7 ms·
GDPR and Google Analytics
- ocdtrekkie 9y agoCan the US please just pass this too? The EU's current stance on privacy and individual rights makes me want to pack up my life and move there. I'd much rather the law just come here though.
- ysv2 9y agoA lot of the GDPR's provisions are admirable, and fundamentally good for citizens. I'd like (some) similar rules in my country. I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU.
- thisacctforreal 9y agoI think it makes sense when your activities infringe on the rights of citizens inside their borders. It's not like the EU is saying "These activities must be abolished from the planet!"; the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website."
- ocdtrekkie 9y agoIndeed. The idea that a country would zealously protect it's citizens' rights is practically unheard of these days, but that's what's starting to happen. GDPR is a great example, another one was Canada pushing a Right To Be Forgotten ruling worldwide as well. It's a statement that someone's private data and intellectual property is theirs. You aren't free to steal it just because you're in another country. Google and Facebook have no divine right to people's personal data, and I am thrilled to see countries protecting their people.
- closeparen 9y ago>It's a statement that someone's private data and intellectual property is theirs Private data is data you don't share. Under some very limited circumstances, you might entrust private data to a third party for safekeeping, i.e. Dropbox, Google Photos, iCloud Drive, and it's important that they not leak or abuse it. But that's only a tiny portion of what the GDPR is about. It concerns records of your interactions with others. It's a statement that one side of an interaction is entitled to force the other side to delete their memory of that interaction, or to dictate the situations under which they are permitted to remember it.
- ocdtrekkie 9y agoYou are anthropomorphizing companies here, and I think it's a pretty poor analogy. Corporations do not have a memory, they have records, and those records comprise the personal data of everyone who encounters them; data those companies don't own. You seem to be characterizing GDPR as unfair towards the corporate end of the interaction, but that ignores the massive power differential that currently exists. Corporations have incredible power compared to the individual, and before GDPR, it was commonplace for services to require unreasonable privacy violations: And consumers had to either accept it, or be cut off. (In many cases, the companies doing this have monopolies, making this even more problematic.) Realistically, this is not going to impact small companies a lot. This is about big ad and tech companies, and giving citizens some minor semblance of tools to resist them.
- closeparen 9y ago>data those companies don't own I don't know if it's possible to have a productive discussion about what seems to be a question of fundamental philosophy and values, but that's ridiculous on its face. If I'm a shop owner and a customer buys something from me, the cash register prints two receipts: one the customer owns, one I own. If a customer writes me an email, I own my copy of that email. If a customer comes in and makes a scene, and I ban him from my stores's premises, the paper I generate telling my staff to call the police if they seem him is mine. If I follow him around and write down everywhere he goes... at some point a line gets crossed, sure. If I start asking other shopkeepers if they've seen him or what he purchased, yeah, something's wrong. But to claim that my records of the interactions he knowingly, willingly had with me are his property just sounds bizarre. >Realistically, this is not going to impact small companies a lot. This is about big ad and tech companies, and giving citizens some minor semblance of tools to resist them. The GDPR does not discriminate by the size of the operation. It's large companies which can reliably afford the consultant, lawyer, and engineering time to understand and adapt to new regulation. The violators are going to be those without security and compliance departments.
- ysv2 9y ago> the EU is saying "You can't do these things to our citizens without their explicit consent, and we will punish you if you do, regardless of where you host your website." The EU has neither the right nor the ability to deliver on that threat. I will continue to ignore the GDPR, as I ignore the ridiculous cookie laws, without worrying about European police raiding my home at night.
- harryf 9y agoLooking at the EUs antitrust fine for Google - https://www.google.ch/amp/s/www.bloomberg.com/amp/news/articles/2017-12-18/google-s-record-fine-of-2-8-billion-was-a-deterrent-eu-says https://www.google.ch/amp/s/www.bloomberg.com/amp/news/artic... it's clear it does have the ability. The message is "you want to profit from EU citizens? You follow the rules"
- ysv2 9y agoNo, you're confused. Google has a physical presence and business partners in Europe; I do not. (Profiting from EU citizens is beside the point.)
- akie 9y agoYeah, but what would you do if the EU decides that you cannot sell your product in the EU?
- ysv2 9y agoI would continue to do nothing special to support the EU's provincial laws. If EU citizens want to send me money, fine. If the EU decides to block its citizens from doing so, that's also fine. But I will take no actions on my end to implement EU laws, and it's laughable that some people in this thread imagine the EU has the power to coerce me to do so.
