5 ms·
I'm really hoping that GDPR enforcement is done in a way that is consistent with the intent of the law, and that we don't end up with a repeat of the cookie reg
by _petronius 9y ago
I'm really hoping that GDPR enforcement is done in a way that is consistent with the intent of the law, and that we don't end up with a repeat of the cookie regulation (the end result of which was merely training users to click through another popup with reading it at all, and no meaningful improvement in general public understanding of what cookies are, and how or why they are used).
The cookie thing was poorly drafted, as a result advice on complying with it was poor, and it became something to be worked around rather than a meaningful improvement on privacy and an understanding for the general public of how and why tracking works. I have higher hopes for the GDPR, although I still think it is too much of a compromise, and worry about what that means for accomplishing its intent.
- meredydd 9y agoGood news - unlike the cookie thing, GDPR mandates that you be able to say no. The cookie thing was pointless because it gave nobody any meaningful choice - "click Accept on everything, or don't use the Internet". GDPR is going to make "Let me use your site, but don't use that fact to track me" an option they are legally required to offer. I cannot wait.
- wav-part 9y agoGDPR Article 7(4) When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. So GDPR does not say its illegal, just that it will be determined on case by case basis. For legal experts, is this facebook consent obtaining GDPR compliant ? https://www.facebook.com/legal/terms/update https://www.facebook.com/legal/terms/update By using or accessing Facebook Services, you agree that we can collect and use such content and information in accordance with the Data Policy as amended from time to time.
- PeterisP 9y agohttps://gdpr-info.eu/recitals/no-32/ https://gdpr-info.eu/recitals/no-32/ is the definition of consent. Simply having a term in the general conditions fails the "a clear affirmative act" part. Saying "use such content" fails the "informed and specific" part - it needs to detail exactly what uses (explicitly listing each) you're consenting to; and it doesn't list the purpose of the use, which is a key part ("When the processing has multiple purposes, consent should be given for all of them") If facebook has obtained your consent for one (or hundred and one) use-case, it does not mean that it can use it for something else simply by amending ("from time to time") the Data Policy, it would need to get additional explicit, affirmative (opt-in), informed consent to the new processing need of your information.
- amelius 9y agoThat's good news, but aren't there legal ways around that for sites that are not based in the EU? The first question could be: are you in the EU? yes -> no access no -> access, but with tracking So, basically training users to lie about their location.
- BrentOzar 9y ago> The first question could be: are you in the EU? Just to be clear - it's about EU citizens, not EU located-people, and your location can change. You have to ask if they're EU citizens.
- robin_reala 9y agoTo be doubly-clear, it’s both. GDPR talks about “EU residents”, and that potentially covers people born in EU countries, people who’ve taken EU citizenship, people who are resident in the EU but aren’t citizens, people on holiday in the EU and potentially even people transferring through an EU country while travelling. https://cybercounsel.co.uk/data-subjects/ https://cybercounsel.co.uk/data-subjects/
- kasey_junk 9y agoSome legal teams have suggested to specifically not adopt that interpretation and rather to assume it covers anyone on EU soil at the time of the data collection or when they make the access/delete requests. This feels to me as not a lawyer as something that will only be clear after precedent is set. I for one don’t want to be a test case.
- _o_ 9y agoFor the ideas like those, there was a post on pagefair https://pagefair.com/blog/2017/tracking-walls/ https://pagefair.com/blog/2017/tracking-walls/ And dont forget that the next regulation is ePrivacy regulative which might fix workarounds like you are proposing. The idea of GDPR is about human rights and if you are having a problem with protecting them, than I think GDPR is not a problem, you are.
- gcb0 9y ago
- deleted 9y ago[deleted]
- rbehrends 9y ago> Good news - unlike the cookie thing, GDPR mandates that you be able to say no. The ePrivacy Directive (aka the cookie directive) also required you to be able to opt out. It was pretty explicit, too: "Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller." The problem was that some member states cooked up an "implied consent" interpretation, according to which visitors can be assumed to have consented. The difference between the GDPR (and the new ePrivacy Regulation, which most likely is going to address the issue directly) is that they're regulations; they're directly applicable EU law, not law that has to be transposed into local law by the member states. The EU Commission is also given enforcement powers; and, if I read the upcoming ePrivacy Regulation correctly, can also go after the adtech companies directly rather than the site owners (because ignoring lack of consent is done at the adtech level rather than by site owners, as opposed to a failure of providing a consent mechanism). I also wouldn't put too much emphasis on the GDPR; while it's likely to cause compliance trouble for adtech companies, the ePrivacy Regulation is more directly applicable.
- Feniks 9y agoGDPR isn't really a revelation. In many European countries there already was data protection legislation. The only thing that changes is that now its more enforceable in a unified market. American companies had a huge unfair advantage compared to their European competition. Now everyone has to deal with the same laws.