German court prohibits LinkedIn from ignoring "Do Not Track" signals
stackdiary.com
stackdiary.com
This case revolves around (third party) tracking cookies.
The Dutch Data Protection Authority (AP) defines 2 cookies as follows:
“Cookies are small files that a website owner places on a visitor’s device. For example on a computer, laptop, smartphone or tablet. For example, the owner can collect or store information about the website visit or about (the device of) the visitor.
Bottom of form
There are 3 types of cookies:
- functional cookies;
- analytical cookies;
- tracking cookies.”
The AP says about tracking cookies 3 :
“If cookies can also be read when you visit another website, we call these tracking cookies. These cookies allow organizations to track people’s internet behavior over time.
Tracking cookies make it possible to draw up profiles of people ( profiling ) and treat them differently. Tracking cookies usually process personal data.
Personal interests can be derived from the information about visited websites. This allows organizations to, for example, show their website visitors targeted advertisements. (…) Do you process personal data of visitors to your website with tracking cookies? Then you must comply with the rules of the General Data Protection Regulation (GDPR).”
https://uitspraken-rechtspraak-nl.translate.goog/?_x_tr_sl=a...
(It's in dutch, translate at your own liberty, I'll give my own below + the stuff the authority for consumers and the market demands, which is linked from their page.)
Basically of the three cookie types, functional cookies require no consent whatsoever. A cookie to set up a user session (the page uses a shopping cart in a webshop as an example and the details mention things like saved passwords and language choices) is totally fine. The AP still recommends informing the users, but it's not required.
Analytical cookies are permissible insofar that they aren't used to profile the user. You're not required to ask for permission as long as they don't contain any uniquely identifying information. You are required to inform the visitor that you are placing these cookies though.
The final category are tracking cookies. These fall under the full scope of the GDPR; you must ask for consent before placing them, you must tell people how you are collecting their data (cookies, scripts or beacons are listed as examples) and you need to tell people what you do with them.
Pre-checking consent forms in general is expressly forbidden (on the same logic that you can't pre-check people into signing up for physical spam mail or paid subscriptions) and consent must be clearly stated, not hidden in some terms of services page or privacy statement.
Those are all requirements on top of the rights the GDPR (in Dutch called the AVG) grants consumers, although obviously most of this overlaps with the GDPR already.
Tracking is server side behavior.
3P cookies aren't a problem, per se. Using 3rd party cookies to join data with other server side data is the problem.
Who are you to speak for "most people". I do object to that kind of cookie being placed without my explicit consent. It provides at least some identifying information that might allow multiple websites working together to uniquely identify you.
The law judges intent as well as technology.
There are various techniques to place "cookies" (sometimes not technically cookies) that can be correlated by multiple websites working together, but the website has to go out of their way to proactively do that, this is not something that gets enabled by simply placing a standard non-personalized cookie.
It is arguably tracking required for the functioning of the site which is a clear exception to the ban.
GDPR threads on HN are always like this. Tons of people saying "no no it doesn't work that way it wouldn't be reasonable" and then when that thing ends up being ruled illegal, "of course it's illegal everyone knew that it's all very clear".
GDPR is written in such a way that you can't ever know what is or isn't allowed.
I use a lot of news aggregators, and never once got a link to a 451.
I think part of that is also that it's not foolproof to identify where a user is connecting from. Because I think legally, you can't use "but that user had an US IP address" as an excuse why you broke EU law against an EU citizen connecting from inside the EU.
Every single consumer protection has people show up on the side of the giant corporations. Usually a libertarian type with no clue how furious they would be if they got what they were asking for.
Isn’t quite the argument you think it is.
Better would be to not (try to) do anything that requires cookie notices in the first place. Might not always be your decision but at least try to push back on the notion that this kind of tracking is needed at all.
For most of my life, it's been done with tickets you buy at a booth and put in your dash, then you use the ticket to exit
If all the privacy-violating companies go out of business, there will be plenty of underserved customers for companies with more legitimate business models.
No, I don't think so. I think most people would choose to pay with info rather than cash even if they have the cash simply because they don't fully grasp the actual cost to them. People make foolish (from my perspective) economic decisions all the time. I am currently traveling in the American south where I am surrounded by shockingly vast numbers of morbidly obese people who willingly trade their health for a sugar rush. No one is holding a gun to these people's heads and forcing them to drink sugary soda and eat fried food, but they do it anyway. They do it because they like it, and because they don't think about (or don't care about) the long-term consequences. People are (again, from my perspective) stupid. But I don't think it should be the role of government to save people from their own stupidity. That is a very slippery slope.
People also chose to use Netflix or Steam (and other streaming platforms) instead of pirating. Last one would (and still is) be free. So it's not unprecedented.
Personally, I handover all my fitness information, driving habit information, spending and banking and investing information, my health information, even my location data, my STD statuses, etc to a company so I can get massive discounts on a bunch of stuff in various ways. It alters my behavior in a good way, it alters other peoples' behavior too, and I'm all the more happier about it. I much prefer this over stupid things like sin taxes, consumption taxes and laws that most people don't stick to or agree with (talk about choice and consent, huh).
Another reason for this is addiction. Addiction has people doing things that aren’t in their best interest despite them being otherwise intelligent humans.
Even the words words "privacy" and "invaded" are such loaded and ambiguous language, I don't see how smart tech people are playing along with it as if it's some sort of innate human right in the electronic sense. You have to convince us, you don't get to just skip a few steps and tell us we're all crazy plebs that don't understand the implications of this thing you decided has to be the case. Hence the comment about this attitude being privileged (elitist).
Personally, I would love to see the kind of offers companies would start to make for opt-in tracking. In a much cooler world, people would be able to sell their data, as subscriptions, to companies, with premiums placed on more 'valuable' data at whatever given time, based on advertiser interest.
Of course, no data tracking would be ideal, for me. But if someone wants to sell their personal data, they should at least be able to sell it for a market price.
Yeah, I get that. What I'm sating is: that's a stupid rule. Why should I not be able to say that, especially if it's the truth?
If you can't afford to pay $5 cash, you certainly can't afford to pay the $6 the firm that's tracking you will make from tracking you.
What's the value of a persons data if that person cannot afford any of the products which are advertised using that data? On the other hand, persons on a limited budget are sometimes most happy to spend money unwisely.
The collection, buying, and selling of your personal data isn't always about ads. The data people have on you is increasingly used to determine what you can and cannot do, what opportunities you're offered, how much you pay for things, even how long you're left on hold when you call a company.
The data companies collect about you can get you arrested, can be used against you in family court, or prevent you from getting a job.
Even ads themselves aren't always about what you buy. Ads are often used to manipulate you, change the way you see the world, even change the way you vote.
People who buy ads or buy your personal data don't do so out of the goodness of their hearts. They do so in order to make up not only the cost of buying the ad/data in the first place but extract more money out of you, one way or another.
