9 ms·
Study: Google is the biggest beneficiary of the GDPR
- VMG 8y agoBut who could have known?
- davidhyde 8y agoThe author of this article didn't bother to read even a summary of the GDPR law. It doesn't matter what the user consents to, you cannot use their personal data ad hoc. You need to justify its collection, storage and transfer to the regulator, not the user. This is in contrast to the ill thought out cookie law where websites could get away with it by irritating consent banners. Sort of like, but not exactly the same as, those consent forms you sign when you go river rafting. They do not legally protect the rafting company from negligence. In fact, they're almost a waste of paper.
- sarabande 8y agoI bet rafting consent forms are still useful in the sense that they discourage most people with trivial-to-moderate injuries from thinking about holding the company liable.
- ghaff 8y agoAs someone who leads outdoor trips, I've been told (not sure how true) that one of the supposed benefits is that it informs about dangers. So someone who suffers an injury--not through negligence on the part of the trip leader--would have a tougher case arguing that no one told them that the activity was other than completely safe and they wouldn't have done it had they known. On the other hand, I've also been told by lawyers that the usual scrawl your signature at the bottom of a paper after a quick glance probably doesn't make much of a difference.
- justtopost 8y agoSame as 'Stay Back 500ft, Not responsible for damage' signs on the back of gravel trucks. Youd better bet they are 100% liable for anything that flies out. But it discourages the unmotivated and the uneducated from seeking their entitled legal relief.
- paganel 8y ago> It doesn't matter what the user consents to, you cannot use their personal data ad hoc. You need to justify its collection, storage and transfer to the regulator, not the user. I think one of the points is that there are very few companies that have the financial resources to do that, one of those companies that can afford it being Google. The next retort is "but then those companies should stop using trackers all-together" which leaves most of those companies that don't have Google's financial resources without ad money, meaning they're most likely to go out of business, practically creating an oligopoly where a handful of companies control most of what's published on the Internet. Granted, we would have gotten there regardless, only that legislation like GDPR is accelerating this process.
- rypskar 8y ago>but then those companies should stop using trackers all-together Yes, why do they have to track their users? Why don't use real targeted advertisement instead? If I go to a car forum, car related ads would be relevant for me. Using ML, tracking and profiling to give me ads for the fridge I did buy last week is not relevant
- Klathmon 8y ago>Using ML, tracking and profiling to give me ads for the fridge I did buy last week is not relevant Come on, that's not what they are trying to do and you know it. There's so many valid arguments you could make, why use a strawman? But the answer to your first question, is because ads targeted to users pay more, get more clicks, and overall perform better than those that are targeted to the page.
- dlor 8y agopatio11 had a great back of the envelope calculation awhile ago on this. Turns out showing ads for a fridge right after you just bought one might be highly successful. Say the average person buys a fridge once every 10-20 years, the probability you're looking for a fridge this month is something like 1/120-1/240, call it .75 percent. Some percentage of fridge purchases end up being returned. Let's say 2 percent of them. If you return a fridge, you pretty much are guaranteed to need a new one, so around 2 percent of people that just purchased a fridge are very likely to buy a new one. That's over double the likelihood of someone that didn't just buy a fridge!
- nwellnhof 8y ago> It doesn't matter what the user consents to That's not entirely true. If a user really consents to being tracked for advertising purposes, the GDPR allows tracking. Whether the consent banners inform users honestly about the extent of tracking is another question. I think they don't. What's worse is that Google still tracks users by default, even if they never visited an actual Google property, let alone have a Google account. That's an obvious violation of the GDPR but Google will probably try to shift the blame on publishers.
- mtgx 8y agoI think the biggest issue with GDPR so far is enforcement. It's still early days, but many companies don't even follow GDPR as they're supposed to, including Google and Facebook. That will only be settled after an enforcement wave against both large and average-sized companies (GDPR is more lenient towards small companies).
- brennebeck 8y agoSomewhat tangential: have you seen GitLab’s notice? And what’s your opinion of that style, as far as informing/consent?
