7 ms·
Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR a
by mziel 9y ago
Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry:
* Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service
* Opt-in/out separately for every activity (no more "research purposes")
* Data deletion and takeout. Maybe in the future EU will also introduce some standards for the takeout, which will allow us to migrate between services much easier (as we now can switch between banks or telcos in a semi-automatic way)
- nrjames 9y agoWhat we are seeing is that the ad providers are considering themselves "controllers" under the GDPR and the tracking of device ad identifiers as critical to their business. Hence, their plan is to inform of the collection via a privacy policy but not to offer users the opportunity to affirmatively consent to allowing their advertising ID to be tracked. It's dispiriting.
- throwaway2048 9y agotheir interpretation isnt nessiarily going to hold up.
- zaarn 9y agoI'm pretty sure that this kind of behavior will be shot down by EU or Local courts. The GDPR contains parts where it explains what kind of reasons might lead to overriding of legitimate or critical interests.
- emidln 9y agoIf this is the case, I imagine a lot of profitable sites will be geo-banning EU users who don't subscribe to a payment plan as a non-profitable drain on resources.
- rmc 9y agoSounds like a good business model. Look at what US tech companies don't want to abide by EU law. Copy their app, but without all the privacy issues, make it free for all, incl EU. You already know what to copy, you don't need to do any research. Development and business risk is much less.
- emidln 9y ago> business risk is much less Minus the part where you're giving away your product for free with legally mandated nothing in return.
- zaarn 9y agoThat's a possibility. The GDPR does forbid hinging service quality/availability on consent but I don't think it forbids putting it behind a paywall as alternative.
- Silhouette 9y agoThe GDPR does forbid hinging service quality/availability on consent Although this is one of the areas where it seems some sort of challenge is inevitable. Requiring businesses to give people more control over data about them is one thing. Requiring businesses to do things that make no business sense, like providing services to people despite getting nothing in return, is something else entirely.
- zaarn 9y agoIt doesn't forbid you to provide free service, to my understanding, you can charge for the service but you can't provide a worse free experience when a user opts out. Additionally, this does not affect data that is necessary to operate the service. When you run a GPS tracker app then it is entirely okay to ask for the right to process someone's position as part of that contract (as long as you don't share it with a third party).
- 9y ago
- lbarrow 9y agoCan you elaborate on what you mean by "doesn't end up like the cookie law"? I'm an American and don't have much awareness of this other than I've noticed that sites in the EU like the Guardian tend to have annoying banners saying they use cookies at the bottom of their splash screens.
- mziel 9y agoYou can read more about the cookie law here: https://www.cookielaw.org/the-cookie-law/ https://www.cookielaw.org/the-cookie-law/ Basically EU wanted sites to obtain consent to use users' cookies (and for the users to give/take away that consent). However, pretty much all the sites just decided to provide you with a banner saying something like "if you're using this site you agree to our cookie policy". Therefore the law became ineffective and just a nuisance to the users. This notion of "implied consent" is being actively fought with GDPR. You have to provide explicit consent to the usage of your data. And more importantly you can revoke it (at any point) and the site can't deny or degrade the service (unless the data is strictly necessary for a specific action related to the service). With ePrivacy this will go one step further. Right now you only need to provide opt-out, which means most people will likely leave it as it. Going forward those additional services (marketing purposes, ad tracking) will need to be strictly opt-in (and there's already internal research done in some companies showing that marketing/ad opt-in rates will be 10-12% at best).
- iagovar 9y agoBut op-int for what? For being tracked? Using you data? Just showing you an ad?
- mziel 9y agoYou're supposed to enumerate all uses of the data (and they need to be sufficiently detailed and specific). The user has a choice to opt-in/out of each of them separately. There is currently no detailed description as to what the definition of "sufficiently" is. For example: - can I use your data to build a targeting machine learning model? - can I use it to target you? - do I need specific opt-in for every model? Most things in GDPR are not specified in order to both give flexibility to the sites and to reduce the number of loopholes (which are technically legal but against the spirit of the law). You need to decide on the implementation and be ready to defend it in case of an audit.
