4 ms·
- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR
by priansh 7y ago
- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR was supposed to regulate this and it is clearly failing to do so. And if you want to boycott it you're welcome to but they've built an empire with their cloud, search, email, etc to the point where that would be pretty difficult and annoying to the average consumer. They're effectively too big to be boycotted at this point.
- It doesn't explicitly force them to do that. And most sites aren't explicitly sharing the data either; i.e. almost every site uses Google analytics which doesn't really comply with do not track all too well, and Google will then share their data with everybody else (which is part of their violations in this article). Also saying "no" doesn't do much either as most of these big sites either already stored the cookie or won't do much to delete it. And it's not that they'll try to work around it, they either don't put forth the effort because GDPR is like a pebble for them, or they already worked around it in a way that changes nothing. Their business model is still the exact same.
I think the spirit of this law is fine, but the actual law does nothing and is just privacy theater. Google isn't buying time, almost 4 years later nothing has changed -- they just know they can't be touched.
- They're not going to sink, they'll just grow much slower and thus won't be an alternative to the big data abusers you hate so much. And they're not failing to handle your data, most of the time startups aren't selling you out they're just trying to figure out who their customer is internally. To do this they collect some data that is usually optional and very much with your consent; GDPR just puts a bunch of hoops in front of this so that it's an enormous pain to do so. I run a startup that collects basically no data (literally, we do not have a database for 2 of our products). It was a pain for us to become GDPR compliant because that disables our metrics entirely and requires a bunch of banners and checkboxes everywhere even though we literally store nothing.
I'm all for the spirit of the law. I just think the execution sucks and they definitely didn't think it through enough. I think the evidence for this is clear based on the sheer number of privacy violations we've had since GDPR was enacted alone, and how little enforcement and regulation has actually gone on.
- luckylion 7y ago> GDPR was supposed to regulate this and it is clearly failing to do so How do you know? The fact that there's still crime doesn't mean that law enforcement doesn't do anything. Somebody reports an alleged violation, an investigation is started, and maybe the investigation will produce that Google is in violation (in which case a fine will "regulate" Google's behavior) or they are not (in which case it may be fair to criticize GDPR for allowing that behavior, or it may not be because the info wasn't correct). > almost every site uses Google analytics which doesn't really comply with do not track all too well, and Google will then share their data with everybody else Unless you have specific info, I believe you're mistaken here. GA is generally seen to be compliant if anonymizeIp is active and you're not pushing PII into it via customization. Google is, if I understand it correctly, not "sharing" GA raw data with anyone, but analyzing the data for their own research and providing the website owners with aggregate data (i.e. demographic information) without sharing data on individuals. I'm not a fan of GA, but I haven't seen any info that they're that obviously in violation. > It was a pain for us to become GDPR compliant because that disables our metrics entirely and requires a bunch of banners and checkboxes everywhere even though we literally store nothing. What was the specific pain? I get that having to add a privacy info sucks (and might cost money if you get a customized version), but I never found it to be that big a deal. If you don't store any PII, it's pretty straight forward, and so will the procedures be if anybody asks about the data you stored: just inform them that your systems do not store any data in general and also didn't store any data on them in particular.
- icebraining 7y agoYour reality differs violently from mine. We're not four years into the GDPR becoming enforceable (it was just last year), and certainly not enough time to see real action for complex cases - regulators and courts move slowly. Startups barely ever asked for consent, and collect way more data than you imply - including, as you mention, by using Google Analytics. The GDPR requires zero banners and checkboxes if you are not processing data.