Can ads be GDPR compliant?
jefftk.com
jefftk.com
USAToday used to do it via deals with hotels to put one outside your room. Boom, extra copies!
They still didn't have a great idea of how effective they were a lot of the time of course.
Maybe the web needs something like Nielsen ratings, where Verified real users voluntarily submit their browsing to help advertisers determine watch time.
Unless you had something like 10% of real users or a super representative 1% I think you'd have a big problem with getting realistic numbers outside huge sites.
It probably works better on things like podcasts but the bottom line is that you can't really trust me to tell you how many viewers my site had without some fraud detection mechanisms in place. (And even then fraud is apparently pretty rampant.)
There's more about this near the end of the post.
yes, you might WANT that. but you do not NEED that. Remember that ad's isn't only effective when clicking on it, but also by spreading visibility of your offer/product.
you could easily use sites visitor count as a estimate for monthly pricing. And frankly without all tracking there would be no incentives to fake click on ads at all, so you could get your own tracking on your own side.
The web cannot do that without tracking...
You might not trust them but I don't see why you'd think a newspaper would have a harder time claiming they've made more copies than they have.
Now, you could say don't do business with people who are trying to defraud you, but one of the more impressive things about the ad ecosystem is that it works without advertisers and publishers trusting each other. I can sell the space on my site and advertisers don't need to figure out how much to trust me in particular.
It's easy to have ad fraud that's plausibly deniable and maybe even not on purpose. Let's say you're a publisher and you want more people to come to your site. You look around and you find someone who says they run a newsletter and would be willing to include links to your stories for a small fee. When you multiply out the cost per visitor this looks like a pretty good deal; you say yes. This traffic turns out to be entirely bots, but you can't tell because we got rid of ad fraud detection.
For a person who worked in ads you are surprisingly oblivious to how both Facebook and Google defrauded advertisers and publishers.
- Facebook Lied About Video Metrics and It Killed Profitable Businesses https://www.ccn.com/facebook-lied-about-video-metrics/
- Google Hit With $268 Million Fine Over Unfair Ad Practices https://gizmodo.com/google-hit-with-268-million-fine-over-un...
Ad industry should burn in the fires of hell.
Similar double-selling of television ads take place as well. A network ad may run in the network feed and will appear in the network affidavit logs as having run. Local affiliates supercede network feeds all the time and in some of those cases they do so during a network ad pod and run station-sold ads. Consumer sees only one of the TV ads but both get reported as run.
Fraud in advertising isn't something new or isolated to the online medium.
Doesn't mean there isn't fraud but someone can't really make up circulation numbers out of whole cloth.
All I'm saying is that the same logic holds for websites and that tracking people is a needlessly paranoid and harmful solution to the problem when it can be solved with trust, contracts and auditing.
I actually agree with you. And large businesses in particular are both audited and do internal audits all the time. It's not that they and their employees are all untrustworthy but audits can both catch mistakes and send a signal that people are watching.
There are probably other mechanisms to do fraud detection. But, as your comment suggests, they may be more heavyweight and therefore might exclude most smaller sites.
[1] https://www.lesswrong.com/posts/dFgfQTo4DRZG5t8Ap/can-ads-be...
What the ad industry refers to as "fraud detection" is just abuse of a monitoring system they didn't have access to in print (pay per view/click) - print ads were still deemed effective even without assurance of per-individual revenue. There's no reason electronic ads couldn't've been treated the same - the only difference is advertisers have been allowed to develop surveillance to gain granular revenue insights (and anything abusing that system of surveillance is labelled "fraud")
Ad fraud is only legitimately "fraud" if you accept the pervasive surveillance it's "defrauding" is legitimate to begin with.
Also...
> the circulation is not a secret
Isn't it? Like yes, there's a published figure, but is it verifiable?
If we're discussing potential for "fraud" here, I don't really see how there's any difference between online and print circulation.
