10 ms·
GDPR Feels Useless
- kzcqt 7y ago>This is so broad and vague that basically if I generate a random number to identify you on my website it becomes your personal data. That's cool. If something can identify me uniquely then it's personal data.
- kerng 7y agoTotally agree! Especially, if you keep the link between the number and user, which is very often the case. But even without that direct link one would have to demonstrate a certain level of k-anonymity. Maybe GDPR wasn't detailed enough to describe k-anonymity
- mrgreenfur 7y agoGDPR is a fundamental step towards controls of data as a basic human right. It does not define clicking on banners or cookie disclaimers. He's mad that the world hasn't already matured their adherence and that's reasonable but don't throw the baby out with the bathwater. GDPR is a great step towards empowering consumers. Give the industry and regulators more than 1 year to change it's behaviors and set new standards.
- guitarbill 7y agoDon't read this. There's so much misunderstanding in this article, I'd be surprised if any good discussion came from it. And refuting it would take ages. For example: > And apparently typing your name, age and other information is not consent. How is this supposed to work by the way? I give you my name but I don’t consent to you using it or remember it? The way it's phrased is misleading. If you need the data and are going to use it in the obvious way, e.g. for shipping a parcel to my address, legitimate interests works fine. If you're a scumbag marketer or data broker/reseller (etc), then yeah, it's going to impact you. That was the idea. So instead of bikeshedding arbitrary scenarios, let's do something more productive with our day.
- ziddoap 7y agoCouldn't agree with you more. Just another Medium post, presented as factual news, steadily leading me to just... Never read posts from Medium.
- pas 7y agoThe better response to "typing is consent" is that, okay, you gave our address, now we're creating adverts with your house, making it look like you're selling it, soliciting offers in your name, and so on. Even though you just ordered a bumper sticker from us. So, consent is given for a purpose, and you can't really do that with just an input box. Hence the fancy opt-in modal dialog wizard thingies, and the checkboxes at registration/payment time, and so on.
- jbob2000 7y agoIt's worth reading. It will remind you of the rule of law; that we all should follow the laws because it makes society better. You can speed your car down the road and there is no mechanism to prevent you from breaking the limit, but most people don't do this because they respect speeding laws and why they were created. Same thing here. Yes GDPR has no mechanism to enforce these things. It's up to everyone to respect the law and enforce it upon themselves. If you don't respect laws, then you don't respect 'em, simple as that. Eventually, you will get caught.
- slowmovintarget 7y agoYou can't refute a "feeling" anyway as it is subjective. I saw the headline and thought I'd verify my suspicion here in the comments (Confirmation Bias!) before spending my time on the article.
- Mirioron 7y agoI don't view GDPR to be quite as useless as the author does, but the point about the user having to protect their data themselves is spot on. GDPR only protects you against good actors that are under EU jurisdiction. Everyone else could very well be doing whatever they want with the data you leak. The EU can't fine a Chinese company if the Chinese company has no presence in the EU. Another thing the author doesn't mention is that GDPR sets a minimum amount of cost/effort to run a website that's way beyond the actual hardware cost and the cost of making the website itself. It requires every website operator to be familiar with how GDPR works, because you need to know whether you're collecting personal data (you probably are) and how you need to handle it. Furthermore, if you are collecting personal data then you must respond to emails of users who request to know what data you know about them within a set amount of time. In the case of a small website, such as a forum or blog, I would consider the cost imposed by GDPR to be greater than the cost of making the website itself and renting hardware to run it. I think it disproportionately impacts smaller sites. It essentially leads to small sites simply breaking the law and hoping that nobody complains about them.
- marcinzm 7y agoThat's the general issue with regulation, it protects the existing large players in a space by adding a higher barrier to entry for competitors. So now instead of hosting your own forum or website you'll use Squarespace or Discord or Disqus instead.
- youeseh 7y agoAll I see is a lot of websites with a cookie notice that I agree to.
- pas 7y agomaybe ... just a thought .. but, don't agree to them? it should be just as easy to agree as to decline. if not, then they are likely not adhering to the regulation, and eventually someone will/could alert them or whatever authority.
- youeseh 7y agoDo you mean that if I declined I should still be able to see the content?
