21 ms·
GDPR enforcer rules that IAB Europe’s consent popups are unlawful
- bajtos 5y agoGoogle, Amazon, and the entire tracking industry relies on IAB Europe’s consent system, which has now been found to be illegal following complaints coordinated by ICCL. EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses.
- gilrain 5y agoI wish my government looked out for me like this.
- optimalsolver 5y agoThen vote for it! Just kidding.
- jb1991 5y agoWhy kidding?
- wayoutthere 5y agoBecause voting doesn’t matter when your choices are corporate stooge A and corporate stooge B.
- gidorah 5y agoI always think of South Park. It's always a choice between a giant douche or a turd sandwich.
- wayoutthere 5y agoMore like if it was a choice between two, shitty giant douches and one was painted orange and the other was painted with a rainbow. They’re both the same thing with a different color paint.
- tux3 5y agoSay you live in a two-party first past the post system. If what you want to express is "I like privacy regulations", the single bit of information that your vote conveys does a very limited job of communicating what issues you actually care about. The signal in traditional voting is very diluted. You vote on a person that you think supports some of the things you care about. You are not allowed to weight in on individual issues in a way that matters. The person works for several years, and the only feedback you have on that process, the only tether that holds that person accountable, is whether you vote for them the second time.
- rjmunro 5y agoHow many EU countries run a "two-party first past the post system" nowadays? If you are in a first past the post system, and in a safe seat, vote for one of the no-chance-of-winning candidates who best represents your views. Although they won't win, the fact that they are getting votes will be noticed and the main 2 parties will respond by adopting some of their policies. E.g. in the UK as more people vote for the Green party, other parties will become more Green to get those votes back, even though the Green party has only ever got a single MP.
- Macha 5y agoEven in a decent PR multi-party system. Our green party for example is environment first, left wing economics second, public transit, pro-agriculture, anti-nuclear, somewhere down the list is internet privacy. Or maybe I could vote for the labour party, which are centre left economics, pro-EU, pro-housing expansion, pro-healthcare investment, pro-environment, somewhere down the list is internet privacy The idea that there's a party that (a) both has the same views on all issues as you do, (b) has sufficient votes to get seats and (c) orders issues in the same importance you do, for everyone, is clearly not valid. More parties = more choices, and this is often better, but ultimately we'd end up with de facto direct democracy to have a party with the exact views for every person. Similarly, even for myself, I consider internet privacy important. Maybe I should vote the for the pirate party then? Except I consider the environment more important and our pirate party is so small that it hasn't even considered a position on non-privacy related issues, never mind have an adequate plan for how we're going to make a transition from a heavily fossil fuel based power supply. Even on that environmental issue, I think the green party's anti-nuclear stance has historically been a mistake, but if the others are just going to build more gas plants, I'll deal with it.
- denton-scratch 5y agoBecause calling for a riot is likely sedition? (Depending on jurisdiction)
- gilrain 5y agoI do, as near as I can anyway. My government has been captured by the capital class and will be difficult to recover.
- marcus_holmes 5y agoThen riot for it! Maybe kidding? Seems the only way to get a single-issue topic on the agenda these days.
- Scarblac 5y agoThe scary thing is that it's the EU doing this. Our national elected governments are not interested in actually fixing things like this because it doesn't immediately win votes, and there is only a limited number of national civil servants so nobody is working on this kind of thing on a national scale. But put those civil servants in a committee in Brussels with not as much short term pressure, and they can work out regulations that achieve the right thing.
- ArnoVW 5y agoThere's a bit of that. But I think a big part of the reason is that national governments can not address international issues. The EU represents 300M people, and has the economic and political weight to make a dent. The same goes for other international issues, such as climate change, corporate tax evasion, cyber crime, etc.
- oblio 5y ago445 million people.
- arlort 5y agoThis is not really accurate. The enforcement of GDPR is still up to national civil services/judiciaries, in this case it was a cooperation of multiple national protection authorities. Even the legislation itself necessarily involved national governments and national civil servants in national ministries GDPR being an EU level legislation has more to do with the absolute nightmare it would be for the internal market to have 27 different standards and the drastically lower leverage available for enforcement than disinterest in the subject
- pseingatl 5y agoThere's this: • Austria: Datenschutz-Grundverordnung (DSGVO) • Belgium: algemene verordening gegevensbescherming / règlement général sur la protection des données (RGPD) • Bulgaria: Общ регламент относно защитата на данните • Croatia: Opća uredba o zaštiti podataka • Cyprus: Γενικός Κανονισμός για την Προστασία Δεδομένων • Czech Republic: obecné nařízení o ochraně osobních údajů • Denmark: generel forordning om databeskyttelse • Estonia: isikuandmete kaitse üldmäärus • Finland: yleinen tietosuoja-asetus • France: règlement général sur la protection des données (RGPD) • Germany: Datenschutz-Grundverordnung (DSGVO) • Greece: Γενικός Κανονισμός για την Προστασία Δεδομένων • Hungary: általános adatvédelmi rendelet • Ireland: An Rialachán Ginearálta maidir le Cosaint Sonraí / General Data Protection Regulation (GDPR) • Italy: regolamento generale sulla protezione dei dati (RGPD) • Latvia: Vispārīgā datu aizsardzības regula • Lithuania: Bendrasis duomenų apsaugos reglamentas (BDAR) • Luxembourg: règlement général sur la protection des données (RGPD) / Datenschutz-Grundverordnung (DSGVO) • Malta: Regolament Ġenerali dwar il-Protezzjoni tad-Data • The Netherlands: algemene verordening gegevensbescherming • Poland: ogólne rozporządzenie o ochronie danych • Portugal: Regulamento Geral sobre a Proteção de Dados (RGPD) • Romania: Regulamentul general privind protecția datelor • Slovakia: všeobecné nariadenie o ochrane údajov • Slovenia: Splošna uredba o varstvu podatkov • Spain: Reglamento general de protección de datos (RGPD) • Sweden: Dataskyddsförordning • The United Kingdom: General Data Protection Regulation (GDPR)
- deleted 5y ago[deleted]
- riddleronroof 5y agoOk but I don’t get how this consent system ran for years? How can one get pre approved? The issue here isn’t that they collected data (it’s own problems), but they they didn’t use the right language! Does this mean it will be a long term of conditions like apple does every time we use a website? ICCL might have made internet worse with this. Not better.