- mrintegrity 9y ago
- JoshTriplett 9y agoTo which the entirely reasonable response from anyone without a legal nexus in the EU (or physical products to ship) is "we don't care and you have no legal right or ability to enforce that". And the entirely reasonable response from anyone thinking of creating a legal nexus in the EU without an extremely business-critical reason is "let's stay in our own country where it's safer and we only have one jurisdiction to care about". For the record, when I build services, I personally don't intend to ever keep any records that aren't absolutely necessary to provide the service. That's a personal decision, a voluntary one, and also one that can be marketed to certain customers, though that isn't the reason. I also believe that if you send data to a website then it becomes subject to whatever terms they want to apply to it, and if you don't like how they use your data then don't send it to them, and block them.
- arkh 9y agoAnd the "reasonable" response to this is to act like China: block those services. China showed it is possible so now the "lol it is Internet you can't stop people accessing things, VPN, crypto blablabla" spiel is proven to do jack-shit for services which need a lot of people and their data.
- kuschku 9y agoThat'll get you an interesting interaction with your bank, which does want to have a branch in the EU, so they'll simply comply and freeze your accounts if the EU requests it. The US has forced its laws on other countries in this way for decades, always to protect profits, it's great that now another actor enforces its laws the same way, for the public.
- nemothekid 9y agoIf I'm a US company, with a non-GDPR compliant website, and a visitor from the EU visits my site, under what jurisdiction does the EU have to reprimand me? Or will my site just be blocked in the EU?
- ocdtrekkie 9y agoIt's unlikely foreign sites catered to foreign viewers would be impacted. When I buy something from a site that only sells in another country's currency, I know I'm probably going outside my own nation's protections a bit. But if you're a company specifically soliciting EU customers, and especially if you have a presence in the EU physically, expect to have issues if you're collecting data on them without consent. Bear in mind, the US will extradite people for committing crimes against US entities who live fully within other countries. Presumably if the act is bad enough... that sort of thing starts to play in. (Seriously, if the EU tried to extradite Sundar Pichai... that'd be something, wouldn't it?) The crime has to be befitting such effort though. One EU citizen's data sweeped up in your Google Analytics data does not make you worthy of a legal case. Do it several million times... maybe. tl;dr: If you're an average company not operating in or marketing to the EU, this doesn't affect you. If you're the size it's likely to be an issue for you, you're likely big enough to handle the additional requirements and do fine.
- SAI_Peregrinus 9y agoExtradition typically only applies to things which are crimes in both jurisdictions. Since these things aren't crimes in the US extradition is very unlikely.
- Kiro 9y agoHow would they punish though?
- Vinnl 9y ago> I just wish they'd drop the absurd pretense that the EU is somehow capable of imposing their provincial laws on foreign companies with no physical presence in the EU. They aren't capable of doing that, if those companies do not do business within the EU. As soon as those companies have the power to negatively impact EU citizens, however, the EU has the power to protect those citizens.
- spektom 9y agoGDPR is coming really soon, but it's still unclear how "Big Data companies" prepare to it from technical perspective. In addition to "getting consent" requirement there are "the right to be forgotten" and "the right of access", and it's not obvious how implementing these two are feasible or, at least, cost effective.
- sb8244 9y agoIt might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it was strange that the SAP SDK at a hackathon essentially required the app to get OAuth permission from the user to access / write an encrypted payload that the app couldn't read / access / delete / update without user consent.
- guitarbill 9y agoFor sure it's a bit of a blunt tool, but we've seen companies can't be relied on to do it themselves. And yes, as devs it does force us to ask hard questions that we've been conveniently ignoring, usually at the request of management or marketing. Does this need detailed analytics? Do we need to store this information? How do we need to store this information? How do we design UX to withdraw consent? How do we handle the absence of consent? Etc. More difficult, but more ethical, too. One nice thing (maybe) is that it's so much effort to get consent to run pervasive analytics on EU users, that many people might just stop running pervasive analytics on EU users at all. Maybe all users? At least I can dream...
- danieldk 9y agoIt might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to track users around the web without any consent (through Google Analytics). I find this terribly frustrating. I decided to opt out of the Google ecosystem completely, but data about me is still vacuumed through Google analytics and Google-hosted JavaScript/CSS. I use uMatrix, but blocking Google-hosted assets is out of reach for most non-technical users. We would not be here in the first place if companies and website owners treated the user's privacy with respect. I don't feel pity for them that they jump through hoops now. If you host a small personal site, just consider axing Google analytics. You can get reasonably good statistics by just using a local log analyzer that does not upload your visitor's data to an analytics/ad company. Respect your user's privacy.
