ECJ finds IAB Europe responsible for TCF consent spam popups across the Internet
iccl.ie
iccl.ie
Their demands are completely countering privacy and will only make our CMP more hostile towards users and less privacy oriented. It's ridiculous. But they have this alignment with Google and so you have to do what they say.
> On 2 February 2022 the Belgian Data Protection Authority, in agreement with 27 other EU data protection authorities, ruled that the [IAB controlled] “TCF” consent spam system is illegal.
You could start be removing all tracking code from your site and code sharing with 3rd parties.
Boom, compliant (in that part) and not even a need for a consent form in the first place.
The you may add a feature to track and share with 3rds, but opt in. The you need the consent but can get it in a privacy friendly way.
Oh, but you “cannot” do this because the ads won’t work and you’ll loose profit? What you dont seem to realise is that this decision is already made for you by EU: with GDPR the eu made the decision that privacy is more important than your profit. You just have to face facts and stop trying to figure a way around it. Yes that means rethinking business models, but I would wager that had people known fully how they were tracked and profiled, they would not have done business with you in the first place thus your ad/tracking based business model was only valid through deception.
If this turns out to be true it would be huge. But I'm (as always) skeptical of GDPR-related de facto enforcement, let's hope I'm wrong this time.
Yes, that is true and under appreciated
> Really hard to see a future for third party ad networks
For now, what are biggest programmatic exchanges still going? I have been out of the loop for a while
If your "poor third-party ad networks who would think of them" cannot operate without dark patterns, abuse of cookie popups and malicious non-compliance, good riddance
Google, Amazon, Microsoft, TikTok, and hundreds of other tracking-based online
advertising companies rely on IAB Europe’s consent system, which Europe’s data
protection authorities have already found to be in violation of the GDPR
following our complaint.If you are an online newspaper running ads in EU, you can’t so much as sneeze without IAB’s blessing. They are everywhere.
> IAB Europe argued that it is not responsible under the GDPR as a “data controller” because it allegedly only sets the rules for how data should be used, but does not process the data itself. The Court rightly rejected this, and confirmed that IAB Europe, as management body for the TCF, is a “data controller” under the GDPR.
IAB stands for Interactive Advertising Bureau Europe [0]
[0] https://www.eesc.europa.eu/en/policies/policy-areas/enterpri...
Article 4 from the GDPR:
> ‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Seems so obvious that they're a controller by that definition (specifically a "Joint Controller" according to Article 26), even if "only sets the rules for how data should be used" would be true, that would put them inside the definition, so even by their own admission, they are a controller?
So, it appears that anyone/company who writes a spec around data that may be considered PII is now a Data Controller.
Why are you surprised they are held responsible?
"Is responsible for the consent popups"... ok. What happens now?
> However, this was appealed at the Brussels Markets Court. [...]
> The Brussels Markets Court can now proceed to rule on the matter with certainty that IAB Europe is indeed responsible, and that the data concerned are protected by the GDPR.
But my tl.dr. as I understand it is that IAB provides a Transparency Consent Framework[2] to its users, which includes popup cookies.
They lost a case where they argued they don't have any responsibility ( to the degree that they didn't even have a Data Privacy Officer or had done a Data Privacy Impact Assessment) for providing the IAB compliance popups. These popups were used by others in order to do gain "consent" to do real time bidding ads (and probably other things), it might be that they also provided some level of RBT.
They lost and the court said they are jointly responsible and need to fix long list of things and pay 250k euro.
IAB then appealed and the appeals court deferred it to the ECJ, who has now said that yes they do have a join responsibility.
So as I understand it, this is sadly not the death-blow to valid or invalid consent popups. But at least it might improve the UX on them.
[1] https://web.archive.org/web/20240109014435/https://www.gegev... [2] https://iabeurope.eu/transparency-consent-framework/
[0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...
I hate the system as it is —the "do not track" header should mean something— but I'll take a disclaimer, an explanation of how they plan to use my data, and an opt-out over the Wild West.
They're catching up but it'll be a while. The Federal HIPAAGLBACOPPAFERPABBQ are all pretty toothless and even the golden child, California's CCPA is a series compromises that doesn't accomplish that much.
Coffee supplier now tells the barista he should promote some coffee and he gets paid for doing it + sales percentage.