This means it should always be cheaper to just pay for the service yourself then "pay" via ads or exploitation of your personal data, since the latter involves more middlemen that want their cut.
The fact that poor people can currently "freeload" off the system is an artifact of imperfect targeting rather than intentional generosity on the advertisers' part to subsidize the poor population, and will be quickly closed off the second there will be a way to reliably distinguish the purchasing power of a user as to deny service to those whose ad views aren't profitable enough (as they would never be able to purchase the advertised products).
This is why many governments are in general responsible to provide enough social support that turns all citizens into privileged people.
No, that's not my position. My position is: tracking as a business model is morally justified if it is done with informed consent. A business arrangement is morally justified even if it has potentially deleterious side-effects to one of the parties so long as it is entered into with informed consent.
People buy and sell tobacco and firearms and motorcycles and junk food despite the fact that these products potentially have negative impacts on people's lives that are at least as serious as tracking. One could argue (and some do) that selling Coca Cola is not morally justified, but that position is hardly the slam-dunk that you imply.
I’m going to keep ensuring that this possibly-only-good-for-the-privileged world is realized and I think modern privacy regulation like the GDPR helps, which is why I’m supportive of it.
We're going to have to agree to disagree about that. Have you ever actually faced that choice? I haven't. Until I have, I don't think I'm in a position to make that decision on someone else's behalf.
Here's another thing to consider: we allow people to put their lives at risk in exchange for money and social prestige by joining the military. The only substantive difference I see between that and selling an organ is that the latter doesn't provide any tangible benefits to the elites who make the rules whereas the former does.
But if you assume the court decisions stands then if your business is based on tracking that means your business is based on illegal activities.
The only way out is to either change your business approach to comply with the law or go out of business. That’s no difference to many other activities that probably could earn money but are illegal.
Why? Tracking is not illegal. It's just tracking without consent that's illegal.
I don't - and I am fully informed and prepared. A month into the cookie banners avalanche and I just started clicking OK without looking. Now I have the "I don't care about cookies" extension and that's it.
I think this question is very context sensitive. The way privacy questions are usually presented ("we want to improve/personalize your experience"), I don't think most people care. But when presented with actual outcomes of loss of privacy (e.g. the Cambridge Analytica scandal) people seem to care a lot. For most people I suspect there's a gap in understanding between how people think their data is used and how it's actually used. Whenever this gap is closed by a major scandal where "how the sausage is made" is revealed, there's often a strong reaction.
But perhaps the biggest indication that people do care about privacy is that ad companies are so reluctant to allow them to opt out of tracking. If (almost) nobody cares, what's the harm in having clear consent or an opt out?
I have an alternative ideology to sell you...
we product enough to feed everyone.
That is: where you can’t track people without explicit consent, consent is as easy to not give as to give, and you can’t choose not to deliver the service or deliver a worse service to those who do not consent.
Scam: "a dishonest scheme; a fraud; a swindle"
I would argue, outside of our closest relationships, the majority of people are attempting to, or engaging in some kind of scamming behavior in at least half of their interactions.
At this point, 2023 worldwide, fear and distrust are table stakes for social interaction
But that the majority must still behave rightly paranoid that it is the majority in order to protect themselves from a really pretty small minority.
Yes well the whole point is to make things better - not just keep them the same
This relates to a piece of advice I gave my children: most people are fundamentally good and decent. A small percentage are not. The problem is that you can't tell which is which just by looking at them.
However it is unquestionable that the default mode for humans in America to operate is out of fear - and the opposite is by exception
Even in human interaction amongst your closest friends and family, they only interact with you for their own benefit - that just happens to be in pursuit of the endorphins/dopamine gained when they spend time with the people they share memories with, and it happens to be reciprocal.
Well, with exception of those which need to be shot with Hanlon's handgun[0]. There's surprisingly many of those, and not where people would suspect (e.g. I see it more often interacting with small businesses than with larger ones) - but in most interactions with others, I find it best to not reach for the handgun until it's clear it's needed.
--
[0] - "Never attribute to stupidity that which can be adequately explained by systemic incentives promoting malice." -- https://news.ycombinator.com/item?id=21691282
This is excellent advice for both metaphorical and literal handguns.
Large corporations where all human values are made illegal are quite shining examples how humans should operate in our system. This is sadly quite common in non-profits too.
I agree with this, but there are situations where because of obvious incentives you cannot make this assumption. Car salesman treating me like his best friend? I wonder why?
I think the numbers are way lower, but it is an old, archaic idea, you do good for your tribe/family - by taking from anywhere outside of the tribe. Stealing from the tribe is very bad and might get you killed. Stealing from another tribe however is not stealing, but reputable work, as long as there are no established friendly relations to that tribe. Many people indeed operate with this mindset (consciously or not)
But all in all I would rather say, that the number of people who consider all of humanity their family, is increasing.
This sentence shouldn’t be associated with anything “non-profit”
Proving yet again that, unless you structure your organization differently than every other capitalist thing (which means you won’t get funding through traditional sources) then you’re just helping capital further entrench their positions of power
You want to have some kind of impact, and you end up having to spending money to do that. You want the most impact and your funding is limited.
The STRUCTURE is wrong is the point.
The entire concept is built around would-be-aristocrats (Board) coercing the management and employees into allocating property (Money) based on their whim with no accountability or democratic function. It is built to exploit.
Instead they should organize as a non-stock cooperative so that is effectively impossible to exploit. That's the actual answer.
Maybe you can call it something else, but for a non-profit ROI is just answering the question "Are we spending our money wisely?
Or were you referring to the non-profit having a board?
Using concepts like ROI for non-profit operations is one of the signs how everything is made to emulate business.
If you don't care, switch on DNT and never see those banners again (assuming this ruling preveils).
Ugh, please don't give them any ideas
So as long as you are collecting personal information, there is no legal difference whether you do it via cookies or another different mechanism.
I'm an external auditor. The GDPR is a cash grab.
Regulations that actually incentivize organizations toward stronger privacy and protection practices are designed more like HIPAA or PCI where the MAGNITUDE OF THE BREACH is the primary factor determining the monetary fines imposed (e.g.,number of records exposed, was it PII, PHI, etc.).
Taking 4% of the company's annual revenue from the previous year, irrespective of the size of the breach, results in a regulation about as effective as clicking those cookie consent boxes. "Oh thank goodness I gave my consent, I think now we can all rest easy that our data is being handled securely and appropriately!" No, the EU included the ticky tacky consent requirement to create major global visibility about itself so that when a company doing business with the EU has a breach, they won't be surprised when they then get an additional bill from the EU for not only having the breach, but now being in violation of the GDPR too.
