Statement on 4 Years of GDPR
noyb.eu
noyb.eu
Which is quite nice for folks like me, who always clear browsing data upon exit.
This of course relies on sufficient enforcement of the regulation to act as a deterrent which is currently not the case.
I have noticed that despite having all the settings to wipe data, not just cookies, cookies are still left.
These are my start page tabs in this order.
edge://settings/clearBrowserData tab all I have to do is click "Choose What to Clear", get the popup window, Time Range - All Time, all options ticked. Once completed but this can hang the browser for upto several minutes once done I switch to the second tab.
edge://settings/siteData tab hit refresh (F5) to see what cookies get left behind and thats when I see sometimes, cookies get left behind, usually youtube.com cookies, they will be blank but loads of youtube cookies.
edge://favorites/ tab, positioned to Favourites bar and have nothing on there because the browser pulls down site icons so you can identify people (browser fingerprinting) from the icon combination that gets pulled down.
edge://application-guard-internals/#status tab can see if its working properly, noticed when its on, youtube video's dont work its always trying to get get data, the stats for nerds show nothing comes downs or minimal 1kb amounts.
edge://policy/ tab because I like to switch these around to create a different fingerprint from the devices that are accessible.
However enforcement is indeed severely lacking as this article describes.
There has (perhaps predictably) been significant lobbying against that by entrenched industry players, so we'll see what emerges as a result.
(I have to admit I'm not up-to-date on the latest happenings regarding this regulation)
You would find cookie consent options in your browser settings (for example, near "Privacy Settings"), and you would configure your rules there (with sensible defaults).
You shouldn't see any cookie consent pop-ups while browsing the web, as a result of that -- your browser would communicate your preferences for you.
As I said though: I'm unclear on the status of the ePrivacy Regulation.
Cookie compliance
To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies.
Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
Document and store consent received from users.
Allow users to access your service even if they refuse to allow the use of certain cookies
Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
Consent is part of the GDPR, but the way I've seen it operate in practice is widely out of compliance. You're supposed to ask for consent in each specific instance of data collection, not present a blanket approval, and default to "no."
Cookies and the GDPR The General Data Protection Regulation (GDPR) is the most comprehensive data protection legislation that has been passed by any governing body to this point. However, throughout its’ 88 pages, it only mentions cookies directly once, in Recital 30.
Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
What these two lines are stating is that cookies, insofar as they are used to identify users, qualify as personal data and are therefore subject to the GDPR. Companies do have a right to process their users’ data as long as they receive consent or if they have a legitimate interest.
I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated.
Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.
This is made even more frustrating by that at least I find GDPR to be not very precise. There are lots of corner cases where it's not clear if some data is covered or not. The strictest interpretations would easily obsolete / criminalize vast majority of ALL software that people today absolutely depend on for their daily lives - like various financial backbone systems - and which largely predate the GDPR.
It's hard to not find the regulation a joke - sadly. While GDPR is not precise, I won't even go into the details about the ridiculous cookie law and the braindead portions of the new 2019 digital copyright directive (that French publishers lobbied in to hurt Google News). If GDPR left you in doubt, that idiocy really showed that these EU bureaucrats are completely out of touch with the reality in the field of technology they want to control.
Honestly, the main thing it revealed is how little value a particular segment of the technology community places on protection of individuals' data. It's actually hard for me to think of any better example of regulation that is designed and written to be in-tune with the technology involved.
Yes, this makes many, sometimes ideotic things, illegal. But not I also cross a red light on foot from time to time and I do not think it should be made legal. Regulations that leave a freedom what to prosecute are not bad by design.
> But not I also cross a red light on foot from time to time and I do not think it should be made legal. Regulations that leave a freedom what to prosecute are not bad by design.
This is not comparable as private citizens are able to petition and sue under GDPR. Hence, there is no similar discretion of what actually gets prosecuted as for jaywalking. It would be comparable if I, as a driver of a vehicle, was able to take any jaywalker to court. Which would be indeed complete madness.
In which case is the IP address in the access log helpful?
And that's just one small aspect of becoming fully compliant, there are millions of other types of surprising data that can be PII, and hence a liability, under GDPR. Email and IM apps, like Slack, are another interesting conundrum. Under GDPR, a customer should be able to request that all emails and Slack messages that contain/discuss his/her personal information must be a) discoverable and b) erasable. How do you even begin to solve that is beyond me..
