16 ms·
Somewhat ironically a consent wall is exactly what TechCrunch presents to an EU visitor the first time, and there's no opting out; only way to get past the cons
by eMSF 6y ago
Somewhat ironically a consent wall is exactly what TechCrunch presents to an EU visitor the first time, and there's no opting out; only way to get past the consent dialog is to consent.
I know this especially well because I automatically clear all browsing data each time I close my browser, and techcrunch.com is one of the domains I avoid on HN because of the more annoying "welcome" on any page. (edit: +n)
- petargyurov 6y agoSame here. Isn't this against GDPR regulations? I thought that sites must give you the option to not provide consent and still visit the site.
- jagged-chisel 6y agoCan a website be compelled to provide its content? I can see the POV where "We cannot serve you unless you agree to certain rules."
- Johnjonjoan 6y agoThey maintain the right to refuse service but my uneducated opinion is that it could be penned as discrimination given the circumstances
- neltnerb 6y agoSurely they can require an account for all users. Of course then no one would register because who has time for that.
- petargyurov 6y agoI may be mistaken, but I think it falls under some sort of discrimination ruling? I.e.: you can't discriminate against those users who don't want to give consent.
- rootusrootus 6y agoThat seems like a weird choice. I mean, it makes sense to ban discrimination based on traits that people have no control of (e.g. all the protected classes in the US), but a refusal of consent is a behavior choice, not an unavoidable trait. I wonder where things are heading.
- TwoHeadedBeast 6y agoData protection laws would be meaningless if you made consent a condition of visiting the site.
- rootusrootus 6y agoBut we've built a world where a large fraction of the population has [apparently] willingly traded their privacy for free product. I completely support making this trade transparent, so people can make an explicit choice, but what's the justification in making it one-sided and requiring companies to provide their service for free?
- ratww 6y agoBut is there any company that survives solely by collecting and trafficking personal data? Facebook and Google don't count, they make money selling ads. If there is such a company I'm completely ok with them not being viable anymore.
- guitarbill 6y agoi guess we'll find out if they really are willing, given a proper choice, and not just forced to click "accept" like in some perverse skinner box. i don't know where all the misinformation comes from, but companies don't need to provide their services for free. they can still show ads - just untargeted ones. or is ads = tracking nowadays?
- vertex-four 6y ago
- elondaits 6y agoYou can charge money, you can have special rules outside of the scope of the GDPR... what you cannot do is make people’s personal data the price for content. Under the GDPR personal data is non negotiable.
- jagged-chisel 6y agoThanks, this makes sense. Edit: I'm surprised that elondaits's explanation isn't at the top of my thread. It makes clear that "exchanging your data as payment for 'free' services" is the target of GDPR and seems to me that's the only sensible explanation. Is someone willing to refute their explanation?
- cortesoft 6y agoYeah, I guess it could be thought of like laws against prostitution... you can give your data away for free, but you can't give it in return for something.
- jagged-chisel 6y agoSure, GDPR lets you give your data away in return for something. But, according to elondaits, that can't be the only price for something.
- cortesoft 6y agoThat seems like a tricky rule.. what if I said “you can access this with either your data or $1000”
- jagged-chisel 6y agoWhat makes that "tricky"? If it costs somewhere near $1,000 to provide the service, why not offer that price as the alternative?
- cortesoft 6y ago
- himinlomax 6y agoThe question is not whether one is compelled to provide their content, the question is what is required for the content to be provided. It probably wouldn't surprise you that it is unlawful to require visitors to sacrifice a kitten to access a site, would it?
- cglace 6y agoLet's say I have a club, you have to do certain things to gain membership to my club if you don't do those things you can't get in. How is that any different? The club should be able to set the rules as it deems fit.
- ratww 6y agoThe club still has to follow the law. You can't have a "murder club" and you can't have a "I don't follow the GDPR club".
- cglace 6y agoMy point was about meeting requirements to gain access. Not about following the law. However, would it be against the law to have a club that is only open to ex-cons? I understand that the GDPR makes it illegal to make it necessary to consent to give up your data before gaining entry. I was just questioning that portion of the law. It would be a pointless conversation to question points of a law and have someone respond back "but that is the law".
- rsynnott 6y ago> However, would it be against the law to have a club that is only open to ex-cons? Actually, in some countries, outside narrow restricted cases like support groups, yes; criminal record is a protected class in some cases. However, being an ex-con isn't illegal. Having a club where you required members to consent to a crime being committed against them, which is more analogous here, wouldn't be legal.
- tinus_hn 6y agoThe idea is that if this is how it is presented, you can tell them you agree and they still have no permission.
