UK ICO response to Google's policy change on device fingerprinting
ico.org.uk
ico.org.uk
There is a subtle but important difference here.
If governments enforce policy by bullying HSBC/Google/E.ON to enforce policies for them, there is no legal opportunity for companies and individuals to argue for their sake. You'll just be shut out of your bank/advertising/electricity for doing something "wrong".
If instead UK ICO would bring a legal case against an individual or company applying fingerprinting (and I'm no advocate of fingerprinting, but that's besides the point) then they can defend themselves in court.
Having Google forbid it makes a lot of sense
(For all I know Japan has similar rules, the point isn't the specific country, but that this would be the UK projecting power internationally that it shouldn't be).
Google isn't just a hapless bystander here, they are enabling and profiting from the practice. Big tech companies all build these billion people villages and heavily tax every person inside but when "outside law" is broken then "outside authorities" should fix it for free.
The rules could be simple: you have a problem in your village, either you enforce the laws there, or national authorities will do it and charge you (the company) for the service.
When Amazon allows any of the millions of ephemeral clone-storefronts to sell shady or illegal stuff, would you rather have the authorities spend years chasing ghosts or have Amazon change their rules to make sure such illegality and abuse aren't possible in their marketplace?
I'm fine with a law saying Amazon is liable for fake storefronts etc. Sounds reasonable. I'd also favor requiring e.g. Uber or Airbnb to provide authorities with data to prevent tax fraud from operators in such marketplaces.
But to me saying Google's advertising product should enforce how the individual websites work [fingerprinting], is to me more in the direction of "an electricity provider should enforce how people live their lives in any home provided by such electricity…"
Google's ad network isn't just dumb pipes for information like an ISP or an electricity provider, they're actively charging companies money in order to send whatever information to be displayed and code to be executed those companies want them to onto the screens of people that they're actively targeting. It should absolutely be Google's (or whatever ad network's) responsibility to not allow bad actors to use their services to spread viruses/malware, nor to allow even worse privacy evasion that they're already doing themselves such as allowing fingerprinting.
"Google's advertising product" should do no such thing, the websites can go right ahead implementing whatever they dream of. Google "the company that develops the OS for my phone and the web browser" on the other hand is responsible for what tools and features it gives to those websites or apps to use on my device and without my explicit permission.
For example Google doesn't allow them to have root on your device, or covertly activate your microphone or camera. Why aren't you asking "who's Google to police what websites can do with my device, camera, and mic"?
> is to me more in the direction of "an electricity provider should enforce how people live their lives in any home provided by such electricity…"
Quite the opposite, Google or the electricity provider should enforce nothing on you or me. The analogy is more like the electricity provider allowing anyone to access information about what you do using that electricity. Why would the electricity provider have access to that information in the first place, and why would they be allowed to create interfaces that share that info with their partners?
If you're fine with Google allowing sites to collect this information from you, would you also be fine if your electricity provider allowed sites to collect info about how you use the electricity?
That's a wild analogy.
You're talking there about what I do in my home without impacting anyone else.
With google here we're talking about companies tracking users in a way likely to be illegal.
> But to me saying Google's advertising product should enforce how the individual websites work [fingerprinting],
This is about the advertisers.
In many jurisdictions, you can charged, for not reporting someone else's crimes.
Even if Google should not be responsible for other sites doing [fingerprinting], the fact that they are enabling it should make them liable.
I don't think this is needed via ICO or via laws, to be clear. This can be a simple lawsuit. That's the right way to do things.
Source? At least in the US, "duty to report" is limited to stuff like suspected child abuse.
Google literally added all of the random APIs into Chrome that fingerprinting depends on.
If you trust Google then they are a bystander. If you don't then they orchestrated this entire situation over the last decade or so in order to cement the dominance of their advertising business.
Your browser needs to be able to render text in different fonts, which means that without paranoid design (and maybe with it) code running there can tell what fonts you have installed.
A web app may want to tell you when something happened in your time zone even though it happened somewhere else. So there's value in having code running in your browser be able to tell what time zone you're in.
