't control what you do or say, but they can establish consequence for what you do or say. Nobody can control whether you assault people or not, but they can certainly put you in jail for it.
> Anything else is awfully invasive don't you think?
I don't think so. Information that you got for the specific purpose of providing a service shouldn't be yours to spread as you see fit. In fact, there have been strict legal procedures in place for a long time for certain professions (e.g. medical sector) to enforce this.
Just like I don't expect my doctor to spread information about my hemmorhoids, I don't expect my bartender to spread information about my drinking habits.
Edit: grammar
You casually say this like it's obviously OK, and like it ever happens in the real world. If I'm doing business with you, and you investigate me to discover other people that I've done similar business with in order to ask them what I like, you're officially a creepy business.
The reason this is a matter of creepiness and not law IRL is because no business with more than a couple of customers could manage to regularly do this. The internet is what provides the dragnets, and the ability to be creepy at scale.
If you keep it in your head, it's not going to be stolen or abused. If you put it in a notebook, the risk increases, but you at least aren't going to be doing this at a large scale, simply due to physical limitations.
Various laws have different thresholds, but usually it's something like a "systematic collection of data" or "automated processing" (I think it's the latter for GDPR), which seems like a reasonable compromise to avoid hampering the low-risk small scale use cases.
Edit, looked it up, this is the definition GDPR uses:
This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
So if you keep your database in a notebook, you're probably still fine, because the structure makes it impossible to do nasty things at scale. Once you switch to alphabetically sorted index cards, you've crossed the threshold.
Should you have the right to watch which direction I'm going when I pass by at an intersection?
How about at the next intersection?
And the one after that, and the one after that, and the one by my home, and all the ones that I happen to go by when I next leave and go somewhere?
There's no single point at which passive observation turns into stalking but we still have laws against stalking and it's still perfectly ok and legal for you to watch where I'm going. If you understand why it's ok to look around you (and perhaps even take notes or draw what you see, snap a photo) but not OK to do that systematically around someone, you should also understand why we might want to restrict automated unwarranted and consentless data collection, even if taking some notes is OK.
The other thing is scale. Laws against seemingly minor things are enacted when that thing becomes widespread enough to upset many people. You probably don't upset people too much by taking some notes in a shop. If every shop had a fleet of staff dedicated to the same thing, that probably would upset people and lead us to a similar discussion.
Augmented capability lets you cause more, newer and larger problems.
We didn't have speed limits on the roads until humans acquired the technological capability to go faster, causing more fatalities.
In particular with data, the processing method makes a qualitative difference, between individual disconnected people each knowing one small snippet of your life, and a megacorp having an overview over whatever you're doing at every moment. By de facto limiting it to "one brain", the panopticon is prevented.
Your rights end where they start impacting other people's rights, and drawing those lines is what we have governments for. Even if you were to use just your memory, if you were tracking what someone is doing in such detail as ad companies do, you'd likely a) not be able to do that to more than a few people b) receive restraining orders for stalking.
That's unacceptable to start with.
>What has changed exactly?
You've automatized something unacceptable ?
>Don't you have a right to record who transacts with you?
Within a certain context, you do. The data that is untrusted to you is done so based on the assumption that you're acting in good faith and won't trade that information without consent.
>Isn't that information yours, to do with as you please?
Absolutely not, at least not in the legal systems we have in Europe.
>Can "John" command us to forget we ever saw him?
Yes, he can ! At least in my opinion and virtually every other European's he does. The right to be forgotten is an active subject of discussion[0]. The stance in the US is that it runs contrary to freedom of expression. The stance in Europe is that personal freedom implies being sovereign over one's own data. In technical areas, the right to be forgotten is interpreted as the right to erasure[1], which happens to be part of the GDPR. I've myself used that right several times. And I end up being very mindful of my usage of data in software I write.
>How is any of this reasonable?
Your ease of business doesn't trump someone's rights over themselves, the data they generate being a extension of it. End of story.
On what grounds exactly? When interacting with people they are able to observe you and record their observations. From where do you derive a "right" to control their behavior in this regard?
How could you classify an observation about yourself made by someone else as "yours"? How would you enforce this "right to be forgotten" when people carry around storage mediums made from meat? Or are you simply suggesting that you should be forced to go through all your letters, diaries, notebooks and ledgers on the whim of someone's demands?
1. When you enter it into a computer, everything changes. The scale with which data can be stored, distributed and aggregated is just staggeringly more huge.
2. People don't like ads, except for a few weirdos. Ads are not a service in the interest of the consumer.
3. Knowing someone personally is fine, but passing on that knowledge without their consent, or at least knowing for certain that it is in their interest, is a no-no.
And that's only the three most egregious things you get wrong.