For GDPR and any other law that enforce something on you, that it has to be reasonable for you to comply. So in my personal interpretation any data you provide and identifies should be auto deletable (a post linked to your account). If I post your PII and you request HN to delete it - they are required to delete it.
I don't think GDPR is too crazy .. but some people try to scare others because they scare to change because of making less money, ..
That’s actually very clear and a simple example that anybody with passing familiarity can answer - and specifically you do nothing, since there is no right to erasure in this case. The “right to be forgotten” only applies in specific circumstances, under article 17: https://gdpr-info.eu/art-17-gdpr/
You have a legitimate interest in keeping server logs, so your responsibility is basically to have a clear and justifiable policy for why you are storing it, store it securely and for a reasonable time, and to make subjects aware of all this.
It’s way less complicated than you’re making out.
This is an inversion of the rule for legitimate interest processing, where the processing is legal unless there is an overriding interests, rights, and freedoms by the data subject. Basically, in the middle ground where neither set of rights and interests clearly override the other, the controller can legally process, but can also be forced to delete via the objection mechanism.
The fact that there is little clear guidance as to in what circumstances one set of interests, rights, or freedoms should override legitimate interests or vice versa, it does make this area of the law basically come down to somewhat arbitrary decisions of the relevant DPAs.
Recital 47 seems to suggest that for the normal direction of overriding interests, most situations where the average person would not be surprised/annoyed if informed about this processing in the specific circumstances is likely to be be permissible. But with Art 21(1)'s reversed burden, the guidance is simply "It should be for the controller to demonstrate that its compelling legitimate interest overrides the interests or the fundamental rights and freedoms of the data subject." No guidance at all about how much or low little this differs from the what is permissible via Art 6(1)(f). Clearly some difference is intended since the wording is clearly reversed from Art 6(1)(f).
It leaves legitimate interests processing (which is by far the one of the most common processing reasons, and probably is common than all the other lawful reasons combined) as basically a giant minefield until the DPAs have established enough "case law" (for lack of a better term) to make sufficiently clear how they balance these competing interests and rights and freedoms.
You don't, nor would you be required to, assuming those logs are being collected for a legitimate non-profiling interest, like detecting abuse, and are only kept for as long as reasonably necessary.
Lets take a look at the cases in which right to be forgotten even applies:
> the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
This would be fair enough if you are keeping the data for longer than necessary, but if you are doing so in such a scenario, you are almost certainly in violation in other ways.
>the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
Not consent based processing, so inapplicable.
> the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
22(2) is direct marketing related so inapplicable. 21(1) is interesting. It allows for subjects to object to legitimate interest processing. The controller must cease processing (including storage based "processing") the data upon such objection "unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims".
But it would not be hard to show that log data important for abuse prevention overrides the interests, rights, and freedoms of the subject here. We are talking about data that is almost certainly not particularly revealing or sensitive to the subject, with a relatively weak personal identifier (IP address), that is not publicly visible, that will automatically be deleted once it is too old to be relevant for such purposes. (probably after only one or two months). We are not talking about say a publicly available archived news article that mentions the street on which the subject lives or anything like that.
>the personal data have been unlawfully processed; >the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
Neither of these would be applicable.
>the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
Ok, if you are running a social network, or youtube or something, and the data subject is a child, but they are either over the age of 16, and under it, but had parents consent on their behalf, then technically these logs would fall under this bullet point, and would need to be deleted. Art 8(1) only applies to procesing by consent, but if such consent were given these logs would obviously be related to the offer of such services. This scenario is not really what was intended though, and is poor wording in the law. (The law has a lot of poor wording!).
The idea here looks like it was supposed to be that Children's data processed by consent must be deleted if consent revoked, even if you still retain other legal grounds for that processing. Normally those other grounds would let you refuse to delete the data, but because ramifications of providing data under consent may be unclear to children, they get to revoke it more strongly than adults.
One question I've always had with this is whether it counts as personal data if it can only be de-anonymized by combining it with other data. So Company A manages some subset of a person's data.Company B manages a different subset (different app or whatever). Individually it is completely anonymous but if you combine them, it's trivial to de-anonymize.
Is this covered by GDPR? Both companies? What if one company dissolves and that data set is deleted?
Obviously a contrived example but an interesting thought experiment, I think.
- GDPR-like legislation existed in most EU countries waaaaaay before GDPR.
- It was known for years that GDPR is coming.
- GDPR specifically gave companies two years after going in effect to get their act in order.
- We are now 4 years after GDPR went in effect.