- pas 7y agoYes. And the whole practice of huge scary obtrusive modal-like dialogs (that tint the background so you can't even read it normally) are the cheap tricks used by sites to incentivize you to consent to tracking. So, it's almost certain that those are not compliant. They replace the fundamental function and purpose of the site with a fake choice.
- ziddoap 7y agoCorrect, to a certain degree. Specific things that require data and/or cookies to function (e.g. providing a shipping address so that your package can arrive) are exempted, obviously. But everything else is supposed to work, regardless of consent or not. This is due to Art. 7, Paragraph 4[0,1] regarding "Freely given consent". If your only option is to consent, or not use the website, your consent is not freely given. [0]"When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract." [1]https://gdpr-info.eu/art-7-gdpr/ https://gdpr-info.eu/art-7-gdpr/
- legitster 7y agoHere's an issue we ran into when implementing GDPR: marketing software keeps a database of people who have opted out, so even if that email address shows up again, we don't risk spamming them. But if they opt out now, under GDPR we have to delete them completely, even from the opt-out list. So we can't remember not to email or track you. The author also points out the double set of cookies, which is how most sites deal with tracking. One set of cookies that do not collect PII, that just tell the other set of cookies to turn on or off. I respect that the writers of GDPR did not confer with the industry insiders beforehand. However, with how poorly some of it understands the technology (implementation of cookies is a great example), I wish they would have had a bit more understanding and drafted a better bill.
- turbohz 7y agoUh? Couldn't a hash be used for that?
- legitster 7y agoAccording to our council, even encrypted or hashed data was still counted as PII as those are security measures, not privacy measures.
- ziddoap 7y agoI mean, trust your council over some random guy on the internet (me), but I would seek a second opinion on this from a technilogically savvy lawyer. There are absolutely implementations available that will allow you to have a hash, not tied to other data, sitting in your opt-out list that you than check other hashes against. No PII in the mix.
- MattPalmer1086 7y agoIf I got the hash database I could absolutely test whether specific people were in it, and I could probably reverse a large number of them with dictionary based attacks. There are no completely robust options where you can claim that this data cannot compromise personal privacy, so I guess from a legal perspective it doesn't stop it being PII.
- Orangeair 7y agoThis is just a weird article. > But do you know what data I have access to when you come on my website ? Well only your IP and some information about your computer and browser. That’s all. It's pretty well known by now that that's often more than enough to identify a specific user. "That's all" really undersells it. > It’s true I can create an ID and save it on your browser (I can do much more but we will stay focus). Your browser, not your computer. That's effectively the same thing -- the vast vast majority of users don't use more than one browser per device, and I'd be willing to be that the few who do use more than one mostly use them for different websites. > So the very first thing you need to understand about data privacy is that YOU protect your own data by not giving it away without thinking. And here it is. This article is basically just victim blaming. "You didn't want this website to identify you based on the unique combination of user agent, viewport, and feature detection? Then you shouldn't have visited this website with that user agent, screen size, and set of features enabled in your browser."
- threatofrain 7y agoI’d ask similarly, when you enter the public sphere, does that give me the right to collect DNA samples you’ve “voluntarily” dropped on the floor, like in police shows? You abandon your privacy when you voluntarily expose yourself to the public, right? I think the public is divided on the issue and have no consensus nor common language for matters of privacy.
- ydnaclementine 7y agoA law is only as effective as it is enforced
- BryanGiese 7y agoInteresting perspective and I can see some of the intent here, but it takes an odd slant to the issue. There are a few failures in logic here (random number becoming PII, only tracking on one browser, laws protecting you from getting robbed) that detract from the goal of GDPR which is to outline the user's digital rights, not define how data can be collected. GDPR does not define the technological methods because those will always be evolving, much like our understanding and expectations of data privacy will evolve. I agree that users need to educate themselves on how to protect their own data, but there is a ton of technology that they either aren't aware is being used, or simply don't understand. GDPR isn't perfect but it will help in the long run. Here is a summary of some of the details and how it will impact what developers need do as they architect software. Some companies will take it seriously, others won't. Then consumers may decide who to do business with. https://fusionauth.io/blog/2019/01/29/white-paper-developers-guide-gdpr https://fusionauth.io/blog/2019/01/29/white-paper-developers...