I work at a megacorp, and we have an entire group that goes around auditing projects to ensure compliance with data rentention policies, which include mandatory deletion of different types of data at different timeframes.
Financial transaction records have a very long mandatory retention, IP addresses for logins have a fairly short mandatory deletion. Product telemetry has strict rules about avoiding PII and very very quick deletion (aggregate data can be kept longer).
I’m sure the policies could be improved, but I suspect every large company is intensely aware of the importance of data deletion, even if competing priorities sometimes lead to longer than technically/legally required retention.
What is very, very quick? And why?
Company A that leverages data will outcompete company B.
Lots of layers to this analogy, given the damage our use of oil is causing.
Companies are going to learn that using LLMs without paying proper consideration to data governance is a recipe for large fines and worse (such as being required to throw out entire models because their provenance violates data subjects' privacy rights).
many direct analogies indeed
I think we'll see a national privacy law in the United States at some point in the next five years. There's appetite for it in both major parties (Democrats to protect bodily autonomy, Republicans to stick it to Big Tech), and I think the targets of the regulations themselves will at some point lobby for a consistent national law rather than the patchwork of state laws that we have now.
Deleting data is hard work that requires a lot of preparation and has to be done without the safety net of backups. In many cases it will require changes to proprietary software. Keeping data happens automatically.
Not having data that you're supposed to have becomes obvious as soon as someone asks for it. Holding on to data for longer than necessary only becomes a problem if there's a data breach (that cannot be covered up).
Everyone should watch it https://www.youtube.com/watch?v=GAXLHM-1Psk
The added complexity is regulation saying you need to keep data on your customers. In a way the early somewhat anonymous internet was better in this regard.
An edit to add, if you encrypt user data at rest (big ask currently). You can destroy the keys past a point and then the data in backups is safe etc.
Anyway it'll take a while for this view of the world to shake through.
Even Google of all places "respects" it now (after pressure). It becomes noticeably better every year.
GDPR may have had good outcomes too, and I am neutral on all other aspects, but whatever part of EU and California regulation led directly to cookie banners is a colossal failure which has benefitted no one (except possibly the dozens of snake oil cookie banner products which pretend to comply).
Understanding the data you collect, why you are collecting it, what you are using it for and what the risks are if the data is leaked is unsurprisingly a useful thing to do as a business.
In the UK, current news cycle is about sewage being dumped on our beaches by water companies that were previously privitised.
I think GDPR is generally good for individuals and the internet but if someone hates cookie banners, isn’t it fair to place the blame on GDPR?
Why can’t websites accept a special header which automatically accepts all cookies? I would enable it and handle clearing/retaining cookies myself through a browser feature/extension.
No, blame companies that set cookies for merely reading a website and then bothering users about it. They have a choice, they choose to make it obnoxious.
I could be wrong but IIRC cookie banners predate gdpr.
It did not specify cookies, and did not actually specify any technical means. The ePrivacy Directive requires that companies get consent from users before storing information or gaining access to information stored on end user devices. This includes every kind of cookie you can think of, including LocalStorage. There is an exception for cookies necessary for the service requested, which typically includes things like auth cookies or shopping cart cookies, so long as that data is not used for anything else.
The GDPR doesn’t specify the technical means, only that permission must be explicit and freely given, with the default assumption being “no permission granted”. I think these conditions are entirely reasonable, and a header that could be set by somebody other than the user, then sent by the browser on behalf of the user, does not satisfy these conditions.
Most entrepreneurs believe that visibility over how your visitors are using your website is “strictly necessary” for running a functional/secure/performant website and surviving as a business, but GDPR disagrees. Hence, cookie banners everywhere.
Not deemed “strictly necessary” > “Statistics cookies — Also known as “performance cookies,” these cookies collect information about how you use a website, like which pages you visited and which links you clicked on. None of this information can be used to identify you. It is all aggregated and, therefore, anonymized. Their sole purpose is to improve website functions.”
So much could have been simplified if the GDPR rules, instead of imposing burdens on a million websites, required the 3-4 browser vendors to have a toggle for preserving first-party cookies on sites where the user submits a form with a password field, and simply cleared all others at session end or periodically.
But by regulating browser vendors, they could have made it so that it doesn't matter what cookies they sent you. If the user hadn't consented in a browser UI, the browser would forget the cookies. Easy to verify compliance.
It's just like the ol' pathetic "Do Not Track" header. Same flaw. Asking "please don't give me a cookie that I'll have to keep and send back to you anytime you see me" instead of saying nothing, and just dropping the cookies you don't need on the ground.
This is not something that can be solved client-side other than obfuscation etc. They can track you with other means than cookies. Even worse, you might have an account on their site. Having an account and using the site (and logged in) makes it trivial to follow you, but that does not give them the right to abuse that information for other purposes. You might have an unique IP and can't reasonably expect to do anything about it.
GDPR covers all of that.
"Just delete your cookies/session" is not relevant.
So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner.
You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
> So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner.
Wrong. The ePrivacy directive has an exception for strictly necessary cookies (Article 5.3), which is applicable for user sessions.
The ePrivacy directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Search for “strictly necessary”. More details in this opinion from WP29, see section 3.2: https://ec.europa.eu/justice/article-29/documentation/opinio...
> You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
Are you able to identify someone from the fingerprint of their browser? Then the fingerprint is PII. Consent (or any other legal basis from GDPR Article 6) is therefore required if the exemption from the ePrivacy directive is not applicable.
GDPR Article 6: https://www.privacy-regulation.eu/en/6.htm
It also isn't necessarily a requirement that such permanent records are digital, this depends on the country.
"He who controls the past controls the future. He who controls the present controls the past."
How else will future generations be able to put your residence on Paeroa St in connection with the consumption of fish in that area during that time, to reveal the political stance of you and your offspring against the ruling party of the Tilapia...
Which reminds me, I really should just write those down somewhere safe.
For example you don't need to know exactly who voted for Trump or Biden in the last election, you just need to know the result