For online "circulation", there are three choices: the two given above, plus the possibility that the "actual numbers" (e.g. generated from server logs) do not reflect what they appear to (ie. bot visits). This is "problem" that tracking seeks to fix, by avoiding a "circulation data source" (page visits) that isn't (and cannot be) reliable.
1. the current incentive where individual brands can defraud ad exchanges' pay-per-x systems. Without pay-per-x this incentive disappears.
2. publishers defrauding advertisers. This has similar cost & risk ratios online as either misreporting numbers or bulk-buying papers does in real life. There's also very little tangible difference between the ability of authorities or legal agents to enforce honest reporting of numbers online and in print. The two scenarios are eminently comparable.
Ultimately, removing pay-per-x brings online ads and the ability to defraud advertisers down to a level of equivalence with print.
Even in cases where the GDPR allows data collection for one purpose, that does not mean you can apply your collected data or analysis for a different purpose.
1. Collect data for DOS-prevention purposes.
2. Analyze it afterwards in aggregate for advertising purposes.
Except you can't do #2 without turning #1 into "collect data for DOS-prevention and advertising purposes", which goes beyond your legitimate interest in collecting the data.
I agree that #2 should be allowed if you'd do #1 anyway, but this isn't how the GDPR works.
Well big surprise: They don't perform as well. Don't you think there is a reason the ad industry went in the direction it did?
The companies who make the real money out of ads are ad tech vendors, with publishers often picking up the scraps
It’s not suprising that people who’ve worked in personalised ads often promote them as the only way to fund the internet
I deliberately made my comment more generic, this isn't just about ads.
Any senior manager worth his or her salt knows that staying on the right side of the law is significantly more important than supporting any dubious "product improvement" which is on the wrong side of the law.
https://twitter.com/garjoh_canuck/status/1318989360407236609 summarizes the studies on this, and this comment [1] gives additional context.
[1] https://www.lesswrong.com/posts/dFgfQTo4DRZG5t8Ap/can-ads-be...
Looking how the data was collected in the studies and where it comes from then Google, FB and other adtech vendors feature strongly (and they can't be considered neutral sources)
In the ad market there are three participants - advertiser, publishers, ad networks.
The last group keep telling us we need them for a health internet, while being completely opaque but making billions creaming off their cut of advertising revenue (there don't seem to be any reliable figures on how much they actually take but an old Guardian study found that sometimes they were getting less than 10% of the revenue the advertiser actually spent - Guardian have brought ad sales in house since)
Alternatives such as category based advertising are often not discussed other than to say 'if personal ads go then the spend is likely to be re-directed towards category based ads'
Even Google while claiming personalised ads are better seems to rely on category based ads for the revenue from search ads (see the CMA report)
IME working alongside various publishers it's often that case that directly sold category based ads are way more profitable for the publishers
Given thread like https://twitter.com/nandoodles/status/1582434737813348352 (and others) I'm deeply skeptical of claims ad tech companies make
For example, dotapicker.com (which allows you to see counter-pick viability in Dota 2) runs ads but they're either ads of web-based video games that shows a lot of skin and have very vague wording to skirt Google Ads guidelines (about a quarter of the time), or random product and services related to my overall browsing history, eg. Amazon/Etsy/Ebay/etc or B2B services like Monday.com.
Contextual ads definitely work where they can, which is why google.com ads are all contextual to your search, but it expands available ad real-estate to run targeted ads in places that otherwise would get no clicks.
Almost everything we currently decide when you visit a page, the only real concession is that it's scoped to the current page, rather than every page that we know you've visited.
I'm honestly not convinced our current idea of targeted ads actually works. Continually showing me links to a product I bought someone for Christmas a month ago isn't remotely clever, despite being precisely targeted. "People shopping for guitars on Saturdays are more likely to convert to sales, than people shopping while they should be working" does not require storing PII, and is (hypothetically) more useful than "If you bought a guitar last week, surely you're more likely to buy a guitar this week".
People sending stuff they brought back and buying something else exist, and also people buying for their friends. But if you had an actually good prediction of their behavior, you wouldn't need to proxy it by "brought a vacuum recently".