- PeterBarrett 6y agoYes, it's also against the rules to auto select all of the trackers as accepted but many sites still do this. By default everything should be deselected and you need to accept all of them to allow tracking. I've found that sites are slowly changing over to this method but it will probably take a big court case for the likes of TechCrunch to change.
- SilasX 6y agoI thought they could have them all selected as long as there was some "de-select all" button? Edit: Never mind, I guess that would violate Article 7's "It shall be as easy to withdraw as to give consent."
- TotempaaltJ 6y ago> Edit: Never mind, I guess that would violate Article 7's "It shall be as easy to withdraw as to give consent." Wait--that exists? Then Oath _definitely_ is violating GDPR. Continuing without consent is basically impossible on their websites!
- dessant 6y agoYes, restricting access when users do not consent to data collection is generally illegal. There are exceptions, like in the case of fraud detection, but restricting access to this article is not justified. Companies like Verizon can get away with this abuse because we're all too lazy to report them in an instant. Verizon has offices in the United Kingdom, Ireland, Belgium and the Czech Republic, but you can also use the online form of your country to report them in the EU. File a complaint against Verizon and TechCrunch here: UK: https://ico.org.uk/make-a-complaint/your-personal-information-concerns/ https://ico.org.uk/make-a-complaint/your-personal-informatio... Ireland: https://www.dataprotection.ie/en/individuals/raising-concern-commission https://www.dataprotection.ie/en/individuals/raising-concern...
- deleted 6y ago[deleted]
- kevindong 6y agoDo EU laws apply when the target user base of a website is non-EU customers? e.g. if Verizon Wireless only operates in the US, do they have to comply with EU laws despite them not attempting to localize content for EU users (aka they get shown what US users get shown)?
- fennecfoxen 6y agoThe law only applies within the EU. However, EU GDPR legislation permits the EU to do whatever it can go after noncompliant sites in any jurisdiction. The legislation also requires all new trade agreements between the EU and other countries to be GDPR-compliant. The legislation permits them to go after "noncompliant" sites for 4% of worldwide revenue. So it's quite brutally extraterritorial by design. The interpretation of the regulation does not require large fines for small infractions by non-EU-focused sites, and indeed the regulators presently work to be eminently reasonable about such things, but the lines are fuzzy and the interpretation could change without further legislation — and even if you could defend yourself against such a case, it may be ruinous anyway.
- ProblemFactory 6y ago
- Shivetya 6y agoI doubt that is the intent, content can be behind paywalls so I see cookie acceptance as a form of paywall. if they are claiming otherwise you get stuck with only paid content. So can they do previews only without running afoul of the law and they specifying cookies for full access?
- PeterisP 6y agoConsent can't be a form of paywall under GDPR. GDPR defines that valid consent must be freely given, and explicitly mentions that if providing service is conditional on providing consent then that is not freely given consent. Consent that's not freely given is not valid legal basis for processing personal data according to GDPR. If users clicked "I agree" under these circumstances, then that "agreement" click is worthless, it does not grant any extra permission that the website owner did not already have. In essence, GDPR makes that consent to processing private data is not for sale, it's not something you can legally trade away in a contract for some money or benefit. It's valid to have informative click-through walls - to gather assertions that the user has been informed that you're going to do stuff with their data because you have a legal basis to do it even if they don't opt-in; but a click-through wall fundamentally can not be a mechanism of obtaining valid consent to some processing where consent is needed. GDPR consent must be opt-in, fully informed, and freely given - something that some of your users intentionally choose because they want to. If you expect all users to "consent" to some processing then that's impossible - you would rather have to argue that the "legitimate need" or some other part of GDPR allows you to process that data without consent. You can have all users acknowledge something, but you can't have all users consent to something, that's not how opt-in consent works.
- Mirioron 6y agoSure, but large portions of the internet do it this way. They'd just stop serving EU users if it comes down to it.
- derefr 6y agoWhat if the law said that the company has to serve EU users the same way it serves non-EU users, and to do otherwise would be considered an act of trade war by a private US corporation against the EU (the same as if e.g. a US private defense contractor, hired by some other power, hacked into EU corporations and caused property damage against them)—basically making the whole thing into a “diplomatic incident” each time it happened? Heck, what if they said that everyone doing things their way is their condition on staying in WIPO, and if a country can’t bring its corporations into line, then the EU will declare all WIPO IP-right assertions originating from that country null and void within the EU, free for any EU corporation to exploit?
- Maskawanian 6y agoI don't think anyone should be forced to service foreign nations. As a citizen of a non EU country, I'd take issue with being compelled to work with them. EU would effectively be declaring war on a significant percentage of the world. They have no jurisdiction beyond their borders. Taking your ball and going home, while not the best for business, should be an option.