- nwellnhof 8y agoGitLab seems to use the Cookiebot solution. I like that "Marketing" cookies are disabled by default, although they should be labeled as "Advertising". Also, even if you bother to read the purposes of all the 80 advertising cookies, the descriptions are incomplete and dishonest. For example: Doubleclick cookie notice: "Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user." Facebook cookie notice: "Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers." These descriptions fail to mention that the collected data will be combined with information from thousands of other websites you visit which allows to create sophisticated user profiles. From these profiles, you can infer things like gender, age, socio-economic status, interests, or hobbies with relatively high accuracy. Even if you asked them, Google and Facebook couldn't tell which hidden categories their machine learning models can discover.
- kristianc 8y agoThis was always going to be the case. Google benefits from having a direct relationship with the customer, meaning that consent is relatively trivial to get. None of these third party tracker companies have that relationship, so rely on securing opt ins on a piecemeal basis. This is why a large number of the third party tracker companies all shut up shop in Europe in the months before GDPR.
- Drakim 8y agoIf I go to a random website and they serve third party google ads, I don't have a direct relationship with Google in that scenario. It's not enough to say that because I have a gmail account I consent to being tracked all over the web on every website.
- kristianc 8y agoYou don’t have a GMail account, though, as there’s no such thing as a GMail account. You have a Google account, and GMail is bundled in as a service. FWIW - ‘tracked all over the world on every website’ also comes with some significant caveats.
- Drakim 8y agoNothing about what you are saying here is related to my point though. If I use one product of google, it does not mean they have a "business relationship" that entitles them to tracking me as a third party on random websites. And even if it somehow did, I could merely opt to not be part of that, and neither the website nor google can deny me service for opting out. That's one of the main aspects of GDPR, you can't make a service conditional on clicking "I agree" and signing away all your rights.
- kristianc 8y agoIf you’re using a signed in Google Account or a signed in Chrome Browser, Google will argue that the tracking is compatible with the services that you have agreed to as it helps provide a more personalized experience.
- blub 8y agoFrom what I've heard from people with Google and FB accounts, both basically ignored the law and presented their users with take it or leave it pop-ups on their online properties. That's why they're getting sued...
- mattlondon 8y agoAre they getting sued? I'm not aware of any GDPR-related cases against Facebook or Google so far?
- icebraining 8y agohttps://www.irishtimes.com/business/technology/max-schrems-files-first-cases-under-gdpr-against-facebook-and-google-1.3508177 https://www.irishtimes.com/business/technology/max-schrems-f...
- lucian1900 8y agoNot terribly surprising. The purpose of GDPR wasn't to hurt large companies, but to protect citizens.
- maltalex 8y agoMarket share is only part of the picture. What happened to the size of the market in the EU after GDPR?
- ericdykstra 8y agoIs there any evidence of GDPR having the desired effect for which it was put in place? Is citizens' data being protected more than before? The second-order effects that everyone predicted are already happening (big tech companies change nothing significant, many small companies shutting down). The long-term and unforseen second-order effects have yet to bear fruit, as far as I know (please let me know if you've seen anything).
- louhike 8y agoIt's just my personal anecdote, but I'm happy to be able to choose which cookies can be used. And when I see the changes the companies I worked with and the comany in which I work had to make, I think it's a good thing. People are more cautious with how they use the data of users now.
- Brotkrumen 8y agoYes, the amount of tracking cookies is declining. https://www.techradar.com/news/gdpr-sees-cookies-crumble-on-eu-news-sites https://www.techradar.com/news/gdpr-sees-cookies-crumble-on-... The shutting down of companies is a desired effect, because those are the companies that won't get consent. Data resellers for example that dont provide any advantage tto the user. We haven't even seen the actual effects yet because google Facebook et al are probably in violation and are waiting to be sued to fight it out in courts
- yardstick 8y agoOne nasty side effect is some large organisations are shutting out Europe. I can no longer access severs popular US based sites and instead get messages about the content not being available in your region. (Most recently: latimes.con and fox8.com)
- Cthulhu_ 8y agoThat's also fine - was their content worth your privacy? If they can't be GDPR compliant we don't want them.
- stanislavb 8y agoAnyone surprised? It was clear since the beginning that that’s going to happen...
- suddenstutter 8y agoThis is the reason the GDPR was implemented in the first place. Its just really sad if people still belive to this day that large organisations of any sort care about the little people.