Yet, companies insist that failure is a feature, and that their local maximum is the best possible world. And will keep harming advertisers, viewers and society to keep their position at that peak.
It seems like what you posit is only a mystery if we take it on faith that targeting works. Once that faith is lost, you can also approach it from the angle that if showing them something we think they want is just as effective as something we know they don't want, you're actually proving that "what we think they want" isn't working either.
I mean, given "we know you've bought a vacuum cleaner" and "we think you'd like a kettle" - if ads for either are equally effective, either there's a lot more people collecting vacuums than either of us would have expected - or we're entirely wrong about the kettle. And it seems to me that our blind faith in targeted advertising leads us to wonder why people want so many vacuums.
But how do we explain how there are also advertisers like Amazon who do know that you just bought a vacuum from them and still show you more ads for it? Since Amazon is in a position to run principled A/B tests on whether showing these ads leads to sales that otherwise wouldn't have happened, and they are the kind of organization I'd expect to get this right, this part I am willing to accept without external evidence. It's probably that the likelihood of additional purchases of the same item, for yourself or others, is high enough, combined with that the cost of advertising to you is low enough.
Removing PII will hopefully hurt the greedy ad serving companies most. Though I am scared they will find workarounds.
Our niche is office design content and we sell advertising primarily to office furniture manufacturers. The ads are hosted by us and are sold directly.
But this is also not a model that can support a very large fraction of the existing web. Most sites aren't built from the ground up to have this kind of highly commercial tie-in.
*edit: that said there is a local news website in my city that has local ads for local services and businesses.
Our specific case is weird in that contract furniture is mostly purchased through dealers so tracking sales isn’t as straightforward.
Someone reading a print article is probably a much stronger signal that they are interested in things related to the article or the topic of the publication than is someone reading an article on a website.
If some random site runs an article about, say, a meteor shower you probably can't infer that the reader has more than a passing interest in astronomy. Even of a site that is focused on astronomy runs such an article they are still likely to get a lot of casual readers, such as people who heard on the news about an upcoming meteor shower and Googled to find more information.
If on the other hand Sky & Telescope runs an article about a meteor shower in their printed magazine it is probably a safe bet that most people reading that have a fairly serious interest in astronomy.
If I were trying to sell astronomical equipment I'd probably be willing to pay a lot more to run an ad in Sky & Telescope than I'd pay to run the same ad on a "free but with ads" astronomy website and I'd pay even less to run it on some non-astronomy site that happens to be running an astronomy article.
I think this largely invalidates most of the "it worked for print so it will work on the web" arguments I've seen except maybe for websites with well enforced paywalls.
Before one says "but if you don't track the user you cannot know how many user did see the AD and you cannot target the AD to the user preferences so no one will buy them", because nobody buys ADs on TV, radio and newspapers where you have the same one directional communication channel? Come on, they are only excuses to collect more user data...
You do not need that information in order to run effective online ads. You've just been conditioned to believe it's necessary by DoubleClick, Google, et al.
Without pinpoint targeting, more irrelevant ads will be shown. That reduces value.
Without lots of invasive tech, you can’t avoid fraud or track conversions. This also reduces value.
This isn’t an unfortunate side effect of GDPR and adblockers.
Of course what you can no longer do (without user consent, because if the user give you explicit consent you can) is to provide ADS targeted to a specific user based on tracking data. But you can assume that if a user visits a page that has a certain content it will be interested in certain type of ads, this is possible because you are not targeting the specific user based on data you collected on the user, but all the user that look at that content will see the same ads (that are pertinent).
Is a big loss? Yes, to Meta and Google, to company doing advertisement not, because this kind of advertisement is not that effective, and to users even more not because tracking is bad for their privacy in many ways.