Different browsers, and different versions of the same browser, have different bugs. So there's value in letting code running in your browser know what version of what browser you're running. (Note that this information has been exposed by browsers, though not always very honestly, since before Google even existed.)
Browser/device fingerprinting has been possible since before Google ever shipped a browser.
I wouldn't be surprised to learn that Google has made design decisions in Chrome motivated by not making fingerprinting too difficult. I also wouldn't be surprised to find that they've done the exact reverse. Maybe they've done both. But the possibility of browser fingerprinting isn't the result of some galaxy-brained conspiracy by Google; that was there all along because when browsers first gained the ability to run code the people building the browsers never thought of the danger, and by the time someone did it was already too late.
You don't get to be that big and make your own rules.
> If governments enforce policy by bullying HSBC/Google/E.ON to enforce policies for them, there is no legal opportunity for companies and individuals to argue for their sake
Companies are in no way stopped from fingerprinting just because of google.
> When the new policy comes into force on 16 February 2025, organisations using Google’s advertising technology will be able to deploy fingerprinting without being in breach of Google’s own policies. Given Google’s position and scale in the online advertising ecosystem, this is significant.
This seems like a very reasonable statement, no?
But when I read this it seems like they are unhappy with Google no longer enforcing their view of fingerprinting:
We think this change is irresponsible. [...] We are continuing to
engage with Google on this U-turn in its position and the departure it
represents from our expectation of a privacy-friendly internet.Their comment that you said you didn't understand made complete sense in the context of that aspect of the ICO's post, but you seemed to not see a link between the ICO wanting Google to reinstate the ban and seeing that as Google policing that subject on their network.
But that simply isn't true in the broad sense. It would stop some or even a large number of people from doing it in one area, but it doesn't stop it happening.
> but you seemed to not see a link between the ICO wanting Google to reinstate the ban and seeing that as Google policing that subject on their network.
I obviously see the link there.
The comment said several things, which really doesn't line up with the post. It accused the ICO of going after google rather than businesses and said that stopped businesses being able to test it in the courts.
However businesses can implement fingerprinting, the ICO can act and this can be tested.
The comment likened this to bullying companies into enforcing policies, and said it left them with no legal recourse. But there are no threats, no action from the ICO against google (except "will engage with google"), businesses can still implement these things and it can go to court.
Let's go through it and why I don't understand their point.
> One thing that strikes me reading this, is that the only thing that's changed is that Google won't disallow it.
Yep, this is right, google are changing a policy which will give a lot of businesses the ability to do something that the ICO thinks is extremely unlikely to be lawful.
> But I think it would make more sense if the ICO actually just went after the companies doing fingerprinting directly,
This is what they're saying they'll do
> instead of being angry at Google for not enforcing things for them.
Angry seems like an odd statement here. They call it irresponsible, and I think justify that. I think they could go further since this will likely result in google profiting
> There is a subtle but important difference here.
> If governments enforce policy by bullying HSBC/Google/E.ON to enforce policies for them, there is no legal opportunity for companies and individuals to argue for their sake. You'll just be shut out of your bank/advertising/electricity for doing something "wrong".
> If instead UK ICO would bring a legal case against an individual or company applying fingerprinting (and I'm no advocate of fingerprinting, but that's besides the point) then they can defend themselves in court.
And as I say there's nothing stopping this getting tested in court.
This is a pretty bland post. It's the ICO saying there's a change coming and a warning to businesses that this doesn't mean it's actually allowed, just that google will stop banning it on their network. They're saying they'll come after businesses breaking the rules.
What should they have done? Posted nothing? Not mentioned google?
Secondly the idea that google are particularly singled out flies in the face of the significant actions by european data regulators against meta and all the other big tech companies.
Thirdly the idea that google are particularly careful with users data is pretty laughable.
Either you don't know what you are talking about, or we attach very different meanings behind some of these words. Let me rephrase : of all companies, institutions or associations that I've been able to glance from the inside in my already quite long carrier, Google was by far the one where user data was the most secured, from unlegitimate access from the outside world or from the employees alike.