- tzs 9y agoNote: the following questions are not because I'm trying to figure out how to work around GDPR. They are to help figure out just what the meaning of it is. Imagining hypotheticals that try to work around a law is a common method in legal circles for clarifying the law. My employer does not keep any data that would be problematic, and compliance looks like it will be pretty easy for us [1]. > Explicit consent for non-essential data use, [...] This raises a bunch of questions. Anyone know the answer to any of these? 1. Suppose that the data is used to pay for keeping the site afloat? Does that make it essential? > [...] you always need to provide opt-out without degrading the service 2. Suppose my site is presented as a site that has basic and premium content. The premium content is behind a subscription paywall. On the paywall, it offers to waive the subscription fee if you consent to non-essential data use. If you either do not consent, or, after consenting later change your mind and opt-out, is it "degrading the service" if I no longer let you have access to the material behind the paywall? 3. In #2, does it matter if that's how my site works for people that I can identify as being the EU, but works different for people elsewhere (e.g., for people in the US it collects data on everyone and does not offer the option to pay)? 4. Suppose I just say "the hell with this...I don't want to deal with GDPR", and have my site ask first time visitors if they are in the EU or EU citizens. If they say that are not, I set a cookie that records this, and they get my normal site, which only follows whatever data collection rules my country imposes. If they say they are, I just send them to a page that says EU people are not allowed to use my site. What's the situation if someone inside the EU lies and tells me that they are not in the EU? Am I in violation of GDPR for keeping forbidden data on them, or does their lying to me count as consent? [1] In fact, most of the data we keep on EU customers is data that we don't even want to keep, but the EU is requiring us to keep it for VAT MOSS reporting. Before VAT MOSS, all our EU sales went through a UK entity, and we paid UK VAT on all of them, which required much less information for reporting.
- deleted 9y ago[deleted]
- tscs37 9y ago>1. Suppose that the data is used to pay for keeping the site afloat? Does that make it essential? If you use the data for bank transactions or paypal subscriptions it's essential. If you sell the data for profit, it might be essential but it falls under "opt-in only" of the GDPR. So in this part; not essential in the above sense. >2. Suppose my site is presented as a site that has basic and premium content. The premium content is behind a subscription paywall. Subscription paywall is fine. What isn't fine is degrading the service if the user opts out of having trackers included in the website when they visit. >3. In #2, does it matter if that's how my site works for people that I can identify as being the EU, but works different for people elsewhere (e.g., for people in the US it collects data on everyone and does not offer the option to pay)? GDPR only applies when you target people currently in the EU (citizen or not) and EU citizens outside the EU. >4. Suppose I just say "the hell with this...I don't want to deal with GDPR", and have my site ask first time visitors if they are in the EU or EU citizens. If they say no, I would say that is okay to believe considering the GDPR also requires a "Are you 16" question. Ask a lawyer.
- dalbasal 9y agoExplicit consent is the principle I'm most curious (and pessimistic) about. It's one of those things that are very easy to describe in everyday terms, but almost impossible for legal enforcement to work with. There are rules about things banks have to inform you of, or pharmaceuticals. On the academic side, this can be effective. Disclosure and making information public. On the consumer side it is almost always disingenuous. Small print meticulously written by compliance officers and reviewed by regulators. No one seems capable of stepping back and asking "are consumers better informed." When internet service X wants you to know your card is about to expire, they make sure that you are informed. When a regulator wants you to be informed about cookies.... we get small print, and a nag screen making us promise that we read it.
- Ra1d3n 9y agoIts pretty easy: The law says, that you always have to set a willing action to opt in. There can be check-boxes, but they need to be unchecked by default ("privacy by default"). Simple. I have already received multiple communications from Banks and credit card companies, and they are all very explicit about it and it was very easy to see the choices and the effect of the law.
- dalbasal 9y agoI guess I can't go forward without reiterating the argument, so I guess I'll stop. But, I think considering it easy is naive, considering the mountain of experience to the contrary. Some things are hard to solve with laws.
- klez 9y agoAt least in Italy, this has been the way it works for years. When I sign something privacy-related I get at least two boxes: one for the treatment of my information for functional purpose (that is, "we can't even take this paper back if you don't give us permission"), the other for research and marketing purposes (that is stuff not essential to the performance of the service). It's working quite well, in my case at least.
- 9y ago