- rapnie 9y agowell.. yes. super useful those google analytics. but maybe it is making things to easy for you :) if you come to think of it, it is also a privacy nightmare.. therefore google analytics is blocked by my Privacy Badger!
- ysv2 9y ago> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't comply with laws I have no vote on, frankly they can sod off.
- michael_storm 9y agoIt being fundamentally incorrect and you not liking it are two very different things.
- ysv2 9y agoYet it is fundamentally incorrect. I'm not an EU citizen, so I have zero reason to care about their laws. I will simply ignore them, and the EU has no recourse, other than possibly mandating that their ISPs block me or something. Which I also do not care about.
- hvidgaard 9y agoIf you want to do business with EU citizens, you have to follow EU law. Before the internet, you had to open a shop here, or send your goods over the border. The only thing that has changed is the fact that you provide a virtual service over the internet.
- ysv2 9y agoNo, if I want to have a physical presence in the EU I have to follow EU law. But if I'm residing entirely in another country, and EU citizens want to do business with me over the internet, I could care less what EU law says. And no amount of whining on this thread will change the fact that the EU has no leverage over me.
- 9y ago
- x0x0 9y agoMy problem with the GDPR is the EU can't even be bothered to tell us what it is before the effective date. And the GDPR itself is quite vague; lots of balancing tests and blah blah with very little guidelines on what those mean in practice. So where do the guidelines come from? Funny you should ask. Consider the ICO -- the UK privacy commission -- has been promising final GDPR guidance for perhaps half a year now, and instead are sitting around with their thumbs up their asses waiting on the Article 29 Working Party final guidance. The Article 29 Working Group held comments open until 23 January 2018. Some unknown amount of time later, that working group will finalize, and then some unknown amount of time later, the ICO will issue their guidance. But don't you worry, the ICO plans to offer no grace period to us! How the hell organizations are supposed to be ready by 25 May when they may receive final guidance in late February is a hell of a question. Realistically, considering the ICOs adherence to deadlines so far, they're gonna deliver their final guidance promptly for May 2019. I'm essentially assuming users will be hit with a blizzard of opt-in dialogues. One of the few things in the GDPR that will have impact is if you use consent as a legal basis for processing, everything has to be default opt-out.
- guitarbill 9y agoTo be fair, it isn't really ICO's fault - the government has never wanted the ICO to be really effective, judging by the UK laws the ICO was given to work with, and the laughably tiny fines they can impose. Wouldn't surprise me if they're underfunded and stuck in the Brexit mess, never mind that the GDPR will come into effect soon.
- BinaryIdiot 9y agoWhile I largely agree with you, for the most part enough guidance has been available that many companies have been preparing to handle GDPR. They should have done a far, far better job with this but it's not entirely a "We won't know anything until late Feb" kind of thing.
- x0x0 9y agoThat's true, however, there's no fixed limit to the possible distance between draft and final guidance. Say you have a large marketing database and you're trying to figure out the nuances of consent. Or you are a large bank and run on a fidgety mix of consent and legitimate interests. Three months is nowhere near enough time to get everything finished.