If you're still complaining that it's "a drakonian law that doesn't let your company do haphazard PII processing aka collecting PII wholesale with no consent", then you company deserves to be sued and fined out of existence.
In order to get a fine you have to act evidently in bad faith or to lose your users’ PII or credit card information.
People don’t get fined billions because a legacy system saves an email address in the wrong table.
I think this is an extremely poor excuse. You're basically saying they don't understand their systems well enough. It is like a chemical company blaming environmental legislation when they've left barrels of polluting chemicals all over the place and not kept track of them.
Wasn't this called out repeatedly over the years and obvious from the start? That a double forum shopping model will produce paperwork and voluntary compliance, in cases where the offender literally didn't know they were misbehaving, but little real action?
[1] https://www.heise.de/news/Kein-Bussgeld-fuer-die-Datenpanne-...
This is the problem of German regulators being too cozy with incumbents. (Also see: Wirecard.) It's related, in that if you're one of the incumbents a regulator is cozy with, you're going to fight to switch forum to Germany. But it's a different problem with different solutions.
https://techcrunch.com/2021/12/20/facebook-transfers-impact-...
https://noyb.eu/en/irish-dpc-burns-taxpayer-money-over-delay...
(DPC = the official Irish body who should be responsible for enforcing GDPR… in bed with Facebook instead. Somewhere between shameful and criminal.)
Speaking as an Irish person, it's probably more accurate to say that the DPC is woefully under-resourced, and FB are super litigious so its more the government haven't given the DPC enough resources to do their job.
This is what makes writing good/effective law a non-trivial undertaking.
If the words on paper don't make positive sense, and negative behavior toward the words isn't backed up with punishment, then the effort corrodes and collapses.
I shouldn’t have to tell people I don’t want to be spied, nor I should have to install privacy extensions and PiHoles and whatever.
> Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate argument.
All the time. It's just important to recognize this type of argument as pointless.
This is a disingenuous framing of the argument as it commonly appears on HN, sometimes by me.
The complaint isn't with respect to what the rules permit and prohibit. (Some people complain about that, but it's not the common mode.) It's the enforcement mechanism. Complaint initiated. Multi-forum and portable. Imprecise on implementation details. Those factors make compliance, even for someone looking to do everything right, expensive. Which raises barriers to entry. (And creates room for mischief.)
The closest similar thing in the U.S. is our approach to securities regulation. Complaint initiated. Each state has its own forum. Each side can complain and defend in different forums and then expensively argue over arcane rules for forum selection. Details hashed out through enforcement actions versus ex ante published rules. Now imagine there was no SEC corralling the mess. That's GDPR.
Because when "you're the not the customer, you're the product" applies, then the GDPR does effectively undermine the business model. Targeted advertising appears to be immensely profitable; raising boundaries on how you process subject's data, and how/to what extent you profile them, cuts into those profits.
The GDPR recognized the protection of PII as a fundamental right. The way I read the argument I quoted, the problem is not that e.g. Facebook would like to comply with the GDPR but cannot do so for e.g. imprecise implementation details. The problem is the GDPR significantly impairs Facebook's ability to generate revenue. And to that end, it appears that Facebook is indeed "openly ignoring" the GDPR to some extent, at least from what I recall from the ongoing complaints by NOYB and others.
[To clarify, I don't disagree with your particular argument; on the contrary, the flaws you pointed out are evident. I just don't think that is was the argument being made here.]
i.e.
https://www.adexchanger.com/data-exchanges/tapad-is-shutting...
Users loved it and expressed their delight that the website exists on a daily basis.
But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody.
Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense.
So I finally took the plunge and turned the site off.
My feeling is that the GDPR plays into the hands of the big web players. They have the resources to deal with it. While small one-man shows don't.
Maybe it's easier to sell merch.
I play Wordle most days. I do enjoy it. The amount I'd pay for it is $0, because there are a thousand other free options that would entertain me just as much. Maybe not even word games. Maybe just Microsoft Solitaire. Apple's Texas Hold 'Em. Minesweeper. Nokia Snake Game. Whatever. Despite playing Wordle so much, if you told me I had to pay $1/month for it or else it'd disappear completely, I wouldn't do it. Its competition includes free stuff like watching the clouds go by, or flicking little paper wads at the trash can.
It's also not all that hard to comply with the GDPR as a small website.