I find this part a bit surprising. Brand advertising surely cares about fraud when it’s done on a cost per impression model. But I expect that brand advertising’s effectiveness is more related to placements, not impressions. For example, Nike once famously reduced the number of swooshes they used because they thought that having too many diluted the brand. Similarly, a brand placement somewhere like a movie or an article might have high impact despite only being seen once per viewer, whereas a placement on a site that gets lots of intra-site clicks (like Amazon or some mediocre review site) will get many more impressions per viewer but likely less impact per viewer despite a higher number of impressions.
So, with a cost per placement model, I would expect the simple forms of fraud to be much less relevant.
But take a brand like Nike as an example. I can imagine Nike paying to put (one!) swoosh on an article on a site like ESPN. But Nike, if they’re doing their job right, would not want a swoosh to interrupt the reader’s experience — that’s the opposite of good branding.
Consider FM radio as another example. Ads on most music stations are obnoxious. Sponsorships on NPR are generally much more subdued, take less time, and don’t try to stand out.
(Oddly, NPR is quite obnoxious about their own fundraising placements. I wonder whether they would be more effective if they backed off a bit.)
Variations on "take-over" exist where you may have a "branded slate" in which the normal framing and background of the site will also be updated to align (and sometimes synchronize) with the "take-over" ads for that day.
You have likely visited imdb.com at some point in time. With so many TV shows and movies premiering throughout the year, IMDB has a higher frequency of "take-overs" than an average site.
The "pop-ups" or interstitials did decrease due to being bad design & bad consumer experience, but have returned and are now overrun with publisher sign-in and privacy/consent interstitials.
See daringfireball as a somewhat vocal example of how this can work. NPR has a similar model.
Click farms will not land actual high paying placements no matter how many click they claim.
edit: there could be a startup opportunity here. Build a placement ad network. Participating sites get vetted. Placements are per article, optionally for a limited time or limited geographic region. No tracking. Sites agree to be monitored by human and AI analysis for quality and non-spamminess. Sites warrant that their content is original and the network assists with copyright enforcement. Ads come from the backend (first-party), may be genuinely a part of a content, are are very difficult to ad-block. Ads involve no scripts at all. GDPR compliance is above-and-beyond. Advertisers pay very high rates compared to current systems but get higher value out.
The network helps warn sites if they are inadvertently letting other networks track their users. After all, a high quality site wants to monetize its own users, not let its users be tracked and monetized elsewhere.
In general, ads on a system like this might not even be clickable.
https://www.ethicalads.io/blog/2022/11/a-new-approach-to-con...
https://github.com/readthedocs/ethical-ad-server
Stats and lots of information about the advertisements and click rates/etc is available.
Been pretty smooth sailing so far, was going to write about it in the future.
(...and if the advertiser pays for the spot, not per view, "fraud detection" becomes moot as well.)
Online advertisers would explode if any online ad gave them viewability equivalent to the "the side of a bus", or "roadside billboards", only they can't measure it (but there are efforts to try with cameras on billboards in the industry), yet despite this buses and billboards actually carry a premium compared to internet ads because it's a less competitive market.
> The creepy world of personalised ads is coming to your TV
> Channel 4 and Virgin Media are adopting Sky's AdSmart advertising system. Sky says it can put viewers into groups of 5,000 or more based on age, location, lifestyle, and "even if they have a cat"
https://www.wired.co.uk/article/personalisted-tv-adverts-sky...
Sure, "circulation" is not so well known, but was it ever exactly known for broadcast* television? free papers on trains? 50% of all advertising is worthless, anyway: to what extent do we have any idea that even fraud-detected CPM ever converts to actual sales? Why does anyone do "corporate identity" placement on PBS?
Finally, I'd have no problems (hint: how many targeted placements do you see on this webiste?) if a certain percentage of the internet disappeared because it was not economic to continue it without targeted advertising "revenue". If the market speaks, then let the market speak.
* my dorm was once a Nielsen household for a week or two. They were warned, but accepted 80 as our household size.
To your other point, the "certain percentage" is most of it and we won't have all that much to discuss here.
Maybe most of yours, not of mine. I'll miss YouTube, but not badly.