- neya 9y agoEdit: I want to make my distinction clearer - I don't SPECIFICALLY target/show my site to EU citizens, I show it to everyone, unbiased, the same way. But, if EU citizens SPECIFICALLY visiting my site have a problem with the way it works (cookies, tracking, etc.), then they should simply stop visiting it instead of their government trying to bully us webmasters. What bothers me the most is, as a non-European citizen of a country that has nothing to do with Europe, I'm expected to modify the source code of my website to adhere to their laws, which aren't from my country. The important part: WWW is a global platform to showcase your service/work globally. I have a problem because one entity thinks the global service needs to be customised specifically for them. How about "don't like it, don't visit it?" Simply put, I don't want to get into an argument whether this GDPR is bad/good, but, I know that I didn't vote for or against this and it's not in my jurisdiction. I don't belong to Europe either, so what are you going to do? This is what I'm going to do: I'm going to block access to my services to anyone based in Europe. It WILL affect our cash flow in the long run, but, I'm tired of governments that I don't care about expect me to follow some nonsense I have no part of under the guise of compliance on a global platform that is WWW ("WORLD WIDE Web"). I think, if enough webmasters fight back, then they'll realise. And the only way is to block your services to EU. As a cherry on top, I'll even put up a redirect notice stating: "Sorry, you belong to the EU and we're not going to follow your laws. Please fight back with your GOV if you wish to have access to our services. This has nothing to do with us." So, what are you going to do? edit: clarity
- bonesss 9y ago> I'm going to block access to my services to anyone based in Europe... I'm tired of governments that I don't care about expect me to follow some nonsense I have no part of under the guise of compliance. Ever been on a plane? ... Used a cellphone outside your own borders? ... Eaten a beautifully ripened imported cheese along with a stunning imported wine? Put your money where your mouth is: boycott all benefits of transnational cooperation and international legislation. NGOs are how a lot of the capitalism on this planet gets done. 'Compliance' is how we protect our businesses and consumers against fraud and mislabeled products. Functionally "compliance" is a judicial equivalent of an API... All I'm reading is "Why do I gotta use Googles APIs? I wanna make my own APIs! No more API use, no matter the costs to my customers, because I'm sick of giant oligarchies demanding I comply to their demands! What are you gonna do?" They'll stop doing business with you, that's what. And shrug about it. Your website will be replaced with one from Romania, and you'll probably develop a deep sense of irony if you feel they've infringed on your IP in any way and want to sue them... because all that stuff is based on 'compliance' too.
- andybak 9y agoI hope everyone is nice and busy setting up encryption, access control and timely erasure for all their server and application logs: https://www.ctrl.blog/entry/gdpr-web-server-logs https://www.ctrl.blog/entry/gdpr-web-server-logs
- chmars 9y agoThe article is full of misunderstandings. The following sentence for example is just wrong: 'You can’t collect and store any personal data without having obtained, and being able to document that you obtained, consent from the persons you’re collecting data from.' Consent is just one option. You can do logging without personal data. You might have a legal obligation do to (full) logging. You might have a legitimate interest. And so one … It is wrong to summarise the GDPR as 'consent is always necessary'.
- lucideer 9y agoYour comment does clarify the issue by pointing out the alternative, and the article could have mentioned that, but the quoted sentence is completely correct as quoted. It fails to mention the alternative, but there's nothing actually wrong in the statement. I'll give you that the article is not very comprehensive, but the GDPR is large and complex and the author doesn't set out to cover it in every detail. What misunderstandings did you see?
- yummybear 9y agoWhy doesn't the main browsers implement some mechanism to help with the notification and consent of cookies? Some standards based description about the cookies/etc. that could be consented. Non-consent means the cookie isn't accepted by the browser.
- martin-adams 9y agoCertainly with the cookie law, I feel the EU should have legislated the top browser makers to make this a spec and be implemented in the browser, than to rely on each and every website.
- chmars 9y agoThe 'cookie law', the new ePrivacy Regulation, is still work in progress. And yep, opt-in via browser configuration (instead of opt-out or no option at all) might become a thing through the upcoming ePrivacy Regulation.
- gandutraveler 9y agoI got a speeding ticket in Germany last year. I want them to delete my record. I own the data, they just tracked me over-speeding.
- xxs 9y agoData retention policies in GDPR specifically address the case, if there is a legal reason to keep the data it should take precedence. That's it you can't tell that you wish your 10k euro bank credit to be forgotten. Accounting logs might need to be kept up to seven (in some cases 10) years, so the data related to them should be kept. The data is sort of field based and some might need to be able to be forgotten earlier.
- woolvalley 9y agoSo if another country says it's not legal to comply with the GDPR in their country, they get off scot free? :P
- xxs 9y agototally, but then again you won't be able to transact with the EU, besides all the diplomatic aftermath.
- Xylakant 9y agoAnd sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping) This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order. It doesn’t impact storage of data required for law enforcement or any other reason that is mandated by law. It just doesn’t allow unconsentual tracking and accumulation of private data.