- foepys 5y agoTo this day Twitter is not even trying to comply with GDPR. They have a banner "we track you, deal with it" and that's it. So far nothing happened. I hope that they get fined billions for keeping it illegal for so long but I doubt it.
- Macha 5y agoThe DPAs are not in the business of pre-approving, much like your local court won't pre-approve your pre-nup and so you might have to fight over it in court in an acrimonious divorce. You can of course retain outside help to advise you but there's no guarantee that they are right and many of the consultancies and providers were incentivized to compete on maximum opt ins. Maybe the CMPs and the adtech companies can fight it out in court over whether the CMPs misled the adtech companies or they just gave the adtech companies options which the adtech companies misused. The ruling is not just "fix your language", though that's what the industry will be incentivized to try, again. They all bandwagoned on hiding secondary opt out checkboxes under "legitimate interest" and this wrist slap tells them it's not ok: > Fails to properly request consent, and relies on a lawful basis (legitimate interest) that is not permissible because of the severe risk posed by the online advertising tracking (Article 5(1)a, and Article 6 GDPR) > Fails to respect the requirement for “data protection by design” (Article 25 GDPR) The route to complying is clear. Don't track without opt in. Know where the user data is going, not just "whichever vendor happens to be in the winning ad". Don't use dark patterns to encourage the opt in. It's the industry's attempts to bury its head in the sand because it hurts their bottom line and their search for increasingly convoluted workarounds that is making this complicated.
- wongarsu 5y ago> Does this mean it will be a long term of conditions like apple does every time we use a website We call that a privacy agreement. But having a proper privacy agreement that lists what data is collected and what happens with it is far from the only part of the ruling
- donohoe 5y agoThis is amazing news. I implemented GDPR consent management for some US publishers with EU exposure. As part of this I evaluated vendors and various systems like the IAB framework. IMHO it was clear it was not compliant. It could never know the potential adtech it was going to load in advance (and therefore could not ask someone to consent), and it still allowed ads/adtech/trackers to load in page before asking for consent. They ignored anyone who pointed this out.
- secondcoming 5y agoBut don't the adtech vendors have to declare what they do with the data? (Purposes and Special Features)?
- Macha 5y agoIAB europe had a shared list of vendors and their purposes amongst the ad industry, and everyone's popups using the TCF framework just prompted with the same list because they _might_ be in the ads, not because they'd actually be on the page. Many of the vendors claimed every purpose, often as legitimate interest, regardless of what they actually planned to do and if they _did_ count as legitimate interest.
- secondcoming 5y agoThe list is here [0] if anyone is interested. [0] https://vendor-list.consensu.org/v2/vendor-list.json https://vendor-list.consensu.org/v2/vendor-list.json
- donohoe 5y agoAlso, in loading ads from these vendors, many often included external JS to whatever flavor-of-the-month adtech vendors or trackers they were using. These were often not even listed in the framework. There was little-to-no compliance/auditing that I am aware. It was business as usual for many ad networks.
- 5y ago
- elmerfud 5y agoIt was obvious to anyone technical they didn't work as they presented themselves to work, but it takes time for the courts to deal with such things. They are also totally annoying and I suspect there primary purpose was to annoy users and not actually comply with the GDPR. It was a way for these companies to fight the GDPR with a war of attrition. I'm glad you see with this round hasn't worked... Yet. I suspect that based on this ruling, things will not get better, as in providing a less annoying user experience and more compliance with the GDPR. Instead I predict another round of pseudo compliance and a more annoying user experience. Eventually they'll start a policy campaign in earnest stating that the GDPR is unworkable.
- donohoe 5y agoYou are right. I also believe many publishers knew this too but the IAB provides a shield of sorts and buys time when it is inevitably (as in now) ruled illegal. Most ad-tech, and programatic advertising, is not compatible with GDPR. I think that is intentional on part of the EU - and something I am a fan of personally. The industry needs to shift - contextual ads or other innovations - others have done this. They refused to self-regulate all these years and had opportunity to move away from their invasive practices.