- vbsteven 8y agoIf I read that graph correctly the number of trackers per page has gone UP 20% since April in some categories for US visitors.
- akerro 8y agoBut it went down in the EU, so I guess they need to make more money on tracking and profiling somewhere else now.
- TekMol 8y agoPlus it knocked a lot of potential competitors off the internet. I know multiple young startups and entrepreneurs in Europe that killed their projects/ideas because the additional burden of coping with GDPR was too much for them.
- robin_reala 8y agoReally? Because I haven’t heard of any, and I live and work here. Any sources?
- TekMol 8y agoThey are young single founders in the idea or mvc stage. So nobody that is mentioned by any sources.
- robin_reala 8y agoI’m a little surprised then, because the only problem I see for basic GDPR compliance for a single founder is if their business model is based on monetising their users’ data. Which is going to be a problem, regardless of the size of the organisation.
- Dayshine 8y agoIt took me 2 hours to get my family member's small web business GDPR compliant...
- pmiller2 8y agoAre you sure it’s really compliant? Are you willing to risk the possibility of huge fines if you’re wrong?
- mocae 8y agoLike who? Seriously. Besides that one blogger who was screaming because he didn't even want to bother with the help wordpress provided, I did not hear of a single person/company that quit because of that. It would also be quite embarrassing considering the time you had to prepare, the help that is all over now or the fact that nobody seems to enforce it. Especially for businesses.
- anoncake 8y agoSaying Google is the biggest beneficiary is grossly misleading. Their reach increased by a whopping 0.9% while everyone else's declined. Even if reach is the only relevant metric, that's hardly worth talking about. The actual biggest beneficiaries are the citizens whose data is protected.
- oytis 8y agoÜber-fucking-raschung. Regulation is beneficial to big companies.
- mattlondon 8y agoIs Google the biggest "beneficiary" here, or is it more that a lot of shady operations were totally shafting people on their data/privacy and so they've finally had to close down or expose themselves to massive legal risks? The significant drop in trackers on EU sites reported here (and not a huge surge in Google trackers on EU sites) suggests to me that it is other adtech/tracker companies that have lost, rather than google gaining. Either way, it is good to see some hard figures on tracking being rolled-back a bit. Now we just need some enforcement to fix the badly-implemented consent-walls (e.g. slate.com).
- buboard 8y agoit is google because they have the largest pot of data which allows them to very granularly target you with confidence. Whatever data the shady small business had, it was probably partial, old and outdated.
- wastedhours 8y agoYou're not looking for a surge from Google though - they're already the 1000lb gorilla, what you're looking for is the limitation in competition, which is what's occurring. As with a lot of EU digital regulations, they're essentially centralising power to organisations who have the legal resources to either go through the process (and find loopholes), or the cash to fight it. A lack of competition in the tracking space won't really mean the practice will disappear, but that the organisation who has the biggest consent database will take all the money by default. I might be biased as a marketer, but I'd prefer to have multiple small companies who're tracking limited pieces of info about me across different parts of my web experience (and who may fuck up occasionally), than one huge company knowing 100% of my information. (Edit: as a side note, the linked article is doing something shitty with the scrolling on the site, which is more annoying than semi-targeted advertising to me...)
- blub 8y agoThe multiple small companies tracking limited pieces of info about you would anyway be happy to sell and share that for money, this is partly how those huge DMP databases are built.
- pmontra 8y agoOfftopic: am I the only one to see the optical illusion of the 0% line bendin upwards to the left in the "change in the number of trackers per page, by category, EU vs US"? [1] [1] deep link: https://static.cliqz.com/wp-content/uploads/2018/10/trackers-per-page-by-category-eu-vs-us-uai-1032x575.png https://static.cliqz.com/wp-content/uploads/2018/10/trackers...
- pantulis 8y agoNo, you're not.
- rectang 8y agoThe biggest beneficiaries of the GDPR are individual citizens. But that doesn't even enter into the tech industry zeitgeist, where commentators are enthralled by the bloodsport between corporate champions and the lives lived by actual humans are incidental and inconsequential.