The GDPR is a despicable joke. And my use of 'the' gives me the right to that opinion. If anyone else out there was involved in GDPR's creation or implementation, I think you would agree:
GDPR owns the Greatest Dung Pile Record, Grandma's Dildo Paste Replenisher, the Gagging Damaged Penis Rectum and one Gigabyte of Dick Punch Radiation in addition to €2.83 billion (as of 12/2022) collected from breached companies in 1,401 cases for "violating the GDPR".
The other option would be to have fixed fines that Google et al. pay out of their small change, while it absolutly would torch their small competition.
Sure, they could also jail CEOs for this. I would also be for that.
If a fine doesn't grow with the income it is a fee. So if you want a corporation to follow your law, it needs to come with a fine that motivates those in charge enough to follow it. Money is the soft option there.
It is totally possible to run websites in compliance with GDPR. I built multiple that require no consent whatsoever, because guess what: No personal data is collected, where it is not absolutely technically required.
For me as an EU citizen the GDPR turned my data-related communications with companies from essentially begging into the void, to actually getting a response.
The GDPR doesn't mandate fines of 4% regardless of the nature of the breach. That's the maximum size of the fine.
You should go ahead and actually read the text of the GDPR. Specifically, Article 83.
Paragraph 1 states that "the imposition of administrative fines [...] in respect of infringements of this Regulation [...] shall in each individual case be effective, proportionate and dissuasive".
Paragraph 2 lists eleven factors that the SAs have to have regard to when setting fines, and top of the list is "the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them".
Many folks assumed DNT is useless. Yet here we are comenting in a thread about a court that is making it legally enforceable.
How exactly do you legally enforce "each link must not be a unique UUID generated per-user or per-page-view"? Do you mandate how "generic" a link has to be, such that a visit to that link exposes less than a certain amount of information about that visit? What about things like order-specific links on a shopping website, that will naturally identify an account if all orders share the same namespace?
Simplified it says: if you collect personal information, you need to ask for consent. If someone doesn't consent they must not receive degraded service. Now there has been a ruling that the Do Not Track info users send you shall be honored by you (duh).
This is true regardless of how you technically do it. So UUID URLs are okay, storing which IP adresses shared an UUID link with which other IP without consent is not.
I think some in the IT world need to finally stop making excuses and stop coming up with new illegal ways of tracking users on a personal level. Just use the same creative energy for finding ways of pseudonymizing and anonymizing users (where possible — depending on what you are collecting deanonymization might always be possible).
The truth is, that we had some rulings on what is considered personal data and what isn't and IP adresses, even parts of them can be regarded as such. Now you and I might think this is silly etc., but if we write software for corporations that have to pay fines as a feaction of their total revenue not knowing that can easily ruin our lives.
And I am merely reflecting the way how these laws have been interpreted and ruled on so far in the comment section for an article on, well another ruling by a court. Legal reality, like physical reality doesn't go away if you close your eyes.
Is this what you originally meant?
Nontheless I hope you can see in which way the whole thing is still deeply connected to the legal question of how one can still learn about their service without tracking single users when they don't give their consent, maybe now even via DNT header.
That is personal information.
It does not matter how you collect that personal information, so whether you use cookies, pen and paper, the digital equivalent of a rube goldberg machine or UUIDs in the URLs — totally meaningless. As soon as you process the IP and use that information for any purpose not considered legitimate interest you are on the hook (and no: if you are in doubt it is not legitimate interest).
Many wrongly believe GDPR is about cookies. It is not. It is about the information and the consent. So whether you change the collection mechanism doesn't make any difference if you still collect the info. It just means you now have to update your consent banner to include that new way of data collection as well ; )
Let me give you a hint: Because they are required to do so by law (at least in the biggest free market on the planet). Now maybe you can figure out how that law is called and why it is relevant in a discussion where the topic is DNT and a German court ruling it needs to be honored.
We are not discussing whether tracking is technically possible — that would be a pretty short discussion: Yes it is possible. So we are talking about something else. And if we are not talking about the law, why did you even feel a need to come up with a way of circumventing it?
To summarize: we’re talking about technical solutions to linking sessions across independent devices. What’s your “short discussion” answer to that?
So when the headline says »German court prohibits Linkedin from ignoring DNT signals« the interesting point isn't what is technically ancient history, but what that new legal reality might mean in practise for those of us who build, maintain and run the things that are affected by said legal reality.
Or what more did you have to say than hint at one very obvious and noticable way to do tracking?
So from my perspective: No. I jumped into a particular thread that seemed to imply one could "get around" that particular legal issue with a technical fix, which is just false. You sure can do that but it will not make the legal risk go away, just because you are not using cookies.
Now of course you could again go and attack the messenger instead of telling us why a technological workaround for a legal issue has nothing to do with the legal issue inside the comment section on said legal issue. Now because all of this could just be one great misunderstanding I am going to assume you don't know that much on the legal side of the issue and my comments on "your" thread came across as aggressive which raised the heat unnecessarily and was not my intention.
"No cookie or localdb or browser fingerprinting is going to tell you whether someone looked at a site once on their home computer, again on their phone while commuting, and again on a work computer to show colleagues."
My intention was to provide a mechanism for solving this problem. GDPR or even Europe in general has nothing to do with it.
Stop spouting nonsense. Enforcement is done by the DPA of the country where the company is located, hence why everyone is annoyed with how Ireland is handling Facebook but can't do anything about it.
I think this is unlikely to happen, because most websites actually want to track you. So they will display the banner anyway, or perhaps a slightly modified version like "we noticed you have your DNT turned on, but are you willing to make an exception just for us?"
That gives them a chance users will consent anyway to get rid of the cookie banner. And they will argue that a specific consent given on their website overrides the generic non-consent represented by DNT.
How would you make it one-off?
The Web makes it so that there is one server and lots of customers. It has to be hardened against SPAM, DDOS, etc. It pays all the costs. But also recoups them by tracking, it’s called surveillance capitalism.
Every site should have no idea how many people visited, actually. Just a bunch of static front-end content that gets passed around.
If people want to store their data, they can pay dumb pipes to store encrypted data.
Get rid of email too. Anyone who gets ahold of your email address can spam you. Instead people should pay for the dumb pipes to store messages, and you can give out capabilities for your attention. They can be transferable but if they are abused then you cut off the root of that tree. And you should charge for using them, too. Just cause someone has your public address doesn’t mean they can reach you.
In short, DNS and the Web and Email promote a certain dynamic where people invest in an upfront service and then take advantage of extreme power disparities forever, to recoup costs. And if they take on equity investors in a ponzi scheme until they IPO then they have more and more costs to recoup. There is no end to it. Wall street earnings depend on surveillance capitalism to continue.
Did they learn their lesson? Because that was an incredibly foolish assumption out of the starting gate; from old-guard developers and companies' points of view, they were stomping into a sandbox they hadn't built and upsetting the status quo that was working; of course malicious compliance should have been anticipated.
Are you telling me that EU lawmakers were utterly naive to common left wing critiques of capitalism? That beggars belief.
