4 ms·
In 1y every website will have a click through EULA with 20 pages that loads before everything else and doesn't store IPS - and which no one is reading - privacy
by _Codemonkeyism 8y ago
In 1y every website will have a click through EULA with 20 pages that loads before everything else and doesn't store IPS - and which no one is reading - privacy served. Just when they install from the App store or install Microsoft Office.
- akie 8y ago"Click here to agree to everything we do" schemes are explicitly forbidden by the GDPR. You need to individually opt-in to every single use case, and you need to consent to every transfer to each individual third party as well.
- _Codemonkeyism 8y agoIANAL No, coupling is forbidden. A 20 page, non-legalese EULA is allowed if you don't couple acceptance to using your site. "You need to individually opt-in to every single use case" No. But I would be happy for your source on that. You can't change the usage purpose after collecting, but if you declare what you do before (20 pages EULA) data collection, you're fine. "and you need to consent to every transfer to each individual third party as well." Yes, foggy data privacy declaration from the past are no longer allowed, but 20 pages EULA, 10 pages with company listings you transfer data to are. I'd also add a teaser on top with the most important things, like here https://juro.com/#privacy-popup https://juro.com/#privacy-popup If Paypal can do it, so can you.
- vntok 8y agohttp://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... > Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided. > Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. In accordance with Council Directive 93/13/EEC (1) a declaration of consent preformulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment. > In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.
- icebraining 8y agoI would be happy for your source on that. It's in the "Guidelines for Consent" document, in "3.1.3 Granularity": "A service may involve multiple processing operations for more than one purpose. In such cases, the data subjects should be free to choose which purpose they accept, rather than having to consent to a bundle of processing purposes." And they give an example: "Within the same consent request a retailer asks its customers for consent to use their data to send them marketing by email and also to share their details with other companies within their group. This consent is not granular as there is no separate consents for these two separate purposes, therefore the consent will not be valid." http://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=51030 http://ec.europa.eu/newsroom/article29/document.cfm?action=d...
- _Codemonkeyism 8y agoThanks!
- _Codemonkeyism 8y agoLooks like we're both right, if you base your legality on consent, each case needs to be presented on their own. If you do not base it on consent, which many lawyers in Germany say you should only as a last resort, you can have a large declaration. Just as I've predicted, the Washington Post implemented a click-through EULA.
- pluma 8y agoIANAL You do need explicit consent if you're trying to sneak something in the user wouldn't expect. So if you sign up for cat pictures but the service sells off your data to a dating service, that's surprising and requires explicit consent because the user can't be expected to give informed consent to that by just skimming your privacy policy.
- IshKebab 8y agoAnd yet, that seems to be the solution most sites are already taking. "Click here to agree to tracking and continue to our site." Concrete example: theverge.com Hopefully they will be slapped down for it pretty soon.
- _Codemonkeyism 8y agoThe way "theverge.com" does is clearly not compliant, because they track/store IP/... before I give consent. I also can surf without consent.
- krageon 8y agoThis is the EU, not the US. This law was specifically crafted to prevent the kind of reptilian behavior that you're describing here. I honestly (and perhaps naively) expect you to understand the source material a little bit better if you're going to make blanket statements about it here.
- _Codemonkeyism 8y agoAlways a good idea to include a personal attack in your comment, well done! Second, my point is not about what I'm doing but about what others will do. I have not and will not work for companies who base their business model on selling data without consent, ad networks or in duping people. I've declined several very lucrative CTO offers in large companies due to their privacy stand. Third, I'm for more data protection and privacy and removed my Facebook and other social media accounts years ago. I would also not click such EULAs as I do not care about "news" sites.
- krageon 8y agoNowhere do I imply that you are exhibiting reptilian behaviour, I said that you are describing it. What you could take personally is that I said you should not talk about things which you do not understand (unless it is to ask questions, which I could have added), which doesn't sound at all unreasonable to me. Why you assume that was a personal attack is completely outside of how I can read my own comment.