Also, of all the big internet corporations, I've read many stories about facebook or microsoft (amongst others) cooperating with the most repressive regimes. On rare occasion where I could read about some big corp prefering to loose a market rather than user trust, each time it was either Apple or Google. Granted, it was many years ago; But already after Google was regularly presented by EU "opinion makers" like the most evil of corporations.
Witnessing this and the ensuing downward trajectory of morale in big IT corporations, I half-jokingly developped the theory that maybe corporations are like little children: they behave just as well as they are expected to. If you constantly tell them that they are immoral and stupid, then they become just that.
Not enough staff in ICO to bring these cases. All the capable people earn much more in private sector (banking/finance) in London.
The vast majority of consent flows ("cookie banners") out there are not compliant and they do absolutely nothing about it. It's very unlikely this would be any different.
The ICO is all bark and no bite.
The majority of online advertisers are small-medium ecommerce brands.
There is no chance ICO would go that route.
I think it’s quite the opposite - Google enabling illegal use of their services should make their offering unfit for market. Being a monopolist in the space, it’s Google’s responsibility to ensure users are safe when exposed to their services.
What business do you think Google is in?!
"The Information Commissioner's Office (ICO) upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals. ICO is an executive non-departmental public body, sponsored by the Department for Science, Innovation and Technology." https://www.gov.uk/government/organisations/information-comm...
Enforcement action by the IÇO is as rare as hen’s teeth, and when they do enforce, it’s a mild slap on the wrist for large businesses, and “put you out of business” for small businesses. Lose 2,000,000 sets of customer information because you accidentally left it public? Reprimand. Don’t do it again. 1000 spam calls? £100k fine. Go to prison.
If you have a U.K. Ltd company, you must pay them their annual fee.
Quite the gig they have. Do next to nothing, collect a tax on every business in the country.
Electoral commission: 40,000,000 U.K. voter records leaked. No fine. https://ico.org.uk/action-weve-taken/enforcement/the-elector...
Random company, 60,000 spam SMS, £120k fine. https://ico.org.uk/action-weve-taken/enforcement/quick-tax-c...
Make it make sense.
Is it public knowledge how much FAANG companies pay?
The highest tier of fee is £2,900 per year, but you're looking at the wrong regulator - major tech companies invariably use Ireland or Luxembourg as their European headquarters, so most or all of their data processing activities (and subsequent investigation or enforcement) would take place under that jurisdiction.
Doesn't the Ireland trick (mainly for tax evasion) only work for the EU market? I'd assume after Brexit the UK would require local presence?
The UK copied the GDPR wholesale, the EU accepted a reciprocal arrangement based on this, so Brexit hasn't materially changed the situation.
https://ico.org.uk/for-organisations/data-protection-and-the...
They should simply be looking to prevent a re-occurrence and a fine on this type of organisation wouldn't help.
Perhaps they should have powers to prosecute executives.
Consider one example - you "process" (collecting, using, storing, viewing - literally anything) personal data in an electronic system without the latest security patch. Are you breaking GDPR/DPA18? Easily done, especially for sensitive data. "...taking into account the state of the art, the costs of implementation, ... the risk of varying likelihood and severity for the rights .. of natural persons ... the processor shall implement appropaite technical ... measures to ensure a level of security approapite to the risk" (DPA18 Art 32).
I imagine a large number of companies flout the above without realising. Especially when processing any information regarding health, criminal offense data, race, religion, philosophical beliefs etc, which is "special category data" and requires strong protections.
DPA18 Article 32 "Security of processing" - https://www.legislation.gov.uk/eur/2016/679/article/32
Most companies flout the 101 of GDPR.
Do you have a registry of the personal data processes you do? Are you able to hand it in less than 48h after receiving a request for them?
Do you do risk assessments when thinking about implementing a new data process?
And it's not only about electronic data. Paper files are concerned.
Yes it can feel like a lot but if you're handling people's personal data you should not be playing around. And if it's too hard, maybe "just" don't process personal data at all. Before GDPR we were already at a point where people just siphoned and stored people's data "in case it is useful later". Now some legislation is in place to make you think about why and how you get and store this kind of data, putting a price on doing it. It's a plus for the public.