- Tomte 5y agoIt's hard to start doing this when your competitors keep playing by the old rules. My hope is that ever more aggressive enforcement will finally lead us to the point where the dams break and everyone scrambles to get compliant at once. The sooner, the better. But I realize that the legal system needs to ramp up the pressure, they cannot start with company-destroying fines on day one. These rulings and fines keep me in good spirits, because I think we're actually getting there. Slowly, but still.
- donohoe 5y agoTrue, but the months ahead of GDR directive coming in was one of those potential moments. Google kept promising us their own framework and consent system. They kept pushing the date to unveil it and as we ran out of time I had to build my own, and many others jumped into the IAB framework because of so few options (and it came down to the wire there too despite knowing for years this was in the works). >> they cannot start with company-destroying fines on day one I think they can - and the GDPR fines are linked to revenue - and I think they have no choice. Companies need to take this seriously. >> Slowly, but still I'll take slowly over backwards.
- foxfluff 5y agoFinally! Some people keep arguing that GDPR is toothless and unenforced, but I think it's just that it takes time to tame the wild west. It's work in progress, and that progress is looking ok. I really hope also pass at least the part of DSA where they make terminal signals for opting out of tracking legally binding.
- m12k 5y agoYep, overall I'm really happy with the GDPR. The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. That way we could finally end this farce of the ad-industry's attempts at weaseling their way around the word of the law (and the latest rulings) by designing dark pattern consent boxes.
- foxfluff 5y agoIn general, I agree that it would be nice. Not sure what the right way to legislate that would be, but I'm sure there are ways. However, if DNT/GPC (which can signal opt out but not much else) becomes legally binding (as they very well might, with DSA), that'd be a huge win for me personally, because I don't see my self ever consenting, and reading consent dialogs isn't worth my time. As I understand it, GPC is already legally binding in California thanks to CCPA.
- Xelbair 5y agoNo need for that if they just complied with GDPR. Consent must be given consciously in informed way - therefore NOTHING can be pre-checked by any dialog to make it comply with GDPR. They just need to somehow ban dark patters, or standardize the dialog. To be honest, just one high profile case that interprets dark pattern as 'uninformed consent'(therefore not legal under GDPR) would be enough.
- bobajeff 5y ago>The main thing I'd like to see changed is that consent dialogs should be a built-in browser feature with a standardized interface that all websites were required to use instead of coming up with their own. I love that idea. Something like Apple's nutrition labels but with check boxes next to data uses. However this is only good if it's legally enforceable since there is no API that would prove/verify data is used the way it's been given permission to.
- phh 5y agoMy favorite part is: > All data collected through the TCF must now be deleted by the more than 1,000 companies that pay IAB Europe to use the TCF. This includes Google’s, Amazon’s and Microsoft’s online advertising businesses. It's not just that they need to find new ways to screw users. It's that since they screwed users, they also must lose their ill-gained data. Which will probably be a nice deterrent against them pulling the same shit again. Edit: loose -> lose
- shadowgovt 5y ago> Which will probably be a nice deterrent against them pulling the same shit again. Unfortunately, there are reasons they want these cookies on there so badly that justify the cost to figure out how to comply with the policy and try again.
- rendall 5y ago> that justify the cost to figure out how to comply with the policy and try again I wonder if this judgment opens them up to civil suits.
- ljm 5y agoI wonder if it's that or if it's also a case of marketing departments going wild with GTM and Segment and the like, literally throwing the kitchen sink in front of the user's experience in a desperate attempt to measure and drive 'engagement'. I mean, if you take a news website like The Independent, there's not a chance in hell that a competent design and engineering team would sign off on all the bullshit that is dumped on top of the page. It's always added on at runtime.
- Macha 5y agoAre they marketing departments not being driven the by the same industry wide focus on OKRs and measurement as the engineers? They just are even less likely to get a default assumption of being valuable.
- Nextgrid 5y ago
- iqanq 5y ago
- ford_o 5y agoI wish there was HTTP header that meant "I want to give you the minimum amount of data, to make your site work".
- ldoughty 5y agoBusiness pepe works just say the minimum is name, email address, etc. is the minimum in that case... And if you don't provide it, the site won't work
- aliswe 5y agothat can be challenged in court though.
- mhils 5y agohttps://globalprivacycontrol.org/ https://globalprivacycontrol.org/ goes kind of in that direction. It's a rebranded Do Not Track header, but referencing specific privacy rights under GDPR/CCPA. That hopefully makes it enforceable, whereas advertisers could just ignore Do Not Track.
- jeroenhd 5y agoI like the idea, but that protocol is too simple. For example, I don't have too much of a problem with Matomo tracking cookies, but I don't want Google Analytics to follow me around the web. This header doesn't specify any of that, and I'd still need to give some kind of consent through a cookie pop-up to websites that want me to use that stuff. I'd rather see a modern version of P3P (https://en.wikipedia.org/wiki/P3P https://en.wikipedia.org/wiki/P3P) with UI designed in this decade.
- mhils 5y ago
- sergiotapia 5y ago>EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. Laughable really. How the hell do you reconcile all this data and make the bean counters happy that yes: this is the data we collected through the popups over the years.