The banners were an extremely predictable outcome of a badly-crafted law.
Just put up a `Privacy` link for those actually conscious of the topic to give them details; you'd be doing both categories of users a solid tucking that info out of the way.
In an ideal world, respecting DNT would instantly bin 95% of the cookies and data processing requests, but I'm still getting automatic (and permissionless) marketing subscriptions from companies when I make purchases, and the British ICO seems unwilling to intervene, so it seems unlikely that DNT being case law is going to have any quick effect on things.
I think that tracking to get "good ads" is a wish that never came true and it needs people with taste to choose products people would like to buy.
Not every kind of advertising is that suspect to fraud but for every budget out there there is some way to siphon it off without giving the advertiser what they were looking for. It's been an arms race between fraudsters and marketeers with the end-users caught in the middle, and between the marketeers and the users with respect to privacy issues. This ruling injects some sanity for those that have declared themselves to be non-combatants.
Because marketing department people come and go so they don't have time/motivation to learn some in-house tool. They know gtag and they are happy with it.
A marketer wants to buy ad space, but doesn't have time to sift through millions if not billions of websites and court their webmasters one by one.
Ad platforms bring together the webmasters and the marketers with a one-stop shop. The webmaster courts Google and gets ads to sell his ad space to. The marketer courts Google and gets ad space to put his ads on.
TL;DR: Efficiency and logistics. Capitalism ho!
Place yourself in the shoes of an ad buyer: a random website offers to display your ad. How do you know what you're getting?
The "measurement function" becomes the uptick in sales resulting from the unique link embedded in said ad and ultimately the money that lands in the bank.
If I buy a newspaper ad I don’t buy unless the paper is well known enough that I can trust their number they claim is their total circulation.
Yes: for the web this means no one buys ads on the bottom 99% of sites.
Because interacting with the advertising industry, or advertisers directly, is a lot more complicated than just slapping a banner spot on your page/app¹, and sites want to concentrate on with their core business rather than learning another one.
--
[1] finding people to advertise, negotiating rates, arranging reports of add positioning and response², detecting click-fraud, convincing your ad partners that you have dealt with any click-fraud & other such issues, convincing your ad partners that your agreement with them really did involve them paying you at some point before the heat death of the universe, etc.
[2] so they can marry that up with the logs of incoming attention on their systems
So good to see legal precedent for it!
I would love for a codified way to specify this in the browser but that also makes way for the inevitable exclusions. for example taken to the extreme, compliance with the DNT means that you can not use any site that even requires a login.
That's a browser limitation. They currently implement it as a global setting. They could also allow the user to configure a whitelist of websites.
The lack of that feature doesn't invalidate it though. It's not a problem.
> the meaning of what to not track is not defined anyway
At a minimum, it means denying consent to everything you can deny consent to.
> taken to the extreme
All this complication and confusion just isn't necessary in my opinion. Tracking is the collection of any information the user did not explicitly provide for any purpose other than what the user wanted.
If I log into a website, I'm explicitly providing my username and password. The site didn't fingerprint me and automatically log me in based on that unique identifier, I did it myself. If I give a store my address so it can ship an order to me, I'm the one providing that information and only for that exact purpose. I certainly don't expect the store to sell my address to some marketing company which then starts spamming my physical inbox with advertisement garbage.
These corporations need to learn to do exactly what's asked of them and nothing else. We don't want them exploiting the information we trusted them with for unknown purposes.
This is the spirit of the GDPR: inform users of the data you collect and what it's used for, and anything not absolutely essential to the transaction may be denied. It is obvious to me that a Do Not Track header represents that blanket denial of any non-essential data collection and processing.
The fact that our legal systems have tolerated and supported it, mostly demonstrates how intellectually weak the legal profession's philosophy and ethic is.
Companies, especially interacting digitally, use TCs, EULAs and other such nonsense like an incantation. Those are not agreements. They are stupid little rituals that strip users/consumers/whoever of all rights.
Any right that can be stripped by TCs... doesn't exist.
The whole concept of "by agreement" in these circumstances is bogus but... If it must be this way... Stack the deck in the other direction.
"By serving this browser a webpage, you agree to the following..."
By dripping a cookie, by recording this person's data. Pro user, pseudo-legal defaults.
Make "you must agree to X, before you use the product you bought" invalid. Give consumers the full right to unlimited time refunds, if divulging data or agreeing to terms (old or new) is a condition for using the product
This ridiculous deck can be stacked either way.
If I have to agree to a coercive contract intended not to be read, in order to use a device... Give me the right to say no and get a full refund at any time. At least invalidate the agreement.
Where TF are our judges, judicial philosophies, law professors? I want to ask "How could they let this happen' but the correct question might be "Why did they do this to us."
They are writing law in MS Word and negotiating any changes in law by sending paragraphs over email, which they check once a day at most.
Fair point. But, I don't think it's good enough, at this point.
Software is not new or marginal anymore, and the business of software certainly isn't.
Practices like terms and conditions... Its not something lawyers can't see. I've heard the same thing about patents and I don't really believe that either. Patent lawyers, specialists and reviewers are nerds... They're not "boomers."
There are no more excuses. It's just makes suck now.
Although that standard might lead to them just moving to a monthly subscription model
The consideration for the change is getting the new features, updates, or using the services.
I'm not sure how this works if it's one of them subsidised phones however.
To my understanding in many countries this is already illegal in practical terms. Users in those countries are usually permitted to just click through those kinds of agreements and they'll hold no legal water. A EULA must be shown before the user obtains the application or appliance (this for example is why Steam will ask you through click through accepting any third party EULAs before you can download a game and why third party EULAs for a game are listed and readable in an attention drawing yellow bar on their store page) and "back of the box link to the EULA" isn't allowed. (And even then, the majority of stuff in EULAs that goes beyond the liability-related stuff is illegal anyway since they forbid things that are considered rights you just have.)
The US is basically the only country where these kinds of shrinkwrap EULAs tend to have more use than fancy toilet paper as far as I know.
(I am however, not a lawyer.)
In a lot of countries only the terms that were accepted during purchasing are legally binding. So if you buy a windows license in a shop without signing a contract, than no additional terms except general copyright laws apply.
With SaaS and online services this got way more complicated though. They can always ask to accept new conditions and stop providing their services if you don't accept them.
Meaning you can't use the software because that would be copyright infringement? EULA are what give you the right to use the software.
Even if I have to sign the EULA in the store before purchasing the software, no "surprising" or "unconscionable" parts can take legal effect.
Using the software is explicitly not copyright infringement. Private modification probably isn't either. Generally you don't need anyone's license to use your private property as you see fit; copyright is an exception but it only applies to a limited set of things.
But as the GP said, the whole thing is a total corrupt farce.
Unfortunately every lawyer quickly caught on that their explorative legal fiction being thrown out entirely might make their employer unhappy, so most EULAs have some sort of clause that if a part becomes unenforceable, it won't break up the entire thing.