Too bad if it does not help sell ads, scams or just abuse people.
Businesses that only use data for routine purposes like staff administration, accounts and advertising are exempt. The data protection fee only applies to businesses engaged in higher-risk data processing. The fee for a non-exempt business with turnover of <£632,000 is £40 per year.
https://ico.org.uk/for-organisations/data-protection-fee/dat...
The primary purpose of ICO enforcement is to ensure compliance. The general principle is that the sanction administered should be of the lowest level necessary to ensure compliance.
In your examples, the Electoral Commission suffered a breach due to a chain of vulnerabilities exploited by a sophisticated actor. In response to the ICO investigation, the Electoral Commission implemented a major overhaul of their security procedures including a formal process to manage and monitor patching and MFA. The ICO were satisfied that the EC had come into compliance and would remain compliant, so no fine was applied.
In theory only. I was a one man band with zero consumer data handling, and they insisted I pay the fee. Back when I had faith in institutions, I reported some really grievous mishandling of consumer data to them, several times, and they were not remotely interested.
> 1000 spam calls? £100k fine. Go to prison.
sounds just and deserved to me, fine spammers into nonexistence
> Quite the gig they have. Do next to nothing
Maybe you are right that there are serious problems with them (electoral commission failure should have been punished), but demolishing small scale spammers is already an useful service. I would fund it if I would be able to taking decision.
I would be happy to pay 1000 £ if that means that last person who spammed me goes bankrupt and to prison (for say 50 days).
> a mild slap on the wrist for large businesses, and “put you out of business” for small businesses
first one should be fixed if it is a problem so large spammers are also fined into nonexistence
and yes, I support putting their CEO into prison for 50 days if any part of their company does spam
I saw a post a few weeks ago on HN asking what's the point (in general) of using a UK legal firm when legal firms in US/EU/India exist (!).
And then there are the sneakier ones; those who dwell in digital shadow, hiding from the luminous glare of corporate glory. What will these funny fellows do, when the fingerprinters tap on their windows and ask for their papers? What of their intent, and the glasses they wear to shield their eyes from the money-grubbing rays?
Edit: Yes, seems to work now. After I complained on HN earlier their CTO asked me to send a trace. I did so and a couple of months later the problem was gone. Whether that was causal or incidental I have no idea.
And then everyone ignored this outcome because of the implications. Ofc there is the "legitimate interests" line. Vague enough for a judge to apply as they see fit, but one judge messed up at least one time.
I didn’t know about this change n in policy from Google but, in summary, it doesn’t change the legal positioning on fingerprinting as something that can fall under PII collection under UK data protection legislation. I do worry that the change from Google will make practical enforcement more difficult, however.
That would be a first. The most useless regulator on earth.
They moved a core principle to an employee guideline!
- in the bottom of the logo
- when you click "About the ICO" (breadcrumb or footer link)
It does say it right at the top of the “About the ICO” page on mobile though.
When I told them I (as a 5 person business) obviously don't have time to go through 1000s of old emails they reacted with surprise to the amount of emails. I guess they don't send many. They didn't offer any other solution.
As others have mentioned this org is a tax on all UK business.
In the UK I would keep business emails for at least 6 years as that's the limit for lawsuits.
At least one firm I worked with had a mandatory 180-day delete of any correspondence not specifically tagged for archival, and the stated reason was to prevent all their random conversations being exposed during discovery if they were prosecuted.
The usual advice, though, is obviously not to put in writing what you don't want to be found later...
Looks like i'm going back to mullvad browser
Someone is still recovering from New Year
...learns later that Reddit already fingerprints devices in the UK.
https://www.informatik.tu-cottbus.de/~andriy/papers/clock-sk...
and there is information added during the routing - not just information from client - from the intermediates.
And you also have to consider the power of patterns - where one piece isn't enough to see the picture, but if you have enough pieces you can ( jigsaw identification ).
The fingerprint is then associated with a user's email address or login identifier and then sent either client-side or these days server-side to Google Ads.
Google has never made money on "their products", really. They make money on ads, and those ads are everywhere