5 ms·
Private Data is necessery for Ads. Ads are necessery for Revenue. Revenue is necessery to provide Service. Whats the problem ?
by wtfstatists 9y ago
Private Data is necessery for Ads. Ads are necessery for Revenue. Revenue is necessery to provide Service.
Whats the problem ?
- yellow_postit 9y agoExactly this. A veneer of personalization can make it so that you must consent to get the service. Realistically not every use can be put down a priori because that would preclude allAB testing of new features. I’m expecting a much larger “cookie pop up” but getting an option to reset data will be nice (until I need to use the service again)
- PeterisP 9y agoNote that you must get consent for each separate use. If users give you consent to use that data for service personalization, then that must be separate from using the same data for ad personalization and from consent for sharing that data with third parties - even if the first use case is objectively needed by your users, the other uses must be opt-in and can be refused. "Realistically not every use can be put down a priori because that would preclude allAB testing of new features." means just that - it does preclude you from AB testing of new uses of that data as you might have done before. It's illegal now unless you get user consent beforehand. It doesn't prevent AB testing as such, but it does prevent "hidden" AB testing that doesn't inform users and doesn't give them an option to refuse.
- x0x0 9y agoAnd crucially, under the consent basis, you have to explicitly enumerate the 3rd parties by name. You can no longer use a defined, every precisely defined, class of 3rd parties. The other available basis, legitimate interests, would be extremely hard to use as a basis for 3rd party target data sharing.
- TeMPOraL 9y agoNo. Not one step of this chain is necessary. - Private Data is useful for Ads, but not the only way to run them. - Ads are useful way of generating Revenue, but not the only way to get it. - Revenue is useful to provide a Service, but not necessary, as evidenced by almost every startup out there ;). Ok, I'm joking with the third a bit, but for the first two points - sure, data->ads->revenue might have been the easiest way to make money on the Internet, but it's not the only way, and the point of GDPR is for companies to explore other, less user-hostile options.
- PeterisP 9y agoThe problem is that, effective in a few months, this argument is not considered sufficient. You don't get get automatic permission to use private data just because you "need" that for revenue. People have an unconditional right to their private data, your business does not have an unconditional right to revenue or success. You get only the data that users consent to. If that's not sufficient for your ads, revenue and service, then tough luck, adapt or cease operations; if your business model is not compatible with user privacy then that business model simply is not valid anymore.
- wtfstatists 9y agoYou are debating different thing. The debate is, can a business deny service, or offer degraded service instead, if no consent is given. Nothing I have read suggest otherwise. http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679 http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A3... 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
- PeterisP 9y agoThis is exactly what it means - it doesn't explicitly prohibit a business to deny service; however in this case the regulator is likely to rule that the consent they received from those users who did click "agree" was not freely given, and the business is using their data in violation of this directive. I.e. instead of "can a business deny service, or offer degraded service instead, if no consent is given" think about the concept "if a business is known to deny service or offer degraded service instead if no consent is given, is that consent freely given or not?", and how will your business demonstrate to the regulator the legal basis that gives that you have the right to use that data - since now by default you're not allowed to have and use it. The evaluation criteria is not "did they click a box with required parameters" but rather "does your whole consent-gathering process ensure that you're not counting consent that users did not want to give" - if your consent-gathering process is flawed and systematically results in people who didn't want to consent being listed as "True" in your consent-database, then it means that you don't have consent from anyone. This is an clear, large financial risk, since if a business does it this way I'm likely to intentionally go to their website, click 'Agree', enter my data, on the same day file the standard request to the business requesting information of the data they have on me and the legal grounds for using that, and if all they've got to say is "well, you clicked the agree button where the other choice was to refuse service" then I'll immediately file a complaint with the regulator that they're using my data without freely given consent (as the service was conditional on that consent) and deserve a fine for this violation. And the fines are substantial.