- raziel414 8y agoI'm not surprised. I used to work on a team at Google that had to deal with GDPR (I still work at Google, but on a different team), and we had to get legal review for a lot use-cases. For example, we had a backup system that took snapshots of our user-provided data. If a user requested their data be purged, should we purge all the backups as well? Since we had legal counsel in house, it wasn't too terrible. For a smaller company that doesn't have those resources though, GDPR compliance must have been a huge burden.
- Angostura 8y agoYou know what? It's only a huge burden for organisations that process a lot of personal data in a variety of interesting ways.
- pmiller2 8y agoI disagree. The sheer magnitude of fines that can be imposed makes the potential damage huge, even if the probability of being hit by them is small. This makes the risk of noncompliance high.
- Matticus_Rex 8y agoAs someone leading the privacy program at an organization that doesn't have that much personal data (relative to most businesses in our industry at least, and probably overall) and doesn't process it in particularly "interesting ways," I strongly disagree. The GDPR was and is a huge burden. You can believe that it's worth it without engaging in the fantasy that it's not burdensome, but don't deny the reality of the burden.
- Angostura 8y agoAs someone who was involved in the GDPR work for an organisation that holds some fairly critical information about people and needs to share it with other organisations both as Data Controller and Data Processor, it really wasn’t too bad, mainly because we had already thought quite carefully about privacy and data security. As a committee member on a local swimming club, it took about 2 hours.
- Angostura 8y agoFrom the final paragraph of the article > In the end, users should never only rely on laws and regulations such as the GDPR to protect their privacy. Instead, they should be aware of who they are providing which data to. Ignoring the fact that GDPR is primarily a regulation ensuring that they know who they are providing which data to, and ensuring they have a choice about providing it.
- tpush 8y agoYeah, I wouldn't trust this source on anything privacy related. They present themselves as user privacy champions but primarily make money via, you guessed it, advertisements. They are owned by Burda, a large German media organization who, again, make money by advertisement and processing of their user's data. "We’re breaking new grounds when it comes to developing our business model. Bringing together targeting and privacy, we are currently testing a technology which allows companies and brands to show you relevant offers directly in the browser."[0] [0] https://cliqz.com/en/about https://cliqz.com/en/about
- rbinv 8y agoThis is also the company that acquired Ghostery.
- hddherman 8y agoAnd also the company that caused quite a stir when they partnered with Firefox to carry out a study, which included collecting and sending browser data to Cliqz servers.
- edwhitesell 8y agoThat explains why the latest Ghostery update on Android was so terrible. It lost all of my tabs and had 3 different places to disable some form of tracking.
- bjoern_cliqz 8y agoHey, Björn from Cliqz here. Great to see the post has generated some interesting discussions on matters of privacy, compliance, and as you point out - business models. Cliqz never has collected any personal data on its users, and never will. Over the course of the last 4 years, we started building a private search engine, to only realize that if we are to truly offer a usable alternative to navigate the web privately - we had to do much more. So we quickly found ourselves building an anti-tracking technology, anti-phishing, and anonymous rate limiting using Direct Anonymous Attestation. This research has been published / presented in the WWW Conference, Crypto and Privacy Village at DEF CON and CCC's Privacy Week. We have packed all these technologies in desktop and mobile browsers. This is what we do and it's what got Mozilla interested in Cliqz, and why they are an investor, just like Burda Media. All the technologies we have built share 2 attributes: 1. None collect personal data 2. Rely on client-side logic (computers are powerful enough these days to be used for more than display interfaces) Offers is part of how we monetize (we're exploring paid products too). Like any other technology at Cliqz, they share the same 2 attributes (No personal data, all triggering logic resides in the client). The code is open sourced here [1]. You can read a high-level description here [2]. We believe our approach is a healthy alternative to monetizing products on the web. At all times we allow the user to control what features from Cliqz they want to use; including offers. We understand there are plenty of reasons to be frustrated with the state of the web (we are too) - but blatantly rejecting any business model that brings privacy-preserving products to the market is not healthy. [1]: https://github.com/cliqz-oss/browser-core/tree/master/modules/offers-v2 https://github.com/cliqz-oss/browser-core/tree/master/module... [2]: https://cliqz.com/en/cliqz-angebote https://cliqz.com/en/cliqz-angebote
- jansan 8y agoWhat I am still missing from Google is a clear instruction that explains how to adjust the Analytics settings to be 100% compliant with GDPR. The fact that this is missing made me decide to drop Google Analytics in the foreseeable future.