People who attract new customers with ads must like them. People who were informed of a product that meets their previously-unserved needs must also, right?
3. is just plain old gossip, which is also what I'm describing. It has always been in poor taste, and should never be illegal or regulated at all. Only religions do that.
What was once 'I'm particularly fond of a certain shops version of a food item' can then become every shop selling that category of item automatically guiding you to the same type of item. Besides the part where everyone knows your name and a quick dossier like you're a celebrity but without any of the perks, life would be so drab if it was "The usual today John?" at literally every place everywhere always.
Honestly, more and more I'm starting to think GDPR is just an excuse to fleece "evil foreign tech giants". It's a set of arbitrary rules with vague and selective enforcement that seems not to be completely understood even by the legislators who wrote it, as demonstrated by legislators not knowing the answer to the simple question: Are pop-up consent forms acceptable. It's whatever the bureaucrats don't like that day really.
Guess some US company will have to go to court (and subsidize the European Legal Industry doing so) for the privilege of figuring it out.
It wouldn't be so comical if FAANG wasn't full of European devs who chose to innovate in the Valley, probably to escape this very bureaucracy.
Say we've learned over time that the color purple is really dangerous and needs to be regulated (work with me here for a second) .
Now try explaining "Purple Considered Harmful" to someone who is colorblind. The fact that suddenly grape juice is bad, but orange juice is good... weird. Or the fact that you'd not be allowed to mix tomato ketchup with blueberry jam. And you'd just randomly get fined for trying to sell that "dark green" sweater. Madness!
It would all seem quite arbitrary to the color blind person. Meanwhile someone with color vision would instantly see that all those things are purple, and thus clearly harmful.
The example might seem bit contrived, but something similar might be going on with the European concept of privacy.
People have been hurt due to PII issues in recent history, so one would like to keep control of PII. But try to explain that tingling spidey sense that has kept one's family alive in the last century to someone who has never encountered Nazis or Soviets before, and has instead lived a life of unfettered freedom. That might be rather difficult. Especially if you can't get the base concept across, and need to do it in terms of (very arbitrary seeming) examples.
And Valley is pretty much there because when the long chain of capital-hungry events was building it up, we were still rebuilding from last war while funding preparation for take three thanks to Truman.
You almost certainly had a legitimate interest in remembering your guest’s preferences, but retaining only the necessary amount of personal information is key, and sharing it with other firms is more restricted- an example of where this could be legal is in sharing warning of violent guests.
Note that even then this seems to be just a ruling and actual consequences are still dependent on individual regulators. Given their prior lack of action it will presumably take years before we see any fines resulting from this.
And another article on the topic: https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach...
In my layperson's knowledge of GDPR, these awful consent popups always seemed completely illegal:
1. They prevent access without a lengthy/arduous process. Certainly in violation of the spirit of the legislation and almost certainly also the letter.
2. This was of course entirely intentional, in order to annoy users into clicking yes and laying blame on the GDPR
"The GDPR made us annoy you". It doesn't.
3. They often do not allow a single click deny, you have to go through sometimes dozens of vendors and deny them one-by-one. This is so obviously illegal it isn't even funny.4. What's worse, if they do have a "Deny all" button, it's almost certainly there to trick you.
Because they have essentially the same list of trackers duplicated under the "legitimate interest" category. Which "Deny all" won't catch. You have to "object" to the legitimate interest. So if you hit "Deny all", you will instead be tracked by all.
This is so brazen it's almost breathtaking.
Anyway, good to see progress on this front. The ad-industry is still in deep denial about GDPR, thinking that they can continue their business model in the face of it. They can't. Their business model is illegal, and has been since GDPR came into force.The conflict has been brewing for some time now, weaving its way up through the channels.
Exciting times.
I have signalled my default intent, and I have not changed it. Respect it.
Of course, the ad industry is hell-bent on preventing anything convenient.
Instead they exploited the apathy & incompetence of the regulators with their so-called "consent" flow. Considering the GDPR was supposed to be enforced since 2018 and they've made it to 2021 without any consequences I'd say that strategy paid off.
It's an inconvenient fact that - perhaps a decade ago - we had DNT, and advertisers were starting to respect it, but then browser makers decided to default it to on, making it pointless.
I'm not sure that was the sole downfall; DNT also had no teeth because it couldn't really be enforced.
I think Microsoft's default-on stance was likely intentional sabotage - Google operates a big ad network and would have to deal with a lot of the fall-out.
However while the ad industry might be okay with a few nerds opting out they weren't okay with most of the general public opting out and so they spread stories like the one you repeated.
There's a lot of money in advertising.
The feasible choices are between (a) DNT, off by default, that the more responsible and regulated side of the ad industry respects or (b) DNT, on by default, that everyone ignores.
Which one is the greater good?
