5 ms·
That's interesting as what it's website privacy policy actually says looks the exact opposite of GDPR compliant. From https://www.mozilla.org/privacy/websites/
by dekrg 8y ago
That's interesting as what it's website privacy policy actually says looks the exact opposite of GDPR compliant. From https://www.mozilla.org/privacy/websites/ https://www.mozilla.org/privacy/websites/ which is linked from as Privacy link from https://addons.mozilla.org https://addons.mozilla.org.
>We may use cookies, clear GIFs, third party web analytics, device information, and IP addresses for functionality and to better understand user interaction with our products, services, and communications. Learn More
>You can control individual cookie preferences, indicate your cookie preferences to others, and opt-out of web analytics and optimization tools. Learn More
- gcthomas 8y agoIf the data collected is not personally identifying data, then GDPR is not interested in it. Maybe it is PII, but the quoted policies don't say that. > We may also use cookies, device information and IP addresses, along with clear GIFs, cookies and third party services to help us understand in the aggregate how users engage with our products, …
- throwaway2016a 8y agoOne of the most common interpretation I've heard is that IP address is PII according to GDPR. Even if not combined with other PII. So based on this description they are doing PII.
- pmlnr 8y agoIf they _store_ IP. You will see an IP with every single connection to a service. If you don't store it - but say, you store a country level geolocation instead - it's not PII.
- deleted 8y ago[deleted]
- pjc50 8y agoFrom the text of the directive: "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them. An IP address is an "identifier". However, an IP address does not in and of itself identify a natural person; you know that, I know that, and even the GDPR knows that. However, if you start building a map of IP addresses to user real names, or some other form of profile construction, then the IP addresses become personal information. (comment hoisted from other thread)
- lmkg 8y agoGDPR introduces a new concept called "Personal Data" which includes things like IP addresses and opaque database keys. Something is personal data if it is tied to an individual, regardless of whether sufficient information to identify that individual is contained in the data itself. An IP Address (or, according to some interpretations, an IP Address + timestamp but not an IP Address on its own) is Personal Data but not PII. The GDPR does not address PII at all. To a first approximation, PII is now an American legal concept and Europe has a completely different (and strictly broader) definition of privacy-relevant data.
- kuschku 8y agoThey’re using Google Analytics, by default, in the browser UI and on their Websites, without opt-in or visible opt-out (it’s hidden in the tracking prevention settings of the browser itself, and chained to the DNT setting). That’s about as violating as it gets.
- gregknicholson 8y agoIf Google is collecting the data, not Mozilla, who's violating?
- paublyrne 8y agoAfter completing our mandatory and very boring GDPR training at work, I can tell you that it's Mozilla :)
- gregknicholson 8y agoOK. Can you tl;dr for me why that is? Is it because I've asked Mozilla to show me a web page, and the data collection happens as an automatic result of that?
- icebraining 8y agoYes, you asked Mozilla for the web page, and they decided to load Google Analytics. Mozilla is the Data Controller, and they asked a third-party (Google Analytics) to process the data of Mozilla's users (that includes simple visitors to the site), making Google a Data Processor. The Data Controllers generally have more obligations than Processors, since they control how the data is handled, and to whom it's passed.
- JohnTHaller 8y agoUsers are free to block third party cookies.
- kuschku 8y ago
- athenot 8y agoThis brings up a interesting point: cookies are not just for user/session identification. Yes that's how the majority of the apps work but instead, it's totally possible to use cookies to customize a site's experience, feature by feature. A cookie for the theme, a cookie for the font prefs, etc. Yet most sites still insist on logging the user in to customize the experience, and rely on some central storage to determime user preferences.
- inetknght 8y agoOnce upon a day, twenty years ago, site feature selection were exactly what cookies were used for.
- tbranyen 8y agoThis is a terrible use case for cookies. Any browser reset or change, new computer, your phone, etc, and you need to redo the whole experience every time. I'd rather login and customize once. Cookies get sent with most requests as headers so you're unnecessarily bogging down requests with data unrelated to the session.
- pixellab 8y ago100% exactly. Cookies are device and moment specific. Whereas a user account can easily save and transport the saved experience/setting anywhere the user wants to access them.