- shaky-carrousel 5y agoWell, that's their problem. They must delete the data or face legal consequences. That should act as a deterrent to future "too smart for their own good" ad people.
- sergiotapia 5y agoI agree! I'm just curious how would you do it? Look at when you deployed the popup to production and then delete all data from that timestamp forward? Engineering leaders now have ammo to push back against illegal roadmaps foisted on them.
- tokai 5y agoI guess that if you cant deliminate the unlawful data from the rest, you'll just have to delete all of it.
- deleted 5y ago[deleted]
- DocTomoe 5y agoIf they can not prove that data was not gained by illegal means, the only way would be to delete all data.
- dmitryminkovsky 5y agoThis comment is being downvoted but I’m also wondering: how will this be enforced? Will authorities go and audit the data? How will they know where to look? Etc. “Hey did you delete the data?” “Yes, we deleted it” would, indeed, be laughable. This is not to mention the problem of identifying “the data” which has certainly now been processed ad nauseum. I think the reason companies don’t take these things seriously is because they know they’ll get away with it, one way or another. You can’t expect to enforce any of this if you don’t also legislate the technical specifics of how data must be collected, stored and processed so that its provenance is maintained.
- nottorp 5y agoThose popups did teach one good thing: when you see "legitimate interest" you know you're about to get scammed.
- randac 5y agoI'd love to know how often a 'reject all' button actually objected to all 'legitimate interest' crap too. I expected the answer is site and consent management system dependent, so where I really couldn't avoid one of these sites, I'd manually object to all legitimate interest first before pressing it. Such a PITA and probably pointless ultimately, but hey..
- mpweiher 5y agoNever, as far as I could tell. That was the whole point of the "reject all" button: to trick you into implicitly "agreeing" to the "legitimate interest" section.
- NullPrefix 5y ago"reject all", then go to "legitimate interest" and click "object all". Or, you know, just disable JS.
- mpweiher 5y agoExcept "reject all" closes the popup. Gotcha! So you have to first got to "legitimate interest", uncheck all the individual "purposes", because usually there is no "object all". Once you've done that (with "object all" if you're lucky), you then have to go to individual vendors, because objecting to all the purposes does not cover all the vendors. Yeah. Again, if you're lucky there's an "object all", but usually there isn't. So gotta uncheck all those. There's lots. And often there isn't even a good scrollbar indicator to show how far you've gotten. If there is it's just depressing. Then you can hit "Reject All". And it's not entirely clear if "Reject All" doesn't turn the LIs back on, because, once again, that dismisses the dialog.
- 5y ago
- endisneigh 5y ago> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and Microsoft’s online advertising businesses. How much data is being collected through these pop-ups?
- samsari 5y agoAll the data they were collecting before that GDPR said they had to stop collecting (without freely given consent).
- endisneigh 5y agoHow much data is that? How do we know? It's not clear to me how the ICCL will know that "all data collected" is deleted. Even if the IAB is sanctioned or you storm their datacenters, the ICCL said that the tracking industry collected data through the IAB. How is the ICCL going to ensure that the tracking industry deletes the collected data?
- inetknght 5y agoIt doesn't really matter "how much" data. What matters is the type of data and whether or not it's strictly necessary to deliver the content.
- Jensson 5y agoThey will ask the companies to delete the data and take action if there is evidence they didn't, just like how all of GDPR is enforced.
- endisneigh 5y agoHow would they know if they did or didn't, though?
- Jensson 5y ago
- em-bee 5y agoearlier discussion here: https://news.ycombinator.com/item?id=29121848 https://news.ycombinator.com/item?id=29121848
- uniqueuid 5y agoThis ruling should not be a surprise. The writing has been on the wall for a long time that GDPR informed consent is to be interpreted in a narrow sense (i.e. actually being informed, not just clicking). And we know EU legal measures often take a long time but can bite hard. So here we are now! [Edit]: Note that the decision can be appealed - so it's going to be a long while before we get a final verdict.
- mhils 5y agoNonsurprisingly, the Interactive Advertising Bureau has a slightly different spin on the ruling [1]: "APD Ruling Clears Way For Work on Developing TCF into a Formal GDPR Code of Conduct". I'm surprised that ICCL very assertively states that all data collected through TCF must be deleted. The Belgian DPA only mentions a €250.000 fine and gives IAB two months to present an action plan [2]. Interesting to see how this plays out. :) [1] https://iabeurope.eu/all-news/apd-ruling-clears-way-for-work-on-developing-tcf-into-a-formal-gdpr-code-of-conduct-iab-europe-statement-on-the-apd-decision-announced-today/ https://iabeurope.eu/all-news/apd-ruling-clears-way-for-work... [2] https://www.dataprotectionauthority.be/citizen/iab-europe-held-responsible-for-a-mechanism-that-infringes-the-gdpr https://www.dataprotectionauthority.be/citizen/iab-europe-he...