- yuhong 8y agoThere was another HN thread with BrendanEich in it talking about this: https://news.ycombinator.com/item?id=18119367 https://news.ycombinator.com/item?id=18119367
- virgilp 8y ago> Although the number of trackers is decreasing overall, a few large tracking operators such as Google receive even more user data. This won't be a popular opinion here, but... it's actually good news/ what you observe is GDPR protecting user privacy. You think that Google is bad? Then, you probablly haven't seen the smaller players. With e.g. Mouseflow, you can literally watch users enter their personal email in your "register account" field, then change their mind and use a disposable account. Or glean other kind of sensitive details (passwords too, I think).
- sleepyhead 8y ago"WhoTracks.me is a joint initiative of Cliqz and Ghostery. It provides structured information on tracking technologies, market structure and data-sharing on the web and thus creates more transparency. On the WhoTracks.me website, interested parties will find visualized monthly tracker statistics. They are based on the evaluation of around 300 million-page loads and more than half a million websites." Considering IP-address is considered personal information it sounds like this study is based on data that was illegally collected according to GDPR.
- Vinnl 8y agoI assuming the data was collected through the Ghostery browser extensions, which requires explicit opt-in to share that data.
- arountheworld 8y agoI was looking at a couple of non technical friends browsing the Internet. Not one took time to read consent prompts, they just mindlessly click whatever takes the notice out of the way. GDPR is dangerous and doesn't fix anything.
- glenrivard 8y agoNot surprising. Regulations almost always have this affect. The bigger players win.
- PunchTornado 8y ago>The average number of trackers per page has dropped by almost 4% from April to July. The opposite is true in the US: there, the average number of trackers per page has increased by 8 percent over the same period. since when is this a bad thing? i want my page less bloated with 100 trackers...
- awkward 8y agoI'm surprised at the US number of trackers count - I would have expected some degree of free rider benefit for US based consumers. Otherwise, the numbers seem to bear out some consolidation, with web pages giving up trackers but more likely to hold onto boutique solutions (the ranked <150 group) for specialized needs.
- tveita 8y agoOh no, not the smaller advertising trackers. This is interesting data but I'm not sure it supports the title - It shows Google's market share in the EU going up a tiny bit, but total tracking goes down in the same period, while the baseline is probably runaway growth like the US. Google may be hurt the least, but I doubt they're a "beneficiary" in economic terms. It's a shame Project Wonderful just shut down - it felt like the kind of project that the GDPR should help. There must be a market for content-based, non-tracking ads that you can put up on any website without GDPR concerns. Google can and will fill that market, but since they can't lean on their global panopticon other ad providers can compete on fair terms. From Project Wonderful's shutdown notice: > Some advertising networks have held on by adopting more and more invasive user tracking, forcing their publishers to sign binding contracts, or by trying to train publishers (and readers!) to expect that "sometimes a bad ad will sneak through", but that's something we always refused to do. We believed - and still believe - that you deserve better. We believed - and still believe - in a world where an ad blocker wouldn't be an obvious thing to install, because advertising would be good, interesting, and non-invasive.
- obmelvin 8y ago> Google may be hurt the least, but I doubt they're a "beneficiary" in economic terms. So, relatively Google is the biggest beneficiary.
- deleted 8y ago[deleted]
- ucaetano 8y ago> Google may be hurt the least, but I doubt they're a "beneficiary" in economic terms. Quite the opposite, if you pass a 20% tax on every company, except for Google, who gets a 10% tax, it is a beneficiary. Everything is relative.
- kerng 8y agoYeah, beneficiaries are the end users and their privacy being worth something now. Which is something that wasn't the case before.
- oh_hello 8y agoOutside of the specifics of this article, I've wondered what effect GDPR has had on smaller companies and even individual developers. My company spent a lot of time and money to become compliant. Not only was this expensive, but we relied on lawyers to advise on where we could draw the line for compliance. If the company were a bit smaller I imagine it would be impossible to tackle this project.