If this goes to the Federal Court (BGH) in Germany they will "ask" the European Court of Justice for their interpretation of the applicable Union law (in this case the GDPR) and other national courts will take this precedent into account.
If LinkedIn does not appeal they will be required to follow the ruling. Even in this case it's not uncommon that national courts will look across the border.
It could be a great thing. 99%+ of all people would quickly learn to opt in to tracking to get rid of the annoying popups.
Besides, if you gave users a free choice, as intended by the law, no one would consent to it.
I have exactly zero popups / cookie banners, and I'm in France and a French citizen (and a GPDR supported). My browser and extensions rejects all requests for consent to be tracked automatically.
We can easily get Web browsers to do that for everyone (it takes about one minute to set up manually) so that everyone could have privacy while having a seamless browsing experience. This is easily doable with the current GDPR.
Now, why would you or anyone prefer to consent to tracking instead?
You can actually configure each toggle yourself.
Maybe I should try it out again, it has been a while...
uBlock Origin with all available filter lists enabled (except the one for Mobile pages, if you're on dekstop).
https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies to reject all tracking consent requests.
https://addons.mozilla.org/en-US/firefox/addon/multi-account... for subdomains you want to log into but still want to access the main and other domains without being connected. For instance, I have it set always open mail.google.com in the Work container so that I can log into Gmail but still search google.com, navigate google.com/maps (etc) outside the work account.
Then, install https://github.com/Cookie-AutoDelete/Cookie-AutoDelete and set it to delete all data from all domains expect the ones you want to stay logged into (Google for instance… but only inside the Work container mentioned above). Then, all websites data (including cookies) will be auto-deleted a few seconds after your close all tabs from that domain. You have to enable the auto-cleaning and support for containers.
You can tweak a few more things but that should be enough.
I also recommend the awesome https://gitlab.com/magnolia1234/bypass-paywalls-firefox-clea... add-on but only for users who support some media financially. It's fine to workaround paywalls (such a bad system) but good journalists still needs to be paid somehow.
Idem with https://github.com/ajayyy/SponsorBlock
As for mobile, I use the excellent https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/ on Android. You can have the above add-ons there too, but you need to use Collections for that (as explained here: https://www.androidpolice.com/install-add-on-extension-mozil...). But this won't be necessary soon https://blog.mozilla.org/addons/2023/08/10/prepare-your-fire...
By the way, Firefox will soon get rid off all cookies banner without the need for "I still don't care about cookies" add-on: https://alternativeto.net/news/2023/6/firefox-115-beta-relea...
Yeah you can claim otherwise and other people are free to just deny you service. EU still doesn't have access to Threads, right? Twitter is thinking of turning off the EU as well. That attitude is why. Trade is a two way street and constantly harassing the providers is a good way to find yourself without any services to harass anymore.
So there is a clear default state - doing nothing is the same thing as refusing a request, and refusing to even read any requests is a perfectly legitimate way of doing nothing. There is no legal or moral reason to afford the request any attention or consideration, if you're ignoring it, then you're not opting in, and the site has very clear explicit information that it doesn't have your consent.
For one reason or another, the header has been deprecated for years now.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DN...
Lol...
As if China and Russia care anything about privacy. They are complete panopticons. You can't compare them with the EU. Which is a democracy unlike the others.
The only reason China has this policy of storing Chinese users' data in China is so they can spy on them more easily, not because they want to give them more privacy.
In regards to Chinese and Russian "news" you're not missing anything as it's just propaganda anyway :)
Maybe in Eurostan, but not in America.
So no, there's not less censorship in the US than in the EU. You just gave up trying to say anything meaningful.
The only mentions of China and Russia in this thread is this post of yours. What are you referring to?
Now that the GDPR and CCPA have existed for a while, and the kinks are getting worked out (see, for instance, the article above), that lowers the cost of adoption, and will make GDPR-type rules an easier sell for US states who want to adopt them, or the US as a whole.
Russia and China do not have GDPR-type protections (they do have some data locality rules, though for rather different reasons).
I think it will have to be challenged country by country to make them use this interpretation.
But this 100% sets a precedent for other EU countries.
The court did not force LinkedIn in any way to actually respect or at least consider the DNT-header in their processes.
This is how I (being a German native-speaker) understood this article by the usually very reliable heise online: https://www.heise.de/news/Do-Not-Track-LinkedIn-darf-nicht-m...
But you're right. It sounds like the court interpreted it that way, but anyways, the ruling is only about the claim, not about whether they respect DNT or not.
If upheld, the judgement certainly seems to open the door for future litigation, and one might even hope for potential targets to adjust their behaviour in anticipation of it, but I would not hold my breath there.
[1] https://www.vzbv.de/sites/default/files/2023-10/23-10-10_Stn...
1. A shopkeeper that watches his customers for shoplifting and observes their flow in the store to know where to place products.
2. An online store that tracks what products people are looking at and what carts are abandoned the most.
3. A global ad-network that gets fed most of your browsing activity across the internet and creates an advertising profile for you.
Don't you agree that a difference in scale brings on a difference in kind somewhere on this axis?
The way I personally see it is that what a user does on your website is fine to observe, but when data is being shared to third parties is must explicitly have your agreement.
You can view and modify the ad profiles Google has for you [1] [2]. I leave it running because I’m vaguely curious what it will find. So far, the ad topics are extremely generic and not anything I worry about.
[1] https://myadcenter.google.com/ [2] chrome://settings/adPrivacy/interests (if using Chrome on desktop)
I'm hopeful that the ad topics code in Chromium will improve this situation somewhat. Maybe someday we will see reproducible builds for Chrome?
This is targeted, but only barely.
GDPR created a lot of burden for small companies and at the same didn't seem to offer that much protection against abuses from the likes of Google/Facebook.
Much like tech standards/specs laws have a section defining the terms used in the law. So, GDPR defines these things. In the context of GDPR tracking probably doesn't even exist as a term. There's personal data that you can't pass on to third parties without user's consent and similar things.
If a person is the subject of your tracking, then you need that person's consent.
If an inanimate object is the subject of your tracking, then you likely in the clear.
The caveat is that if you track a person via your tracking of inanimate objects, then you better have that person's consent.
Whether a space is occupied or not is an observation of the space. What an inhabited space looks like is an observation of both the space and its occupants.
Sorry, but I can't find any other response to what you said there.
is this "need for my business model" or "need because we can't send a package without your address"?
Fairly typically applies to small local news websites in the US.
I was imagining a scenario similar to what Facebook is doing in Canada, with messages stating "We cant show you [x] because your government hates free speech" (hyperbole)
https://gdpr.eu/gdpr-consent-requirements/
Consent must be "freely given", which means you have not cornered the user into agreeing to you using their data. Requiring consent to data processing therefor excludes consent. You need to be able to say no.