That seems more of a problem than GDPR exposing that underlying issue.
edit: seems like Google have a non-personalised ad option, but it still uses cookies:
> A Non-Personalized Ads solution (Ad Manager Help Center, AdSense Help Center) allows you to present EEA and UK users with a choice between personalized ads and non-personalized ads (or to choose to serve only non-personalized ads to all users in the EEA and the UK). Non-Personalized Ads only use contextual information, including coarse general (city-level) location. Although these ads don’t use cookies for ads personalization, they do use cookies to allow for frequency capping, aggregated ad reporting, and to combat fraud and abuse. Consent is therefore required to use cookies for those purposes from users in countries to which the ePrivacy Directive’s cookie provisions apply.
But have we forced every non abusive advertising platform out of business as a result of tolerating this abuse for so long?
There sure is: Contextual ads. DuckDuckGo does it, various documentation sites do it (https://www.ethicalads.io/), a dutch broadcaster does it (https://archive.ph/Zk4Pv). It's how newspapers used to work and TV channels still do, as well as YouTube sponsorships (and probably many more).
It improves the UX over personalized ads because
a) you don't have to invade your users' privacy (including asking them for permission to do it, obviously) and
b) the ad is actually relevant to the context the user is thinking about, instead of something completely unrelated from some other part of their life (or, more often than not, something completely random).
Besides ... most current ads are distasteful regardless of context.
Reading into it, looking up the legalese, building a solution that shows a cookie banner and prevents ads to load before users agreed to it etc.
I only gave up after all of that failed.
It just became unjustifiable to throw more time at it.
It takes the liberty to dynamically inject stuff into the site. Even after the user provided consent. Maybe so the user always has a menu to change their settings.
They seem to try to put that dynamically injected thing below the fold. So maybe blog like sites don't mind.
But on my site it wrecked havoc.
I tried for a while and couldn't fix it.
(can't be 100% sure this is what made Spotify change direction, but it seems likely)
That’s not bad at all.
The music industry purposelessly makes it harder and harder to get lossless file based music for the first world, save for indie bands on bandcamp and the occasional release by a triple A band/label.And again, this is next to impossible in developing nations.
I don't have hundreds of hours and thousands of dollars to dedicate t getting every song I want to listen to on a whim in the above mentioned format, and I have much less time and money to manage those across my devices in a format that is anything short of maddening.
I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests.
They can't fine me, I don't have a physical or business presence in Europe, though I do have European customers.
The only reason I handle requests is to protect my customers, not myself.
The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not.
If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so.
What US law requires a US citizen to comply with EU law?
If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe.
GDPR is framed as a human rights law, and that has long-reaching claws.
It is currently not well-enforced, but there are many examples of clawbacks coming in. For US slavery, those clawbacks are coming 160 years later: buildings, businesses, and schools are being renamed. Statues are being torn down. In some cases, you're starting to see reparations (see Harvard). Milder versions of racism are subject to cancellations; things acceptable in 1980 are having repercussions on people's careers in 2020.
Then you've got issues of when you're persecuted for an unrelated reason, and the government is looking for an excuse or pretext to take you down. A famous mobster was taken down a century ago for tax evasion.
I want to be clear I think they have a moral and ethical obligation to delete that person's information if so requested. There's just no (legitimate) legal requirement. The huge jurisdictional overreach by GDPR is part of why you're seeing companies just outright ignore parts of it.
Reasonable people can disagree about whether or not GDPR actually covers anything in the spectrum of "human rights" but for the love of god slavery has nothing to do with anything about it.
Reasonable people can disagree about the extent to which privacy is a fundamental, human right, or where the bounds are, but that is literally the phrasing of the law.
Reasonable people can argue about a lot of issues, and views on rights change with time. Ancient Greeks and not-so-ancient Afghans had sex with kids. Just over a century ago, women couldn't vote. It's hard to predict how views on human rights will evolve. Right now, there are huge cultural disconnect about a lot of things digital. It's not clear where they'll land.
Also, I still find it weird that the EU (GDPR) laws apply at the client (visitor) rather than at the source (server). The question is: is the server providing a service in EU (sending a webpage) or is the client "going" to a server in the US?
If people start caring enough to actually cancel services that harvest their data, then the harvesting would stop. But it is very easy to underestimate the power of machine learning and correlation, especially when the data being correlated is gently sipped over years.
That's at least partially the intention, and I'm entirely in favour of it.
Great. "Data harvesting" without explicit consent should not be a thing.
> If people start caring enough to actually cancel services that harvest their data, then the harvesting would stop.
I think that's quite naive. Much harvesting comes from websites that share data with each other about individual user behavior. There is no service to cancel unless you mean "browsing the web".
