No, and no, and no.
Most privcy-adjacent laws that EU has released in recent years are neither complex, nor do they cost too much money.
Well, they cost some money because businesses have this entrenched idea that they have an inalienable right to your data, so they don't even know which data they collect, sell, exchange, let leak, or use throughout their systems. Well, boo-hoo. Spend some time and money to get rid of this idea.
And the laws are "indirect" in the sense that all laws are indirect. They have to be general enough to be applicable not just in the year they were released to the technology of the time.
Please visit https://gdpr-info.eu/ and read the text of the 99 articles that make up the GDPR. You don't think 99 separate statements of the law are too many? Not complex? Add in reading all of the CJEU opinions and the original directive behind GDPR (which remains in force). Also add the e-privacy directive, a 15 year old law that is also still in force. How can you say that isn't complex?
> Well, they cost some money
My argument is that it costs more money than it's worth. Hard to find good statistics, but we can leave it at that.
It’s the fact that our browsers don’t solve this issue in a standardized way.
Everyone who serves HTTP in the Eu and includes third party tracking, shows you an idiosyncratic consent banner. Often these things download a large amount of JS as well.
That’s completely and utterly idiotic.
- It’s confusing for users.
- It interrupts the user’s flow everytime they visit a site.
- It’s bad for overall performance.
- It’s bad for people who publish content.
- Developers have to defer to legal experts for trivial stuff out of FUD.
- It doesn’t work correctly on the technical side.
- It doesn’t work from a user’s perspective, because they just get annoyed or uncertain and falsely consent!
Nobody wins.
It should just be a standard, global feature in browsers. A site should only ask you _once_, if at all from a user’s perspective.
The browser should send a “profiling and tracking” whitelist, or simply make it available via a JS API.
Why is this not the case?
> That’s completely and utterly idiotic.
Yes. And that's not the fault of the law, but the fault of the companies.
1. The law doesn't talk about browsers, or cookies, or banners. It's a General Data Protection Regulation. It applies in equal measure to browsers, apps, VR, AR, offline interactions, and whatever you can think of
2. The law is ridicuously simple for 99% of use cases, and is extremely cheap to implement. It says, "Only use data you need for the operation of your business. If you collect any other data, you have to ask users for consent. Consent has to be informed, and it must be as easy to say no as it is to say yes"
> Why is this not the case?
Because the companies think that tracking you and selling your data on theopen market is their god-given right.
And the standard is literally already there: it's called GDPR.
"Legitimate interest" is there to cover areas that are too numerous to cover in a law. E.g. combating fraud is a legitimate activity, and it requires more data than you strictly need to operate your business.
However, as with all things, companies will try and exploit any and all loopholes possible.
"I can make money by collecting this data" is not a legitimate interest.
So why would companies who don't give two shits about user privacy bother with any implementation or standards? The law already tells them to provide a yes/no option, and yet here we are.
This should give you the answer to "why this isn't sufficient". The ads industry does not respect anything until it's driven out of existence by fines.
and top is complaining that his industry was instead given unholy ammounts of money to agrue that it isn't.
It's an EU law what did you expect?
You just described regulations.
If they were to “ban behavioural advertising”, then advertisers would simply rebrand it: “oh no it’s not behavioural advertising, it’s ’interest-centric’ advertising, completely different”.
The point is to ban it in “spirit” not in “letter”, because a ban in the lette would simply get lawyered around and end up not being worth the paper it’s written on.
The advertisers know that these regulations ban behavioural advertising effectively, which is why their immediate tactic is to decry the wording as “too hard” and “too confusing”. This is an obfuscation tactic. Like with GDPR, it’s actually shockingly easy to comply with:
Just don’t track users and sell their data.
Yes they could, so the question is why didn't they?
I suspect the answer is that there are lots of factions within the EU, some want to ban it and some don't and what they've done is a compromise.