(of the ~dozen other stories I've commented on today, only one would likely disappear: https://news.ycombinator.com/item?id=34296560 )
OTOH we have places like youtube where content makers seem to make more money with sponsorships (which are like contextual ads) than with google's adsense. So it seems like it s time to call out the advertisers: Why haven't they ever taken a stand vis-a-vis stalker advertising? It also seems weird to me that advertisers are not being fined for targetting users even though they are the original perpetrators.
I would like to be able to monetize my websites, but google and EU are both my enemy
Even if not more, it would be in addition to what the google way would generate. Or for those for which google won't pay due to copyright claims, it is the only way, in which case any sponsorship is more than google.
1) GSuite. Here's their data processing terms https://cloud.google.com/terms/data-processing-addendum/inde...
2) Office365. Here you go https://www.microsoft.com/licensing/docs/view/Microsoft-Prod...
So both of them will absolutely sign one. Maybe you don't like google and microsoft. Let's look at some others. What about Fastmail?
https://www.fastmail.help/hc/en-us/articles/6049922252943-Fa...
Basically any legitimate email service will sign a gdpr-compliant data processing agreement as far as I can see. Certainly all the ones I have ever used do.
Follow up: Suppose the option for $X is ruled illegal. What is Y now?
https://techcrunch.com/2019/05/31/targeted-ads-offer-little-...
The most relevant part seems to be
> [...] ads were sold with targeting attached, and advertisers were willing to pay a 60% premium for those ads.
So, say $3 vs $2 or showing two tracking ads vs three basic ads.
So tracking seems surprisingly useless for all the work involved?
Like, if I had a blog about mountaineering I would like Google to only show ads about hiking gear, regardless of the cookies of the person visiting the website. Of course my CPM would be lower, but at least I won't need to track my users and I won't have baby formula or school supplies ads between my reviews of snow boots.
They don't because it limits revenue
It doesn't disable tracking by Google or advertisers, e.g. them noting that they saw user X on a hiking website and increasing the chance to display ads to them for hiking gear elsewhere on the internet
God, I wish. Imagine a world of content with no ads, supported by willing payment, not data extortion.
It's not even that far off, a lot of the people I follow make their money from subscriptions, donations and sponsorships.
So many (most?) sites are in a state of noncompliance simply because they believe their business model requires it.
But I find it hard to believe regulators create laws without the intent of enforcing them. The fines for noncompliance can be very stiff.
Personally I’m hoping there will be a few high publicity examples made soon.
Just do the same on the web:
You (or an ad aggregator network) can ask (by e-mail or automatically via an API) a specific website to show a specific ad without leaking any details about any specific visitor.
You can still target safely by the website (target audience) and specific page, time, IP geolocation, for registered (at the website you advertise at) users also by the details they voluntarily provide (without leaking personalized details to you/aggregator).
Okay, the number of TV channels is small, I get your point. But there also are physical ads, e.g. billboards, subway posters, cards/booklets, local newspapers which often are focused to a small number of physical locations but still happen to generate enough revenue to sustain a business.
There also are agencies which would put your ad on posters all over the country - ad aggregator networks can still work and manage the consolidation this way, we only want to hide viewer personal details from them, not to eliminate them completely. This will decrease significantly (yet not kill completely) targeting efficiency, make display/click price bargaining more subjective but that's all.
This would water down the whole GDPR since its primary function is to stop using PII as merchandise.
Also, if consent is the legal basis for processing, it must be possible to withdraw consent without any adverse consequence, so if e.g. you give a discounted subscription to people who gave consent, then you can't revoke that subscription or discount if the data subject withdraws that consent a minute later. If you say that you'll provide some service only if the user "consents", then GDPR presumes that the consent is not freely given (e.g. recital 43 of GDPR).
e: I see a stealth edited reference to recital 43, which I hadn’t seen before and does seem to show I’m wrong here. Thanks for the reference.
The final part of recital 42 "Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment." is probably even more clarifying than recital 43.