- darrenf 5y agoThe PDF[0] linked to from the original article says this, in "Sanctions" C.533: 2) In application of Article 100, §1, 10° DPA, order IAB Europe to permanently delete all TC Strings and other personal data already processed in the TCF from all its IT systems, files and data carriers, and from the IT systems, files and data carriers of processors contracted by IAB Europe; Page 114. [0] https://www.gegevensbeschermingsautoriteit.be/publications/beslissing-ten-gronde-nr.-21-2022-english.pdf https://www.gegevensbeschermingsautoriteit.be/publications/b...
- mhils 5y agoThanks for the pointer! Do we have any idea why the Belgian DPA's press release would skip this part?
- globalise83 5y agoA new job opportunity has come up :) https://iabeurope.eu/blog/want-to-join-the-iab-europe-team-new-position-available-privacy-counsel/ https://iabeurope.eu/blog/want-to-join-the-iab-europe-team-n...
- MauranKilom 5y ago> The Belgian Data Protection Authority said IAB Europe “was aware of risks linked to non-compliance” and “was negligent”. It also found that IAB Europe had failed to honour its data protection obligations to maintain records of data processing (Article 30 GDPR), to conduct a data protection impact assessment (DPIA) (Article 35 GDPR), and to appoint a Data Protection Officer (Article 37 GDPR). Even if you were to give IAB the greatest possible benefit of the doubt, the fact that they didn't appoint a data protection officer makes it clear just how little they care(d).
- Tomte 5y agoEven with good salary, who in their right mind would possibly accept the DPO job at IAB? That's pretty much guaranteed legal trouble, because IAB will always try to point their finger at you. Unless you're fresh in the job market and still believe in the good of people, maybe.
- franciscop 5y agoArguably, in a company where the primary purpose is legal there'd be teams of legal experts (lawyers, attorneys, etc) that would be the ones deciding features and wording, not the devs themselves (assuming you mean, "who" as in "what developers", since we are in HN)
- pseingatl 5y agoNormally, you could outsource that function.
- parkingrift 5y agoCollecting and selling digital data is not a legitimate business enterprise. It’s spyware. If no one wants to pay for your product, the market has spoken. Too bad. We must correct the insanity and digital economic imbalance that spyware businesses have created.
- parasense 5y ago> Collecting and selling digital data is not a legitimate business enterprise. According to who, you? > It’s spyware. How is it spying when the people are freely giving away their data? > If no one wants to pay for your product, the market has spoken. Too bad. Very true, however it's not clear how a truism about something else relates to the topic? Was this supposed to be persuasive about collecting digital data? > We must correct the insanity and digital economic imbalance that spyware businesses have created. Fair enough, but that entails not creating or fostering an imbalance by constantly providing the internet with your personal information.
- the_mitsuhiko 5y agoHow does anyone have a choice in this?
- Rygian 5y ago> How is it spying when the people are freely giving away their data? The ruling has proved that no, people are not freely giving away their data. One of the infringing issues is that the system "Fails to properly request consent."
- Nextgrid 5y agoWhen consent is enforced by a system that can't be bypassed via dark patterns such as Apple's App Tracking Transparency, the actual opt-in rate is around 4%, suggesting that when given a proper choice users don't actually want to give away their data.
- 5y ago
- csomar 5y agoComing up next: Full page with mandatory reading (through eye scanning which will require camera access with popup consent for camera access). Followed by a 10 Quizzes to test your understanding for what you consented for. Then an email/ID verification to confirm your identity and consent. This is going to be fun.
- oezi 5y agoBut the good part is you can just decline to consent. Because under GDPR if they need consent at all (that is they really don't need the data), then you can decline.
- slig 5y agoCan the site deny your access then?
- saithir 5y agoMuch like the few US-based news sites that already decided to just not bother and show me the "you're coming from the EU and we can't be bothered to not collect your data" blank page instead. At which point I'm free to decide I wasn't interested in their content anyway.
- robin_reala 5y agoNot legally. Personal data isn’t transactional.
- YtvwlD 5y agoafaik no, but you might lose some features
- nybble41 5y agoNo. They consider that "coercion". So there really is no point in even asking, as the only correct answer is to decline. Anyone who accepts can be presumed to have been tricked into falsely thinking they would get something in exchange for granting permission.
- secondcoming 5y agoI don't understand the findings. The TCF system doesn't collect personal information. The spec is at [0]. CMPs are the popups responsible for creating the TCF string. The IAB provides a spec for how these should operate, but does not supply one of its own. These can absolutely misbehave, and the IAB has previously notified the adtech industry about known misbehaving CMPs. [0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework/blob/master/TCFv2/IAB%20Tech%20Lab%20-%20Consent%20string%20and%20vendor%20list%20formats%20v2.md https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...
- ricardobeat 5y agoMy understanding so far is that the TCF allows providers to accept 'legitimate interest' (instead of direct user consent) as a valid legal basis to store or process user data. This is commonly used for user tracking and advertisement / profiling, meaning you'll get tracked even if you clicked the 'Reject All' button.
- secondcoming 5y agoMy understanding is that Legitimate Interest is something defined by the GDPR lawmakers, not the IAB. If so, and now it appears that LI is not a valid legal basis, then every business operating in Europe needs to be concerned with this ruling, not just adtech. For example, HN probably collects my IP address under LI. Now it may be illegal for it to do that.