NOYB has more information, it seems: https://noyb.eu/en/projects
No, it's pushing against megacorps (and corps) and they're trying to gaslight everyone into thinking it's pushing against users by annoying the users on purpose and telling them the GDPR forced them do it (while also breaking the law and still hovering up as much data as they can while they think they can get away with it).
4 years on, and people still think GDPR is about cookies – and even responsible for the intrusive consent pop-ups!
It is a testament to the power of the adtech giants and all the other shitty shady businesses, how they managed to twist the narrative.
And that's on HN, a presumably tech savvy audience. What chance does the "normal" population stand?
2. It's not GDPR that made it worse but ad-tech and similar leeches who want to continue vacuuming up all available data without reprecussions
I agree they should have thought better of that cookie law, which is a different one. But GDPR really was and is on point.
They chose to put up cookie banners as a way of making to seem like the people making the laws told them to do it.
> 99% are just fake. If you reject cookies you keep get them
This is silly. The rule is that people are allowed to opt 𝚘̶𝚞̶𝚝̶ in to tracking. Just because some companies use cookies for this doesn't mean that cookies are banned.
If you are using cookies to store your website's settings then that is perfectly fine.
Sorry to correct you, but the rule is that people are allowed to opt-in to tracking. This fundamental misunderstanding is kinda the problem...
And even after opting in, you are allowed to opt out.
The problem is that people think the cookies are the problem, when in fact it's not the cookies but the tracking.
The GDPR is about data processing consent as a whole, regardless of how the data was collected. It includes data that you can’t withhold such as your IP address, browser fingerprint, etc.
They need explicit permission to track you. The browser doing absolutely nothing is what most people want.
The website can set whatever cookies it wants for the activity of the website itself.
No, all websites that have cookie banners do so because they were already ruining the web, the only thing you can blame GDPR for in that regard is visualizing it.
It creates visibility where there was none.
Fake cookie banners are illegal under the GDPR. Seriously, in what other aspects of life do people respond to terrible enforcement by saying the law is the problem? (Of course there exists a bunch of stupid laws that are also terribly enforced, but here the objective of the GDPR is not stupid – it's merely a matter of terrible enforcement)
> Cost money to company (so cost to customers)
Most regulation comes with a cost. The fact that this does, too, is kinda meaningless on its own. Food safety regulation comes at a cost – that, in itself, is not an argument against such regulation.
> A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.
Are you seriously arguing that legislation to enforce such privacy standardization would be easier to enforce than the current GDPR? By all means, what you're proposing sounds great – better than the GDPR even – but massively harder to do.
Every other case where the law is widely broken and selectively enforced? From low-level traffic offenses to drug legalization.
Note that cookies that are technically required to serve the site don't need a cookie banner. This is something many people get wrong. Other people shift to LocalStorage instead. But the actual legislation does not distinguish between cookies and local storage (and similar techniques).
Also, there must be a "reject all" button which should appear visually equivalent to the "accept all" button. Rejecting all has to be as easy as accepting all. Additional clicks are not legal.
That's illegal, then.
They're not obnoxious because GDPR made them that way, they're obnoxious because companies who think they have a right to unfettered and undisclosed abuse of people's data (because that's what they were used to) are trying to pretend that the law is the problem and not their malfeasance.
A fully compliant GDPR banner has two buttons, of equal prominence: reject all, and accept all. That's it. Any obnoxiousness is on thy implementor, and it's likely illegal.
Another fully compliant solution is to only collect the data you actual need and then you don't even need a banner at all.
You can't necessarily raise prices just because your costs go up.
The most hilarious thing is cookies!
For example, cookies exist, and they work a certain way... and despite not liking how they work.. they are here, and not going away, and imposing some kind of contract-law of cookies being accepted or rejected totally ignores that the user has, and always had, the ability to reject cookies at the browser level, unilaterally or with policies, without any contract laws.
How does one actually do that? Embed a session id in every request/response?
Right, through cookies - unless you want to embed the session ID in every single link or button in the whole page. The way pages "contain" session data like that _is_ cookies! snapetom mentions embedding in query parameters, which while a possible solution, seems even worse to me, as it means sharing a link to the current page you're on leaks your session token. I'm really not sure I'm following what you're saying here.
EDIT: What I originally wrote is somewhat off. It was directly in PHP: https://www.php.net/manual/en/session.idpassing.php
I don't know if I'm remembering right, but I seem to remember some early PHP framework or templating system, $_SESSION variables could be configured to use query parameters instead of cookies. So every link generated by the framework automatically inserted a "?SESSIONID=12345" at the end of the link. The backend translated this into the PHP $_SESSION object.