The barista next morning promotes some bags of ethiopian blend to you to increase the conversion rate.
Replace said barista with a website.
You did not consent to anything and I'm not aware of any laws related to this.
The first time I went there I spent about half the day in the park tossing frisbees to dogs just to marvel at how smoothly everything seemed to move.
Hence the 29.97 FPS for TV ...
1. TV was 60i (interlace), which equates to 30p (progressive)
2. The missing 0.03 frames is due to how color NTSC works https://www.youtube.com/watch?v=InrDRGTPqnE
You see that, and your problem is not "why do they need PII to let me do anything, nor "why are they giving my data to others", nor "why to SO MANY others", nor "why do they not want to tell me", no your problem is that they tell you. By describing the problem as "the law that force them" instead of "sharing so much with so many", you are saying of the two solutions available to fix that, you would prefer that they not tell you, instead of just not doing this mass sharing of PII anymore.
These banners are not what the law said had to happen. These banners are the mass sharing companies malicious compliance to get users to complain about the protection the law gives them instead of complaining about the original abuse that triggered it.
They're doing it this way because, as you show, it does work, people buy it and eat it.
> removed all non-essential cookies
It helps not to have built a business fully dependent on third party ads
Edit: related, perhaps also interesting to an international audience
Tweakers in the Netherlands recently announced a return of tracking cookies after switching to context-based advertising a few years ago. The reason given was that advertisers simply don't have tools to work with this, they'd need to implement custom software to both deploy banners to Tweakers specifically and then also to measure banners' effectiveness (like by appending ?utm_source=banner7271 to the URL). None of this is rocket science, but if you can publish on thousands of websites with one click and Tweakers requires talking to your software development team first... they were losing out. Ad-free subscriptions were and are available by the way, but people aren't buying them enough (not even the tenth part) to get rid of ads altogether. Github apparently does have that luxury
(I wish I was kidding, though it is not such a common occurence)
I visited the US and it took me a few months to stop receiving spam from businesses I interacted with. There were ads at the petrol pumps and in the bathrooms and basically everywhere else. There was little concept of consent wrt advertising and data collection, something I've come to take for granted.
It wasn't as bad as I make it, but it shows how our priorities might differ.
“People across Europe have been plagued by fake “consent” popups every day on almost every website and app since the GDPR was introduced almost six years ago”, said Dr Johnny Ryan of ICCL Enforce.
Grateful to have him onside
I'm not sure banning foreign competitors count as "caring about internet privacy". Has there been anything lately to actually protect internet privacy in the US?
If they wanted to fight for privacy, they wouldn't have to go to China to find egregious mishandling of personal data. There are plenty of examples well within their borders.
You can't seriously believe this. It's quite obvious that the TikTok debacle is mostly a protectionist measure for Facebook & Google who are looking to get their money's worth for their lobby.
Sure, for the state to snoop on you, especially in the USA, they’re supposed to need judicial oversight and approval, which is arguably a better system, than having the state snooping on you without any oversight.
Is this still meaningful in a world where BigCo is snooping on you, and then able to sell that information to the state without any oversight?
Is there a point where BigCo should be treated as a part of the state, that’s just being funded partially by your tax dollars?
Is there a meaningful difference between the state building a snooping infrastructure itself, or outsourcing that to a private contractor who provides Snooping as a Service?
Its amazing how those in the west worry more about a country that has no power on them instead of the psychos who can kidnap, torture or disappear them at whim.
https://www.washingtonpost.com/news/monkey-cage/wp/2017/03/1...
https://blog.didomi.io/vietnam-data-privacy-law-pdpd-everyth...
However, I guess we won't talk much about Vietnam's new law on the English speaking web, whether it's successful or not. Purely because we don't talk or hear much of anything about Vietnam's internal policies on the English speaking web. While we will continue to discuss every tiny detail about the GDPR.
Because large legislation by the EU like the GDPR and DMA has the the Brussels effect.
https://www.priv.gc.ca/en/privacy-topics/technology/online-p...
Canada has its own version of TCF.
There are loads, and loads more are coming.
No plans for a US federal regulation here? Wouldn't that save a lot of money and headache for everyone, if instead of complying with 50 different regulations you had one?
It's about to become increasingly tedious to be a website operator.
https://github.com/InteractiveAdvertisingBureau/Global-Priva...