- ricardobeat 5y agoIt's defined in GDPR as something that 'can be reasonably expected for the business' and has 'little risk of infringing on privacy'. They specifically list fraud prevention, information security, dealing with employee data, as valid use cases. Marketing most definitely is not. This move is basically clarifying that you can't simply claim legitimate interest for most advertising purposes, which the TCF was encouraging/facilitating.
- chefandy 5y agoWe designers must reasonably but seriously convey the user-hostility of these patterns to higher-ups at every available opportunity. Sure, you'll get overruled by the dollar-focused Jr. Marketing Exec. On the other hand, the folks who say things like "Refuse! It's a designers job to say no!" probably have much bigger savings accounts than I and most others do... but not saying anything implies consent, and that's when behavior that's bad for your users and bad for the world become a silently absorbed into your corporate praxis.
- alkonaut 5y agoMost large companies have ethics hotlines you are expected to call when there is something questionable ethically or legally going on that might be difficult to bring up to a superior. Personally I'd refuse to add a dark pattern cookie dialog, but I'm in the privileged position of being able to switch jobs. But regardless, I'd probably send the ethics hotline an email saying that regulations are violated. Perhaps I'd send an email to the relevant regulator too, just in case.
- majewsky 5y agoUnfortunately the CEO does not report to the ethics hotline.
- chefandy 5y agoWeird— I haven't worked for a big software development organization in some time but I've never heard of that. That's a positive thing if the company has good corporate culture and uses the information well instead of just calling your boss and asking them to consider being more ethical because you complained.
- alkonaut 5y agoThese things are there so that investor's money are safe. In my case the ethics hotline is above the company, in the owning company (Berkshire). They don't want massive lawsuits, or tarnished brands because of things like VW dieselgate or things like that. And I think a lot of times even minor things can get pretty big consequences if it's actually illegal and not just "well it's a matter if interpretation".
- irrational 5y ago> EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. Plagued Europeans? Are they seeing additional consent pop ups beyond the ones all the rest of us are tortured with?
- Rygian 5y agoNo, we're probably seeing the same as you.
- inetknght 5y agoWithout knowing what country you're in, I suggest that your comment indicates that Europe has more strict laws about tracking than your own country.
- marcus_holmes 5y agoAs we're discovering: plagues are universal
- ryukafalz 5y agoIf you live in the US as I do: yes, they are. I traveled to Germany and Belgium shortly before COVID, and the pop-ups were everywhere, even on sites that I know didn't have them back home. Anyway, I'd prefer if we had privacy laws like this in the US too.
- pseingatl 5y agoCalifornia does. There is no comparable federal legislation. No other State comes close to California.
- DominikPeters 5y agoYes, there are more popups when in Europe and they're often a lot bigger. You'll see it if you use a VPN to a server in Europe.
- vanviegen 5y agoI'm under the impression that some sites have created an especially annoying cookie wall for the EU, while serving their baseline annoying cookie wall to the rest of the world. Most of the sites can't be bother to make the distinction though.
- anonymousab 5y agoHopefully the deletion includes both backups and any ML models trained on that data.
- rwmj 5y agoI can't find any English language news about it, but Yahoo Japan are going to withdraw a bunch of services from Europe in April including webmail and news. They're citing GDPR costs. Edit: Apparently it's been picked up since last time I looked: https://www.theverge.com/2022/2/1/22911965/yahoo-japan-europe-offline-regulations-compliance-gdpr https://www.theverge.com/2022/2/1/22911965/yahoo-japan-europ...
- Isinlor 5y agoWhat does Yahoo Japan have to do with Europe?
- rwmj 5y agoNot sure exactly what your question means but I'll attempt an answer: They currently offer services in the EEA and UK, such as webmail and news alerts (all in Japanese) and they will withdraw those services (presumably by geoblocking) in April.
- dane-pgp 5y agoHopefully that will encourage Japanese expats living in the EEA and UK to push for equally good data protection laws back in Japan.
- johnchristopher 5y agoIncredible. On one hand our Data Protection Authority gets that done and on the other hand the European commission is about to start legal action against Belgium for GDPR infringements https://www.brusselstimes.com/news/belgium-all-news/173086/european-commission-general-data-protection-regulation-gdpr-legal-action-belgium-frank-robben https://www.brusselstimes.com/news/belgium-all-news/173086/e... And we just passed a law that permits our IRS to have our bank account's data. And there is an ongoing project to store and register citizens' health data in one single database, available to insurers and government agencies. Over the last year there's been drama and real concern around the DPA https://iapp.org/news/a/belgian-dpa-director-resigns/ https://iapp.org/news/a/belgian-dpa-director-resigns/ with director resigning and claiming pressure from the authorities post resignation (as PI rummaging through here trash bins). We have a guy who single handedly decides if databases projects are OK with GDPR and privacy laws and he's the one providing the software solutions. Belgian surrealism at its finest. I know there are people from the north on HN, I wonder what are their view on these matters ?
- littlecranky67 5y agoAnybody wants to shed some light what exactly was illegal at the consent popups? I think Google, Microsoft and others use all different/branded popups, so I would want to know what the problem is there.