The legal problem with geo-blocking to work around the GDPR is that the error page is usually not GDPR-compliant either. That said for most US sites which apply geo-blocking this is very much a "we'd rather lose that part of the audience than respect anyone's rights" kind of deal. You can roll out the GDPR-compliant treatment for your US users too and it'll be to their benefit. It just means your broken business model that relies on abusing your users' privacy might no longer work.
Note that there are EU sites that do force tracking ads on their users while still being GDPR-compliant by only doing so after the user has consented to it and offering a paid subscription without these ads as an alternative. So it's not just "but we need ads" but explicitly "but we want to harvest your data and do who knows what with it".
Other than those two I don't see how spying on users is a business necessity.
Websites that refuse to serve be any content due to that law are just yelling at me saying "we don't care one bit for your basic rights for privacy". They have zero intention of sharing anything respectfully and would just sell my data instead, with no accountability whatsoever.
Consent must be freely given
“Freely given” consent essentially means you have not cornered the data subject into agreeing to you using their data. For one thing, that means you cannot require consent to data processing as a condition of using the service. They need to be able to say no.
It's just like any contractual clause that would sell yourself in indentured slavery or oblige you to make sexual favors is automatically void, since consent to these things is not something you can sell, you can change your mind about these things at any time no matter what contracts you've signed, because they can't be binding for that.
Just like no company can purchase my kidneys. I can donate them, and hospitals can transplant them, no problem. But they are not for sell.
We know what is being done with human organs when it's on the market for profit. Nothing good. Idem with privacy (especially when your personal data encompass other's: contact details, emails, photos, etc).
The argument is that denying doesn't prevent you from acessing the site.
I recall there's precedent for this being legal, but I can't seem to find it. Search engines have really gone down the drain lately.
I've also seen a Spanish site with this, but as far as I know it has only been accepted by Austrian and German authorities (and challenged recently by some courts).
https://news.ycombinator.com/item?id=36720629
It just hasn't been broadly enforced yet.
> # Freedom
> Freedom of movement gives citizens the right to move and reside freely within the Union. *Individual freedoms such as respect for private life, freedom of thought*, religion, assembly, expression and information are protected by the EU Charter of Fundamental Rights.
>
>[..]
>
> # Human rights
> Human rights are protected by the EU Charter of Fundamental Rights. These cover the right to be free from discrimination on the basis of sex, racial or ethnic origin, religion or belief, disability, age or sexual orientation, *the right to the protection of your personal data, and the right to get access to justice*.
(excerpt, emphasis mine based on current context, original: https://european-union.europa.eu/principles-countries-histor...)These basic rights (considered parts of the so called European values) are often infringed by US companies employing extensive surveillance.
Hope I could help.
t. Eastern European assuming the desire for privacy is a universal European value, not only thought in school curriculum.
Care to explain what part is laughable or are you just preaching to some "government bad!" choir?
4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
The spec itself (at the time, at least) said that it could be ignored if the header was always sent/not user-enabled.
Why?
Then Microsoft enabled it by default in Explorer 10 and the ad networks took it as carte blanche to ignore the DNT header forever, claiming Microsoft had violated the agreement. Nowadays it's usually not set even by the overly privacy conscious out of fingerprinting concerns, since its another unique way to identify your traffic.
The same way they campaigned against adblockers but had their own petty little voluntary pledge thing.
That's what you get when your NGO gets so big your leaders end up playing on the same golf courses and waiting in the same netjets lounges as the enemy.
I couldn't find any explicit discussion of that aspect of the spec (https://datatracker.ietf.org/doc/html/draft-mayer-do-not-tra... is an early version), but I suspect that as noirscape wrote, it made consensus-building easier. Not that it mattered in the end, of course.
The original Internet Explorer situation was different because it came pre-installed with the operating system, and whether there is choice in operating systems for any given piece of consumer hardware is often rather dubious today (and was probably “no” in more cases back then).
it doesn't need to be argued as the fact that the user did not disable the DNT option in such a browser is the action that matters.
You could argue that by using a browser where the DNT header is set by default, they are making that decision on their privacy by y'know, using those browsers over the ones where they're not set by default. Ad companies don't want that argument, they want you to opt out in every browser (and ideally they'd just ignore the header entirely, which they do after Microsoft enabled it by default in Explorer).
I don't blame people for forgetting that part sometimes, given how 90% of the population uses a browser that doesn't serve their interests.
How would that work? Has the server a mechanism to check if DNT was set by default on the client/browser?
Obviously, this was a ploy to gut the standard while still pretending to self-regulate.
It's EU - the default is to require consent for using personal data (which in at least few of the jurisdictions IPs are included). The the 'default' should be out.
To which I'd say: they shouldn't even see the cookie banner in that case. DNT alone is enough.
And if I say "yes, actually, even though it was very rude of you to ask, given the shirt that I am wearing...in fact, I would like to have sex with you," then you should at least have the decency to wait for me to take my shirt off before having sex with me.
If I decide it's really not worth the effort to take the shirt off, then it turns out, actually, no, I really did not want the sex after all.
Consent/tracking doesn't mean solely 'cookie' banners.
EU courts have already ruled that "cookie banners" that are too-confusing aren't considered consent.
> According to the General Data Protection Regulation, the right to object to the processing of personal data can also be exercised using automated procedures. A DNT signal represents an effective contradiction.
I assume automated procedures include default settings. Not a lawyer and not from the EU though
Let's assume Aunt Agatha reads about the DNT setting in one of her magazines, goes to the browser settings, sees that it's enabled, takes no further action. That is no different from Uncle Ulysses who has a different browser with a DNT-disabled default who goes to the settings and enables its.
My letterbox has a sticker on it that I don't want to receive unsolicited ads. I don't need anyone to try to presume that it wasn't me who put that sticker onto my letterbox.
After that, I got ads put into my box again. Once I asked one distributee if he can't see the sticker.. "it's damaged. So I thought you wanted to remove that, but it made problems so yo left it striken through"
¯\_(ツ)_/¯
Just like the same reason for you can get fined for throwing away litter. If it's not your litter box.. :)
I wish that the free willy said "I don't want" is binding for all people over the world.
In Firefox you can't even turn it off, except maybe via some about:config thingy, so that's not really an entirely valid assumption.
The choice just happens on a other level.
There's a setting on Firefox (Beta at least) that enables it.
See:
https://globalprivacycontrol.org/
https://www.huntonprivacyblog.com/2021/07/15/california-atto...
https://commission.europa.eu/law/cross-border-cases/judicial...
You could try that in court since the base gdpr is the same, but EU law implementations still differ.
Don't know though how different court judgements are interpreted. I'd guess it would have to be an EU-court judgement for it to bind other courts. In most EU countries only high/supreme court rulings set a precedent anyway.