Adjusting GDPR core principles for the purposes of website ads would be like the tail wagging the dog - if it "fixes" web ads but worsens handling of much more sensitive things like companies wanting to exploit data in physical shopping, telecommunications, healthcare and banking, then it's not worth it.
On top of that there's USA itself. Which said "if an American company serves anyone anywhere in the world we have the right to request any and all data on all users of that company, regardless of their residence or citizenship". That's what Schrems II was about: there's either privacy and protection of people's data or working with US-based companies. Europe keeps chosing the former, thankfully.
According to https://www.iubenda.com/en/help/24487-cookie-walls-gdpr
> As regards paywalls, the Garante published a press release to inform that it’s analyzing this solution as implemented by some Italian publishers.
> The Austrian and French DPAs have already indicated that the paywall system is a valid solution as long as the subscription to the site has a modest and fair cost so that it does not constrain the user’s free choice.
> As it stands, the decision of whether paywalls can be compliant or not is still somewhat of a grey area. We will have to wait for a uniform approach from the DPAs to better assess the compliance of these mechanisms.
I have mixed feelings about this. There is some validity to providing an alternative method of funding the website, but at the same time it will most likely maintain the status quo as the vast majority of people are conditioned to accessing online content for free.
A sufficiently memory-hard and ASIC-resistant proof of work scheme could be used here. But obviously, that implies some non-negligible load on the client.
* Lock up, say, $5, in anonymous cryptocurrency like Monero
* When visiting example.org, sign a message "example.org <current timestamp>" with your private key, and include the signed message in a request header
* example.org can verify the signature (and the fact it's backed by $5)
* example.org can also forward the signed messages to the advertiser as a proof of legitimate pageviews
* if a bot farmer wants fake pageviews, they need to lock up separate $5 per bot (and if we're counting unique pageviews, then per pageview)
edit: one gothca here is that sites could collect the signed messages to track users across sites. Perhaps there's a way to sign messages so that you prove you have $5, but not which $5 – I don't know.
PhotoRoom Is Hiring a Fullstack API Developer (OpenAPI, Python, React) in Paris (lever.co)
Perfectly GDPR compliant(Many people on HN are fully invested in an industry built around personal informaiton theft so hate things like GDPR as it stop them extracting money from people hence the immediate downvotes)
Perfectly GDPR-compliant, simple, and worked in practice for decades. Of course it's less lucrative than ads based on invasive surveillance, but if those get prohibited, that's a reasonable alternative.
HN is simply rendering a link. This is different than many online ads, which make a call to some remote server which returns the ad content (and presumably tracks you without consent).
There is not a third party serving the content for the HN portfolio company hiring link, so no GDPR violation, right?
Help me understand the problem.
The reason that HN ads aren't a problem under the GDPR is that they don't (as far as I know) collect or use any personal data in their ad system. But that's something that works much better for HN than for most sites.
The other argument about the Der Spiegel paywall-or-ads model is also tricky. I do understand where they're coming from, but the argument only holds in a theoretical situation of perfect knowledge (a visitor to your website fully understanding the implications of accepting ads). Requiring this level of consumer understanding isn't reasonable imo. This doesn't even work in Der Spiegel's favour: the only reason to offer the free ad-supported model is that they're forced to compete with free ad-supported alternatives. Otherwise the incentive to pay would be higher for visitors.
Ultimately though, the biggest argument to allow things like the above is corruption: currently we're very slowly seeing the GDPR being enforced many years later in just one or two large cases. There are millions of potential cases that'll never be prosecuted, not only because doing so would generally be unviable (it could still be an effective disincentive) but also because there's massive amounts of government lobbying to disincentivise prosecution and to defund independent data protection offices (keeping the level of enforcement even further below what it should be).
The question being asked is, can spyware be made GDPR-compliant if we just get the user to hit "accept". That's a much more difficult question. But do not conflate adverts and spyware. It doesn't have to be this way.