- Nextgrid 5y agoFrom a UI point of view, the failures I typically see is that agreeing to everything is easy but declining is difficult despite both options needing to be equally prominent. From a technical point of view, the tracking scripts are often loaded to begin with (where your IP address & browser fingerprint is already leaked) and declining tracking merely "asks them nicely" with no guarantee they'll obey the signal or whether the already-collected data (from just loading the script) will be deleted.
- Macha 5y agoAlso the legitimate interest abuse was also ruled against. Many of these claim legitimate interest so they have a second set of options you need to untick or click "object" to individually. This isn't valid consent as not giving consent is harder than giving it, and per the ruling isn't valid legitimate interest as the companies did not conduct an adequate balancing of the user's interests vs the businesses and when the DPAs did so they did not find the company's interest outweighed the user's privacy interests.
- rkagerer 5y agoTo be frank, the practical result of GDPR is that it made my browsing experience worse. Nearly every website opens with an annoying cookie popup, often blocking the content (or reducing it to a fraction of my screen on mobile). I've never once clicked "Yes, track everything", except by accident when tricked into it by deceptive UI (eg. a button designed to look more inviting than its less invasive counterpart). I get that wasn't the intent, and there are less intrusive ways for companies to comply. But the result we ended up with is a mess.
- mpweiher 5y agoNope. > there are less intrusive ways for companies to comply. These intrusive ways are companies not complying. This is what is currently being litigated, an industry pulling out all the stops to not comply with the GDPR. This ruling is a major victory along the way.
- martin_a 5y agoWell, all those popups are at least showing how much you've been fucked up before by tracking and analytics and other systems in place. While the outcome isn't optimal (for the moment) we now at least see what's happening.
- jpambrun 5y agoThis is those companies successfully instrumenting you to lobby on their behalf. It is purposely and spitefully made to be annoying. Let's not reward that.
- rkagerer 5y agoDon't mistake my comment as an endorsement for data collection. It was about the practical effects that came about after the legislation was introduced. I hardly believe webmasters around the world coordinated a premeditated, mass conspiracy to annoy their visitors. I rather think the mess results from a misunderstanding on the part of businesses about what is actually required by the various legislation, complacence by the poor chap who's just trying to publish a site, and, yes, dark patterns on the part of platforms providing elements of the stack. e.g. Those annoying banners aren't needed if you construct your site to not use cookies at all, until they're actually required for functions a user explicitly requests. Platforms have no business asking for my consent in the first place to cookies they know darn well do not serve any bonafide interest for the user.
- cstross 5y agoSome crazy figures here: The maximum fine for such a breach is 4% of the company's global revenue. Microsoft, in 2021, turned over $168Bn. Google turned over $181.69Bn. Amazon turned over a staggering $457.96. Between them they had a combined turnover of $807.65Bn, making them liable for a fine of up to $32.3Bn per year (assuming revenue is flat and they all get hit for the maximum penalty and don't do any kind of damage limitation). The EU general budget in 2019 was only €148.2Bn. So such a fine would actually cover nearly 20% of the running cost of a 27 member multilateral trading entity with a population larger than the United States.
- deleted 5y ago[deleted]
- marketingtech 5y agoIAB Europe is the entity being fined, not their participating partners. The linked PDF says their fine is 250k euros, which is "proportionate to the infringment" and less than the maximum.
- Nextgrid 5y agoSeems like the IAB is essentially volunteering to be the scapegoat to shield everyone else. 250k is peanuts compared to how much the industry has made breaching the GDPR over the last 4 years.
- cstross 5y agoIAB's business model is broken at this point. The EU's point is that you can't rules-lawyer your way around GDPR violations by outsourcing the lawbreaking to a paid scapegoat company: having ruled the practices to be essentially illegal, this is going to end up being kicked up a level to the big advertising corporations themselves (by which I mean: Google, Amazon, Microsoft).
- Nextgrid 5y ago> this is going to end up being kicked up a level to the big advertising corporations themselves When? In a century? It took them years to reach a conclusion that even a layman skim-reading the GDPR would reach in an hour.
- jdrc 5y agoGood, but i 'd like to see someone going after the root perpetrators of this racket, the advertisers themselves. That industry is surprisingly immune from scrutiny despite the fact that they 've wholesale sold their soul to google which is now both the buyer and seller of billions of advertiser money. They re just enabling the monopoly
- phicoh 5y agoAdvertisers need content to advertise on. The GDPR basically forces content providers to get rid of tracking. That will require Google to provide an ad platform without tracking. And then the fun is over for the advertisers. Of course with underfunded government privacy enforcement bodies, that process takes a long time. And then there is Ireland.
- jdrc 5y agoNo, advertisers want attention. And they are lazy, they are not going to look for content that fits their product. Google tells them "i have X users interested in your product" and that's what they buy. What's going to happen is they will move all their ad inventory into google search advertising.
- phicoh 5y agoGoogle will still tell them 'I have X users interested in your product'. It is just that Google will compute that from the contents of the wedsite instead of from tracking users. It would be amazing if there would be no ads outside google search. But that will not happen. That is a void that will be filled very quickly.