On paper that is the idea politicians had, but they don't always have the final say in practice. For instance Germany's Federal Constitutional Court reserved themselves the right to make decisions superseding EU regulations, however re-affirming the authority of the European Court of Justice "in the general case", since it is compatible with Basic Law for the Federal Republic of Germany. Neither court is explicitly considered to be higher and their stance is cooperative.
So far, as far as I know, no EU regulation was struck down in Germany, only parts of various laws implementing directives.
If there is a contested interpretation of EU law then the lower courts of a member state MAY refer a question (or questions) to the CJEU to resolve the issue.
In the case of the highest courts (where there can be no appeal) they MUST make a referral to the CJEU.
These referrals also aren't "appeals" as such, either, but are designed to answer the questions in such a way that the member states' courts can resolve the case with an authoritative (and consistent) interpretation of EU law.
Also national court decisions do not apply to other member states.
Well, they can't.
But as long as these companies unneccessarily track my browsing habits in order to serve ads, I'll continue using a tracker blocker like uBlock Origin with the sad side-effect that the ads disappear from the page.
Speaking of, I am expecting DNT to reset to disabled silently on next release of chrome. So people forget about it and tracking is allowed.
Those two-stage "legitimate interest" opt-out toggles are pseudo-legal nonsense dreamt up by (mostly non-EU?) companies trying to shoehorn their business model into the new legislation, just like the "consent pop-ups" that don't provide a single-click "disagree with all". Those are actually explicitly forbidden by the ePrivacy directive btw: there must be a first-level "disagree with all" button and it must be as visible as the "accept all" button if there is one.
I actually see nothing in this ruling about DNT that makes DNT do anything that isn't already the default under the GDPR. As far as I can tell, the ruling just supported the claim that LinkedIn was demonstrating deliberate intent in its violation of the GDPR by saying it does not consider DNT to be relevant. It was likely already violating the GDPR based on what the article describes, this just establishes a justification to issue a serious fine rather than just a warning.
Because after all, it's run by YC who is a for profit organization who couldn't care less about the privacy of it's users
When logged in I do get 4 cookies
- user (technical)
- _ga (Google analytics? Source doesn't include any)
- ajs_anonymous_id (Dunno. Searching around brings up atlassian jira cookie...)
- ph_phc_.................._posthog (PostHog?)
Anyways, the site is superlean and hn.js is such a short script.I think other 3 could be related to parent site. user cookie only scoped to news.
https://blogs.microsoft.com/on-the-issues/2015/04/03/an-upda...
https://dejure.org/gesetze/UWG/7.html
Sure, theory and practice and sueing offenders are all different things, however most obey that here I'd say?
Perhaps advertisement is only something big companies do? /s
https://dejure.org/dienste/vernetzung/rechtsprechung?Gericht...
If their job is to litter, then tough luck.
I also send nasty letters to parties who consider themselves exempt from that before elections (they're not).
What pisses me off is that they advice to do the same in my country when I complain about leaflets from Lidl, Kaufland, Rossmann and others. Take your silly practices back to Germany, I don't need to label my postbox NOT TO RECEIVE your spam over here. "No spam" is the default without any label.
"Our business depends on tracking. That's how we make our money. We cannot provide this service for free to someone who has activated do-not-track. We do offer a paid version of the service at $X per month. If you want to subscribe, click here. Otherwise, if you want to continue to use our service for free, you will have to disable DNT."
But you can rest assured that GDPR enforcement is and will remain totally broken. If GDPR was actually enforced there wouldn't be tracking-targeted ads etc in EU at all, because very very few people actually want them. And why would they?
Why? Because nobody respected it, and since it was a user setting that needed to be explicitly enabled, it proved to be a useful additional dimension for browser fingerprinting.
So the irony is that, "do not track" ended up being used... to track.
But with most things GDPR, enforcement is key. I doubt any other website will actually change their behavior because of this.
There's a single website that I have encountered that publicly respects Do Not Track: Geizhals.de
No other website, that I know of at least, actually checks this.
One could dream.
Still sad that our legal counsel didn't like the idea of self hosting web analytics (since then we'd become a data processor).
My local dentist has a cookie consent banner up and it's certainly not because they need that vital web tracking of the odd person who tries to find their opening hours but because it's the default setting of their hosting provider.
If it becomes a hassle for companies to deal with this it'll lead to data minimization.
Most companies do not need detailed analytics beyond counting inbound links.
geizhals.de shows a message that it honored DNT, but in the ideal case you don't even see it.
However, it will take time...
Asking again for consent after being rejected is forbidden.
Just check how confusing and ambiguous the whole header is across various references
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DN...
Wonder if they will continue to make this ridiculous argument now.
This one feels legit; DNT has been around (and ignored by everyone) for a long long time. But the summary here is saying, oh, the consumer signalled something so sites have to obey. It feels like fools could make up all kinds of arbitrary signalling systems packaging all manners of data handling directives to sites.
So, what if any limits does the court see or allow? If DNT is something sites have to obey, what's something sites wouldn't have to obey? And how do sites become aware of all the different mechanized ways consumers might send processing directives to them?
I could configure my browser to add some custom headers to my HTTP requests, like `DONTDOTHISTHINGTHATISIMPORTANTTOME` or something. I don't think courts would accept that, as it's not an established interface / protocol, and furthermore GDPR does in fact allow for data-processing if it's needed / required to offer the service.
By providing an interface standard, however, the browser vendors have kind of set the stage for the courts accepting DNT as a valid communication medium for the service consumer to state intent to the service provider. This is akin to the courts taking into account how the card-payment terminal works when ruling on matters of card-payment in stores, etc.
The EU has had problems with this kind of activist lawmaking for a long time. It's one of the factors behind Brexit. Some Leave campaigners argued that it was impossible to make any kind of deal or compromise with the EU if it meant staying in, because no matter how clearly written it appeared to be and no matter how watertight the international treaty encoding it was, the European courts would simply ignore it and/or rule it invalid. This criticism landed because there was precedent for that, where the courts had previously done exactly the same thing with other agreements. The same debate is now playing out around the ECHR as well, which the UK stayed in because it's not technically an EU court, just a European court. Same cultural issues though.
https://www.politics.co.uk/news/2013/11/13/the-stolen-refere...
It was one of the events that led to the ECJ's perception as an activist court that makes EU law unknowable, because what is or is not illegal can't be understood by reading the treaties or laws. Here's an example of some British lawyers expressing that view:
https://lawyersforbritain.org/wp-content/uploads/2018/04/eu-...
The effects of the Charter, whether applied to UK laws made before or after Brexit, cannot be predicted as its operation would be dependent on the rapidly evolving and expansionist case law of the European Court of Justice, and would open the door to judicial adventurism in our own courts.
Not just the UK has complained about this. Here's an example of corruption in the ECJ uncovered by Irish journalists, in which the ECJ was trying to surreptitiously expand EU powers:
https://euobserver.com/investigations/131569
It is clearly corrupt to hear a bogus case like that where the plaintiff doesn't even know they're in a court case at all and both sides are represented by the same firm, yet nothing was ever done about it.