Because big companies with deeply unethical business practices are basically saying: "if we annoy you to death, maybe you get governments off our backs and let us make even more money".
They're like Big Tobacco when tobacco ad regulations were introduced.
It was quite clever - make people believe the legislation is for their benefit, whereas in reality it has been created to help with data abuse and make money off of it.
I'd happily replace that whole cookie mess.
Sorta? I don't consent to much when I get the pop-up. You can revoke consent at any time as well and you're entitled to the data the company has on you.
You have a bias for being a tech person who understand this, but vast majority of people have no idea what it is about and they just consent because they don't care or know the impact of their decision.
Do you have a link to the study that shows this?
Amazon Europe Core S.à.r.l. Industry and Commerce LUXEMBOURG 746,000,000 euro Non-compliance with general data processing principles 16 Jul 2021
WhatsApp Ireland Ltd. Media, Telecoms and Broadcasting IRELAND 225,000,000 euro Insufficient fulfilment of information obligations 02 Sep 2021
https://www.enforcementtracker.com/?insights In 2021, Amazon EU S.à r.l. had a revenue of over 51 billion euros
Can't find numbers on profit, but companies such as amz are experts on creativity, as indicated by eg this quote: Amazon paid zero corporation tax in Luxembourg last year, despite seeing a record sales income of €44 billion.
As first reported by The Guardian, accounts for Amazon EU Sarl published online showed that despite making billions of dollars in sales, the company's Luxembourg unit, which oversees retail in countries across Europe, made a €1.2 billion loss and therefore paid zero tax.
Not only did the company not have to pay corporate tax, but it was also handed €56 million in tax credits to offset future tax bills in the event that it does turn a profit. That also comes on top of €2.7 billion in losses that have been carried forward and can be used to offset future tax bills.
Ie, not a sledge hammer.> even worse just retract from the market
I disagree that this is worse - if privacy-violating monopolies retract from the market then it opens the doors for privacy-respecting competition to take its place.
On paper yes, great intentions[1], in practice no. E.g. Right to be forgotten.
Implement RTBF in context of IPFS.
[1] Second order effects like prevent rats/snakes by awarding award for rat/snake heads, lead to rat/snake farms.
> if privacy-violating monopolies retract from the market
You get Splinternet. Several independent Internets, walled from each other.
> Implement RTBF in context of IPFS.
How does IPFS deal with CSAM being published on it? Not saying it should detect CSAM, but once it is found, how does one go about having it removed? You use the same system to handle RTBF, and if you can't, then maybe a platform where it's literally impossible to delete something isn't a good idea (partly because undesirable content will ultimately outnumber legitimate content)?
> You get Splinternet. Several independent Internets, walled from each other.
If there's an internet where Facebook and Google can't spy on me, sign me up!
So do people with skeletons in the closet. Not saying you do, but right to be forgotten can infringe on other people's right to be well informed.
This is not a hypothetical. It has already happened.
> How does IPFS deal with CSAM being published on it?
Using CSAM to justify a law, is not a winning strategy.
It would be tedious but probably destroying all nodes. Which means IPFS is not compatible with RTBF.
> If there's an internet where Facebook and Google can't spy on me, sign me up!
That does leave state actors though.
The impossibility of the assured annihilation of data is true of all protocols for data retrieval so long as client nodes are free and able to copy the data retrieved.
It's why removal of illegal content from the internet has been an abysmal failure.
Could you elaborate on the second order effects?
>The GDPR (European Law)
> As of May 25, 2018, a new data privacy law known as the EU General Data Protection Regulation (or the "GDPR") went into effect through the EEA countries. SafeGraph does not offer products or services involving the collection or sale of “personal data” in EEA countries. We likewise seek not to collect such personal data from our data providers. Should any of the foregoing change, we will update this section of our Privacy Policy.
If this is not a net win, I don't know what is.
This is like saying that regulating damage to the environment is bad because would make businesses that can't exist without doing said damage would retract from the market. Good riddance, if a business can't or isn't willing to protect EU's citizens data they should go away, like many polluting industries that had to adapt or die.
Sure if a global problem is only taken by a small subset of states. It's not solving a problem just essentially grandstanding. See climate change.
But GDPR and related laws have been a mixed bag and a combination of neat and "why the hell do you think that will work?".