Unfortunately this approach means that shady companies will still break the law, since breaking the law would give them a very big advantage. All ads would just be bought via some company fronted in some country with no regulation, or by a chain of companies that appear and disappear. It could also be like "FTX" and "Alameda research" again - this time not tokens, but information about ads would be shared. You can easily see various ad companies coming out of nowhere - if they broke the law, their ads would work better, so everyone would jump there. Then the company would implode, so everyone would jump somewhere else.
Other option, an option that I dont like, but still an option is a move towards requiring users to make accounts. This of course is not great, since nobody (including me) wants to make accounts. But then, you can send ads to groups of accounts, or include / exclude some accounts from seeing the ads. And you can show "ad 1", then "ad 2", then "ad 3" to users. It's a bit more like TV. Less targeted of course. Since nobody (?) does that does it mean that it is not effective, or that it breaks GDPR?
On a side note: there are many apps that require you to have a subscription and show you the same few ads again and again. Do the advertisers really think that after I install app X, that I use for say 15 minutes per day - and I see the same damn add 5 times per use.. that I will buy the product? It makes me dislike their product and not want to ever buy it. Does this approach of showing the same ad again and again really work? (I can understand that it can make me want to buy a paid version of the app, which I did at some point, but it made me hate the advertised things). Also why do they even agree to show the same ad every few minutes?
We get it.
Base the ad on the web page content, not on constantly spying on everyone.
Which is true. It’s just not as secure, just like dumb ads wouldn’t be as profitable as todays’ ads.
But no one is arguing they would be nearly as profitable. Or profitable at all. Only that they are possible. Maybe you get 5c where tug used to get $1. That’s fine! Take the 5c and just shut down the site if that isn’t enough. There will be new jobs in print advertising…
And this IS the argument for by-the-letter GDPR interpretation of cookie wall laws, or proponents of Adblocking: we don’t think the problem is to somehow find a solution that respects privacy and at the same time doesn’t torpedo the whole ad-based economy.
I just want ads not to spy on me and my regulators to do their job, even if 75% of “ad funded” content disappears tomorrow.
Not to mention the part where optimizing content for maximum ad impressions has led to the rise of extremist content and political infighting.
So my argument is basically this
1) I don't think many understand what's being exchanged in the transaction. And I think such transactions shouldn't be allowed. So I don't think they must necessarily be "banned" outright, but they should be made very clear. And that's what the GDPR is trying to do. Not make anyone make transactions where they aren't aware what they are giving away.
2) If everyone is "aware enough" of what they are giving away, then I don't think enough people would accept it. So simply put, there is the "barren internet" or the internet that people like but for the most part because they aren't aware of what's going on.
Now,
Not only is it of course "my will imposed on others" (As is any legal/political argument or suggestion). But not only that, it's also a case of me arguing "people aren't clever enough to take care of their own integrity". And I stand firmly by that one as well.
Again, ads are entirely possible without constantly spying on everyone, they are just less profitable, which is a good tradeoff for those who are not excessively greedy.
If you want to be allowed to spy on someone, all you have to do is get their informed consent.
Again Jeff pretends that data you need to collect to combat ad fraud can be freely used for any other purpose.
Again Jeff deliberately misrepresents the facts of the court cases he links.
Again Jeff makes it sound like Schrems is a bad ruling.
And throughout this all he presents this misinformation, intentional misrepresentation, deliberate twists of meaning and falsehoods bordering on outright lies as fact.
Jeff. Stop.
Edit: comments to the blog post call all this out and provide additional analysis. I highly recommend reading through them.
As for the question posed in the article, the answer is obviously yes. You don't need to track people to do online advertising.
The issues of fraud and what not are separate. Sufficiently cheap ad space would still be desirable.
What the EU privacy push has created is an incentive for ad networks to improve. What we are already seeing are strategies that preserve both privacy as well as a revenue stream using, for examples, cohorts or that strategy (whose name I seem to have forgotten) of adding some randomness to raw data that cancels out at the learning stage.
These aren’t perfect, but it is an improvement.
Inherently there’s a trade off between personalization and effectiveness of advertising.
I think you will find the article raises some problems with that view.