5 ms·
This is an interesting case. So France is essentially arguing that not only should opt-in be visible (as they mention it is on Google's create account page), bu
by CorvusCrypto 8y ago
This is an interesting case. So France is essentially arguing that not only should opt-in be visible (as they mention it is on Google's create account page), but that configuration should be immediately visible as well.
This will screw over much more than google should it be upheld.
It's interesting that this wasn't brought up to my employer in sweden. We had default data collection settings checked and in a separate view accessible by a similar "more options" toggle and it was deemed okay as long as we had a visible blanket opt-in checkbox and a link explaining the settings, how we use data, and how to adjust. Our regulators said it would be enough as the goal of GDPR is to make every use of data reasonably known, adjustable, and revokation with good faith toward the user. Yet here it seems France is arguing that it is about immediate showing of all settings to the user and that every website should tell in the user's face about every single configuration of data usage. It's possibly a good approach, idk, I feel it is a bit too annoying of a precedent and that they are nitpicking a bit.
I can't wait for this to fully play out. Regarding documentation and informing the user, I disagree with their findings entirely about the frustration of finding data usage info as all of Frances concerns were lost on me upon visiting https://safety.google/privacy/data/ https://safety.google/privacy/data/. To me it seems that google has made a good faith effort at least in documentation.
- the_duke 8y agoI agree that this would put basically any service in existence into non-compliance. As a user, I do agree that a "blanket opt in" button/ default checked checkbox is so pointless that it could as well be left out. A EASILY DIGESTIBLE page explaining what data is stored and how it is used , with an agree button at the end (and separate opt-in for different sets of data/functionality) should be mandatory. Emphasis on the easily digestible, because we all know that the "terms and contions" pages out there are constructed to be as obtuse and uninformative as possible to make users just skip them.
- zAy0LfpBZLC8mAC 8y ago> I agree that this would screw over basically all services in existence. So, the market is so skewed that that is how presumably somewhat informed people perceive it? I mean, I would think it is just obvious bullshit. There are plenty of businesses that sell you a service for money, and that is all they do, and this kind of regulation has exactly zero impact on them. The only problem is that they have to compete with others who simply mistreat their customers in order to be able to ask for less money--so it's about time that a level playing field is restored where it's obvious that anti-asshole regulation does not impact everyone.
- the_duke 8y agoI was just referring to the way information is currently presented on most websites. I did not mean businesses would become unviable, just that everyone needs to change the way they present GDPR relevant information.
- zAy0LfpBZLC8mAC 8y agoBut that is exactly the bullshit that I was referring to! No, if you haven't mistreated your customers before, there is no need to change anything, and there are plenty of businesses that haven't. There was never any necessity to spy on your customers, and thus there obviously is also no necessity to get consent for the spying that you are not doing in the first place.
- the_duke 8y agoI have no idea what you are talking about. This has nothing to do with spying or misreading customers. As a customer, I want to know what data a service stores and how it is used, without digging through pages of cryptic terms and services. Informed consent is the keyword here. Plenty of paid services share their data with third parties.
- zAy0LfpBZLC8mAC 8y ago> As a customer, I want to know what data a service stores and how it is used, without digging through pages of cryptic terms and services. As a customer, I simply want my data to not be stored at all, unless I explicitly asked for it, in which case the consent is obviously implied. > Plenty of paid services share their data with third parties. And plenty of paid services don't. And those don't have to change anything. That's my point.
- tzs 8y agoConsider a site that sells digital goods for download. They need to store information that provides evidence of your physical location, such as IP address [1], in order to satisfy tax authorities that they collected the right jurisdiction's VAT or sales tax. I doubt that you are going to explicitly ask sites to store your IP address, so how do you think that should be handled? [1] IP address alone doesn't prove location, but it is evidence. The EU, for example, for requires for internet sales that you justify your choice of whose VAT to collect by providing two non-contradictory pieces of evidence for the location you chose. IP address can be one of those pieces. Billing address of the card used for the purchase can be another, and for most people that and IP address is enough.
- tomjen3 8y agoHonestly at most 10% of the sites that I have seen allow you to opt-out with a single click, whereas basically all of them allow you to out-in. Some don't allow you to browse the site without accepting. We need some general browser based auto script, so that websites don't get to ask, something like a do not track header, but one that was legally binding. Until then I click accept on all the sites that I use on my phone, they can set all the cookies they want, as I use Firefox Sync, which erase all data whenever you press back or close the browser.
- MayeulC 8y agoI use a firefor add-on[1], which works for the Quantcast banners (adds a "I refuse" button), but would definitely like something that works equally well for all websites, or that websites fix it themselves. Maybe even better, if they could simply follow the DNT flag, or not track their users in the first place. I worry that accepting cookies once, for one of these sites, will lead them to try and de-anonymize you, maybe even across private browsing windows, or different sessions. If you give them the right to basically fingerprint you, be assured that they will abuse it. [1] https://addons.mozilla.org/en-US/firefox/addon/qookiefix https://addons.mozilla.org/en-US/firefox/addon/qookiefix
- alkonaut 8y agoIt should be a very simple requirement that whatever the way is to “agree to collection and enter site” must not be simpler or more prominent than the action required to NOT agree to non essential collection and still enter. That is, no more “agree and continue” that isn’t accompanied by an equally prominent “continue without tracking”.
- Despegar 8y agoInformed consent is the bane of any business that relies on dark patterns.
- 794CD01 8y agoAnd any business whose users are too stupid to be meaningfully informed. AKA just about everyone.
- Sir_Cmpwn 8y agoThe point is to make you stop collecting the data at all, not to make you wriggle and worm your way into continuing to spy on users.
- fmajid 8y agoThe CNIL has explicitly stated it is going after dark patterns, and blanket opt-in is one. The only real question was over standing, I.e. whether the Irish DPA has jurisdiction or not. As for the amount of the fine, even if it is small in comparison with Google’s profits, it has to come from one employee’s budget. That one person will be strongly motivated to fix this.
- number6 8y agoThe case has to be seen in the light of the complaint: https://noyb.eu/wp-content/uploads/2018/05/complaint-android.pdf https://noyb.eu/wp-content/uploads/2018/05/complaint-android... CNIL agreed with the Complainant