There are counter-arguments but I see no need to thrash them out. It's nice just to see some fucking thought.
If that were the only reason (nobody said it was) then the UK had to leave the UK immediately.
I mean, what you're complaining about here is how ~all vaguely modern legal systems work, not anything special about the EU.
It's neither bad nor vaguely written.
It's not courts who "discover" something, it's the predatory industry that keeps discovering that yes, laws matter, and yes, privacy matters.
It would be really fun* if the headers of an HTTP request were to be considered part of a legally binding agreement between client and server.
*In a "mentally deranged fun" sense, of course.
It's not a crime to put an advertising truck outside a house, but it can be to put a (private company) surveillance truck.
„ the data subject may exercise his or her right to object by automated means using technical specifications. “
https://www.privacy-regulation.eu/en/article-21-right-to-obj...
From that it seems pretty clear, that automated signals like „do not track“ are allowed and legally binding.
https://wideangle.co/documentation/data-do-not-track-handlin...
(but you can disable it if it does not apply to your situation)
However, you’ll have to live with the consequences. Maybe it’s time to reduce reliance on tracking after all?
You cannot discriminate based on race, for example.
A major point of GDPR is that it basically made "do you agree to tracking? yes/no" a protected category as well.
Specifically, it requires freely given consent to allow tracking. Freely given consent is defined by the GDPR as consent that was given without any discrimination, rejection of service, or extortion in any way influencing your choice.
So no, you absolutely cannot discriminate based on whether users agreed to tracking or not.
There does seem to be a loophole for enforcing tracking ads as "legitimate interest" (i.e. not seeking consent) if you also offer a paid subscription without them, which is what a lot of German news sites seem to have shifted to. There was a recent court case in Germany however because a company got sued for not providing an option to not consent to everything that wasn't related to ads (e.g. analytics, third-party widgets and so on) and most sites seem to now provide granular controls even when they force ads if you don't want to pay. Note that they still have to lazy load the ads after consent is given in order to be compliant. I'm not sure if this way of forcing ads is compliant throughout the EU as it feels more of a gray area given that the site usually sends the full article and then gates it behind a consent modal on the client, i.e. there's no technical requirement to show the ads, just a sustainability one.
In America yes. In Europe no, you can't project US law here.
For example the "We don't bake cakes for gay couples" is absolutely not ok here either.
https://en.wikipedia.org/wiki/Masterpiece_Cakeshop_v._Colora...
Good luck, then!
Maybe I am too naive
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/451
1. I hate that LinkedIn ever makes me log in to see a profile and
2. It's pretty much the purpose of LinkedIn to share your information publicly
The idea that you have to obtain explicit consent to do what your website advertises itself to do is idiocy.
If I make a website called 'publishmypii.com' is a German court going to force me to add a click through agreement that says I will publish user's PII? Total nonsense.
"The social network LinkedIn is no longer allowed to announce on its website that it does not respond to "do-not-track" signals with which users object to the tracking of their surfing behavior via browser settings. This was decided by the Berlin Regional Court after a lawsuit by the Verbraucherzentrale Bundesverband (vzbv). The court also prohibited the company from setting a preset, according to which the member's profile is also visible on other websites and applications."
...
"If consumers activate the "Do Not Track" function of their browser, this is a clear message: They do not want their surfing behaviour to be spied on for advertising and other purposes," says Rosemarie Rodden, legal lecturer at vzbv. "Website operators must respect this signal."
...
"The District Court of Berlin agreed with the opinion of the vzbv that the company's communication was misleading. It suggests that the use of the DNT signal was legally irrelevant and that the defendant does not have to pay attention to such a signal. That's not true. According to the General Data Protection Regulation, the right to object to the processing of personal data can also be exercised by automated procedures. A DNT signal is an effective contradiction."
Not only will the Germany of the 2030s be less technophobic, it will be significantly less relevant in the EU and on the global stage.
And by and large, Europeans won’t miss their stewardship.
I have a heavily modified web surfing browser that offers me some amount of privacy and ad free experience. Pay walls I circumvent with "Pass paywalls clean" or with a bookmarklet that looks up the site on an archive.
In the end, it makes it harder for an average website to track me but not impossible. Dont believe me? Try this website:
https://www.amiunique.org/fingerprint
By the way, ghostery, the ad blocking software, is (was?) owned by a German media company. Hubert Burda Media. You can't make this stuff up. And no, you should not use it.
I flatly do not believe that CGNAT is not used in Germany. Do you have a reference for this?
> the ISP contract owner takes full responsibility for anything happening behind it
What's that got to do with anything? The issue here is the bad behaviour of the website, not the client.
Edit: to clarify, a specification based on asking for something is a recipe for everyone to ignore you. It's a design flaw. And if they fix that with a legal patch then it will just be moved out of the jurisdiction that the legal patch applies to.
Most large companies would like to continue making business in Germany, so I expect this to have some impact.
If you allow any citizens of the EU you're forced to fully comply with the gdpr or face legal action. It's illegal to cherry pick.
You can require a checkbox with "I'm not a citizen of the EU and I'm not in the EU at the moment" to sign up, but that's going to cost you.
If anything, a technological solution would be inferior. We're a rule of law world these days, not a motte and bailey world, and that's benefitted everyone except the moat diggers.
Enforcement is always the biggest issue with these kind of laws and the EU has been taking a slow approach so people barely care.
the big multinationals are (by definition) the companies that predominantly serve the European market so the gains for the consumer and liability for the companies go hand in hand. Sure the Oklahoma Gazette isn't going to care but like three Europeans visit their homepage every ten years so it's not like it matters much in the first place.
The actors you want to discipline are, like in this case, LinkedIn, Meta, Google, what have you. The sites that account for the overwhelming majority of traffic.
I don’t think it applies to the US. The first amendment takes precedence over German laws. They can block access, but they can’t sue if there is no entity in Germany.
I like the GDPR. I’m glad we have CCPA here. I’m also glad I’m entirely outside the GDPR’s jurisdiction and I’m not subject to it.
GDPR also includes restrictions of speech - you can’t talk about corruption convictions if they happen more then x years ago - that I wouldn’t mind the US going to war against Europe to shield these rights.
I've had some luck in said arguments by pointing out that Chinese law forbids certain content, and asking if they abide by it. It's interesting to discuss why EU law should apply to non-EU hosts, but Chinese law should not apply to non-Chinese sites.
Whatever the US wants to enforce, gets enforced. The DMCA, for instance.
And a small company might be able to ignore the gdpr, but the owners would still potentially get in potentially serious legal trouble. There are quite a lot of extradition treaties in the world.
That being said, the EU has been very slow on gdpr enforcement so yeah, it's currently toothless.