- woolvalley 9y agoThe GDPR isn't as good as you think it is. It's going to turn into one of those laws where small software startups / or normal small businesses are just going to be in constant violation, because the amount of resources required to do it properly requires a team of 5 or 10 expensive software engineers. It's going to be a great way to nip small companies in the bud and consolidate this kind of stuff into bigger companies. It gets even worse with it's extraterritoriality, because you can still be under it if your dealing with a person who lies that they are an EU citizen and they are using your service in your own non EU country as a resident of the non EU country. It's like data FATCA. And there are other loopy catch 22 ambiguities, like if you want to delete someone from your audit log, do you delete their personal info (which is fairly expansive definition under GDPR) from the audit log too? Then how can you show you deleted the person's info if they are also deleted from your audit log? Read this to see more from the small company side and how much of a mess it is: https://www.brentozar.com/archive/2017/12/gdpr-stopped-selling-stuff-europe/ https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli... Think of this theoretical situation. If your an EU citizen vacationing in a developing nation who has a medical emergency, could that hospital just decide to reject you because the hassle & cost of dealing with GDPR is too great? Remember, it's a developing nation, they can choose to just refuse service to you. Kind of like how a lot of americans get rejected by non US banks because dealing with FATCA is just too much of a pain ass today?
- bryanrasmussen 9y agoThere's a ux problem here, because Google needs to be able to determine if it can save the data and the company using google analytics might also have a requirement to notify the user they are saving other types of data. Too many notices, requests for confirmation will be a problem. So I expect the company should be able to instantiate analytics with a parameter saying that they asked for confirmation and what the response was. Aside from that I think there might end up being a performance benefit from the GDPR. The difficulty of keeping permissions to track across different adtech providers becomes onerous, and big media companies start throwing out a bunch of them.
- cromwellian 9y agoLet’s all have a moment of silence for John Perry Barlow’s Declaration of Cyberspace Independence back when it was envisioned the internet would be a place where any entities could communicate or associate free of government control or censorship. Loads of people in here who support the concept of net neutrality which helps enable permissionless innovation by not imposing huge costs on those who publish or allowing others to impose costs on them, now cheerlead for the right to impose extraterritorial regulation without representation. There was a time you could just set up a site on the net and not have to worry about much, apparently now you have to worry about the Union of all possible foreign laws in case anyone from outside geographic regions visits your site. It’s could be a race to the lowest common denominator of freedom, or conversely yield bulkanizarion of the internet as more Geo-IP blocks go up or more great firewalls. How many of you love “this video or music isn’t available for playback in your region”? That could be much more common in the future and contrary to commentary far more likely to hurt smaller and medium sized players than the real targets of the laws.
- iddqd 9y agoYou can still set up a site and not have to worry about much, as long as you're not processing other peoples personally identifiable information without their explicit consent.
- smhg 9y agoBut then you don't consider the IP address personally identifiable information? The GDPR does.
- iddqd 9y agoYou can serve web content without storing the IP address of the user. If you need to use it for anonymous correlation of requests, you can hash it first.
- smu 9y agoIn addition, you can store the IP address if you want to use it for infosec (such as, finding out who to block in case of a ddos attack). See https://gdpr-info.eu/recitals/no-49/ https://gdpr-info.eu/recitals/no-49/ The recital also mentions "accidental events that compromise availability, integrity, authenticity,..." That seems to cover debugging for me. No need to ask for consent. To do certain analytics like page count, you don't need the IP, so that seems ok for me. To track individual customers however, that's something else. PS: according to GDPR, a hashed IP will be "pseudonimisation", not anonymisation because you can have a key to go back to the original value. True anonymisation removes all info (the IP in this case)
- RutZap 9y agoSpeaking of GDPR, I, like many others, am a little bit confused. I've read parts of the legislation but not all of it, so perhaps somebody here can help me out. Moving towards slightly more delicate issues (compared to tracking someones browsing habits), in relation to the right to be forgotten, if I make a request to Equifax and Experian to remove all personal identifiable information they hold about me, will this actually be possible? Will my bank then contact me for consent to pass my data back over to them? Will I be able to open a new bank account in the future if Experian and Equifax delete my data? How would this whole legislation deal with something like this?
- kazagistar 9y ago(This response is quite late, but hopefully it helps at least a bit.) 1. All third parties that a site might pass information to must be listed. 2. The site is responsible for ensuring all the third parties it passes information to support a way to delete that information. So if you ask them to delete something, they have to forward that request to third parties, who then have to delete what was provided by that site. The site is liable, so they have to make sure they have contracts covering this with any third parties they would pass the information to. 3. The deleted information by the third party only has to be the information from that site, not every site. 4. There are a number of exceptions specifically involving things like baking, especially if you have a legal, signed contract that obviously cannot be erased with the click of a button. So specifically in the case of Equifax and Experian, its unclear. 5. I am not a lawyer, disregard everything I said lololol.