- derefr 6y agoI mean, you're not forced to service foreign nations. But if you are trading with foreign nations, then you've got to realize that that is fundamentally a voluntary relationship—trade doesn't exist by default, it is created by a spirit of mutual cooperation, on a foundation of compromise. If that spirit of cooperation and foundation of compromise don't exist, then the trade cannot exist. Or, to put that another way: WIPO itself is something the US "forced" on the rest of the world. But it wasn't actually force; it was just a condition on other nations continuing to trade with the US.
- umvi 6y ago> I thought that sites must give you the option to not provide consent and still visit the site. What the heck? That seems a bit overbearing. It's my server. Don't agree to my rules? GTFO. Why should you have the right to ignore my rules and still use my server? That's like having your cake and eating it too. "Thanks, I don't consent to your monetization scheme but I'll go ahead and use your bandwidth for free."
- PeterisP 6y agoThe right to not be tracked if you don't want to is (now) a fundamental legal right that overrides any rules you can implement. It's not that they don't consent to your monetization scheme, is that a monetization scheme that involves tracking people who don't really want to be tracked is illegal as such, you can't have one. You can deny access to whoever you want, but the key point is that if you "threatened" them to deny service if they don't accept, then that does not really indicate that they wanted you to use their data, does it? You can't say "oh but I gave them some goodies to influence them to click 'Accept'" - nope, if they don't really want to be tracked, then you aren't allowed to do so, the consent is not something that people can trade away in a contract for some content, server time, money, lentil soup or whatever.
- umvi 6y agoOk, then EU shall not have a free option on any of my services. Pay or GTFO. Harms the poor, IMO, but at least the poor's privacy will be protected from ad companies.
- PeterisP 6y agoEveryone's privacy will be protected - the same consent restrictions will also apply to your paid customers. Free webservices are not the majority of the world's businesses, a big part of why GDPR was needed is because all the paid online and offline services also traded all their subscriber private data; and with GDPR you can't just have a line in your paid service terms&conditions that allows you to screw their privacy.
- grenoire 6y agoWhen it comes to TechCrunch's website, there are many more reasons to avoid it besides their cookie wall.
- clarry 6y agoIt's bad enough that I consider the site outright malicious and just flag these submissions.
- fuzzy2 6y agoOh, but you can opt out. You first need to click the other button. Then again. Then you get the list of hundreds of “partners”, for each of which you have to manually figure out how to opt out. And then, in the end, you undo all your hard work opting out of hundreds of services by having to press the accept button anyway. :-D /edit: Heh, yea. It’s not just “hundreds”. It is _way more than 1000_ “partners”. Insane.
- mcv 6y agoAt some point I just stopped reading sites that make it too hard to opt out. Though I would really like to have a browser that automatically opens links to such sites in incognito mode, accepts the popup for me, and makes sure everything is thoroughly deleted afterward.
- dangerlibrary 6y agofirefox focus does ... some of this?
- StavrosK 6y agoI would like an extension that replaces the page with "It's not worth it" so I know not to even try to opt out and just leave.
- SkySkimmer 6y agoIf you block the domain in umatrix it basically does that. For instance techcrunch redirects me to some "guce.advertising.com" url and umatrix blocks it https://imgur.com/bxGAbiH https://imgur.com/bxGAbiH
- StavrosK 6y agoI'll look into doing that with uBlock/Privacy Badger, thanks!
- mszcz 6y agoOh, that's too much work. I've been using Cookie AutoDelete for Firefox and I've set it to clear all non-whitelisted cookies a couple of hours after last visit. This way I have to click once if I visit a couple of times a day.
- metreo 6y agoClearly the matter isn't simply presenting the ad. The issue is being able to trace and identify the user. Sites will put walls that identify blockers which when passed through by declining will still display ads! Showing the ad isn't nearly as important as tracking who is looking at them.
- beshrkayali 6y agoBecause douchebags like TC and whatever service they're using will come up with ways to annoy the fuck out of you so that people will go back to blind consent. One additional point should've been added to GDPR: malicious techniques to acquire consent will result in triple the amount of fines.
- hardlianotion 6y agoI agree that TC make a mockery of the principle of user consent.
- notRobot 6y agoYou should consider using uBlock Origin. It'll block all trackers regardless of what you click.
- deleted 6y ago[deleted]
- st1ck 6y agoTypically, disabling JS (e.g. with NoScript) prevents most of the annoying dialogs like this. Also it helps with some paywalls. Of course, it adds a bunch of other annoyances with websites which won't work properly without JS (that is, most of them).
- kevin_thibedeau 6y agoPage still renders content with all JS blocked. All of the other crap is gone.
- Zenbit_UX 6y agoInspect element + delete div
- wimagguc 6y agoTechCrunch works without javascript, which is quite nice from them though. Compare it some others, where the content is literally loaded after consent, using js.