In other words, you're welcome to walk up to me, slap me in the face, and call me a son-of-a-bitch... but that's probably not a great start to a conversation that ends with "Would you please work with me on this?"
And no, I don't want to "work on this", I want to not be tracked by default.
Wow, that's quite some re-framing going on there, if you're casting yourself as the advertiser in that sentence. It's more like if you were regularly "borrowing" my car without permission. Do not track is a bit like the lock on the car, which obviously you can get around in 30 seconds flat. Everyone has a lock on their car, right, and it's installed by default, so by the advertisement industry's reasoning it isn't a true indication of whether I want you "borrowing" it. If you were regularly "borrowing" my car without permission, it'd be reasonable for me to walk up to you, slap you in the face, and call you a SOB, but I'd me more likely to just call the cops.
Data about me is owned by me, and other entities can process it only in strongly limited circumstances. That's the default position, by the standard of basic decency, and also in law. Stop making it sound like me demanding control over my own possessions is unreasonable.
Often it is. Firefox, Brave and Safari explicitly advertise themselves as privacy-friendly browsers.
That leaves non-savvy users who just use whatever defaults exists, but there is an even stronger argument to protect precisely those people - you can't consent to something you don't yet understand.
Tracking can leak extremely sensitive information, just like microphone, screen sharing and webcam permissions could. Protecting the user is a sane default in all of these cases. The fact that personal data has commercial value is secondary, just like it would be with webcam access.
Imo, the only meaningful difference between tracking and camera access is that fully-fledged tracking was an accidental side effect of third-party cookies, and before "we" understood the implications of that a trillion dollar industry was established. The reason we're apathetic to tracking is because it's abstract and novel, whereas snooping to your audio or video is easier to grok.
Unfortunately they didn't specify that it should be up to the consumer how they wanted to signal their intent and not the website.
When the legislation first came in I reported about 100 websites that were breaking the law in obvious ways, they are still like that and the ICO hasn't even responded to those complaints.
And this worked. Even on HN an awful lot of people blame the prevalence of cookie banners and consent forms on GDPR, and call GDPR a stupid law.
All you need is to build this in to devices sold in EU - iOS, Android, Windows...Each give you privacy controls at the OS layer that applications must respect, on the browser level, this may be a "reject tracking and cookies". Boom. Done. All EU websites will be required to check for this API and their JS code must be plain to see for any visitor using the "view source" option. Going forward, we can build privacy controls at the technical layer, so regardless of the'stack'/'layer' software and hardware is built with GDPR in mind. We are still a long, long way away from that reality and truthfully, we will likely not be there for many decades.
Sadly, it seems this "cookie" debacle is one that is more society based than technical, and it's obvious cookies should probably be replaced by now with better solutions.
Maybe the GDPR might finally yield some positive changes but I remain doubtful. The industries it wants to disrupt have powerful lobbyists (hence why most right to repair legislation doesn't dare challenge Apple, for example).
The GDPR mandates that data subjects provide informed consent before you are able to collect and/or process their personal data for non-essential purposes (ads & analytics don't count).
The technical means you use doesn't matter. It can be cookies, but it can also be browser fingerprinting or IP addresses (which you can't deny as the remote server needs to know your IP to communicate with you), or it can even be information you manually enter (such as name & address for payment processing).
A purely technical solution will only cover the black & white case of "provide the data or not", it will not cover more nuanced cases where you need to provide the data for essential purposes (the IP so you can load the website, personal details for payment processing) but do not wish this same data to be used for other, non-essential purposes. A legal solution here is needed and that's what the GDPR is about.
If you do that today, you will never get past the GDPR popups.
The point was to force websites using cookies for "dubious" tracking purposes to be forced to show the banner as a mark of shame so that users would naturally migrate to websites not spying on their users and therefore not showing such banners.
Obviously, this universe being the dystopia that it is, every website started showing these banners overnight and users started ignoring them anyway.
If you just enforce all browsers to ignore cookies period, then you have another X-Do-Not-Track-Me scenario (or whatever it was called), where everyone just sets this flag and therefore tracking continues, just using other methods.
IAB Europe is some kind of advertising/marketing thing.
No relation to the Internet Architecture Board.
GDPR requires explicit consent and childish excuses like "your continued use implies ..." not only does not count, but does not exist as a concept.
Sadly the majority of cookie "consent" banners is still in breach of GDPR.
The main word I can find that seems like it might be regarded as over-emotive is "plagued". Is it that kind of thing? [ OTOH, bad GDPR popups are pretty much a scourge... ]
edit: oh I guess the stuff about advertising firms depriving people of their "fundamental rights" is yeah a bit over-wrought...(though privacy is important, at least to me, and I think it's ok for a civil liberties organisation to care a lot about it).