- jdrc 5y ago> no ads outside google search There will be no content then, so the inside of google will be equally empty
- deleted 5y ago[deleted]
- dogleash 5y agoWhoopsie daisy! I'm sure IAB's err was a total storm-of-the-century, couldn't ever have been expected, failure of their otherwise iron clad commitment to honoring and respecting digital user privacy.
- alkonaut 5y agoGood. Now pick a random one of the companies that used this particular product/service and make an example of them. The problem I think until now has basically been that sites that rely on tracking ads know they are in violation. They don't want to comply, because it would be too costly. Basically, a meeting at one of these businesses (I'm imagining) has a conversation where people say "Ok what do we do about the cookies? Unless we at least write the X and Y and Z tracking cookies, we can't keep the lights on so we cant't risk users just clicking 'Reject all' and getting dumb ads. What should we do? I think we should use that dark pattern dialog which leaves X Y and Z on for 75% of visitors who just click the biggest button. That at least buys us some time. If regulators complain we can always change it". A regulation that was scary enough would see sites prefer shutting down over using a dark pattern. For that to happen, the fines not only need to be big enough to be fatal to the business, they have to actually go further and be personal fines to key employees.
- ocdtrekkie 5y agoIf you want to solve the problem, roll up on Google and Facebook headquarters, throw Sundar and Zuckerberg in jail for a year. Companies will think twice about their approach of "claim compliance until proven otherwise and then take the wrist slap". Put CEOs in prison and you'll see lasting change. As long as they can harm billions of people and only pay a modest fine in return, they will not change.
- stale2002 5y agoYou are confused about what the "lasting change" would be. What would happen is that most of these major tech companies would simply ban all EU users. If the EU wants to be shut out of most of the tech world, fine. Because that would absolutely be the result of if all "tracking" was effectively blocked or stopped.
- phicoh 5y agoThat would be a great outcome for the EU. It means that EU companies have a home market that is shielded from their biggest competitors, while being free to compete on the world wide market. If the EU would do that intentionally there would quickly be a complaint at the WTO. In reality, as long as Google, Facebook, etc can make money in the EU, they are not going to leave.
- mchusma 5y agoThese GDPR banners have made the internet a worse place for most users IMO, there needs to be an easy way to consent to all tracking and skip the banners across all sites. I'm fine with this being opt in, but it should be easy to do on a "normal" browser (like chrome or edge including mobile) without the need for an extension. Forcing everyone to deal with these things is bad.
- aaomidi 5y agoYou could just, not track. That's always the option and it's what the final intention of these rules are. Just browsing a website shouldn't be grounds to start tracking users.
- jamesliudotcc 5y agoHere is what I don't understand. They clearly mean to ban online tracking. They make the laws. But instead of making a law that makes tracking illegal, they make a law that says you must consent, and leave blank what consent means. Then they make rulings about what consent means that amount to "it is illegal to collect data for tracking." Why not just ban tracking and be done with it?
- rtb 5y agoThis is a good question. I think the answer is that it's difficult to define up-front what is illegitimate "online tracking" and what is legitimate tracking of users necessary for things like accounts and saving of preferences (without drowning in special cases and loopholes). The idea was to let users decide for themselves, case by case, whether they wanted the tradeoff of being tracked for the rewards (including things like saving your preferences). The tracking industry didn't want to be banned and wouldn't give up without a fight, so they looked for a loophole in this fake consent spam.
- simpss 5y ago> and leave blank what consent means Actually, this is not left blank at all... -------------------- Consent means offering individuals real choice and control. Genuine consent should put individuals in charge, build trust and engagement, and enhance your reputation. Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent. Keep your consent requests separate from other terms and conditions. Be specific and ‘granular’ so that you get separate consent for separate things. Vague or blanket consent is not enough. Be clear and concise. Make it easy for people to withdraw consent and tell them how. Avoid making consent to processing a precondition of a service. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- lmkg 5y ago> They clearly mean to ban online tracking. There's your error. GDPR is not about online advertising. Things regulated by GDPR: * CCTV in public spaces. * Medical records. * Employment records that businesses keep about their employees. * Credit reports. * Government records like voter databases and housing information. * Trawling public business filings to send direct-mail spam. * The loyalty card issued by your grocery store which tracks your purchases. * The CRM database used by the sales guys in your SaaS company to keep track of hot leads. GDPR regulates a wide array of data collection, and outright banning is not the correct solution for most of them. So it's about what obligations are attached to data collection and processing. Online advertising is only a small part of what's being regulated. Even online, there are modes of data collection which are permissible. E.g. collecting anonymous site statistics for your own internal use. The obligations get harder and harder to satisfy when your business practice is to spread data hither and yon to whomever will pay a nickel for it.
- tiborsaas 5y agoOh no, I carefully trained google and Facebook to only show me ads about home renovation products by accepting cookies on specific webshops :/ Only half joking here.
- jacquesm 5y agoSo, how long until at least one online media giant realizes that not tracking their users and good old display ads are the easy way out?
- jdrc 5y agonot gonna happen. (I don't know if it's related, twitter just showed me a cookie dialog out of the blue). Google is big enough to set their own consent standards, the IAB was a ruse anyway
- eproxus 5y agoNever, as long as their core business model is based on privacy invasive tracking? They have every incentive to fight this back and none to actually comply (unless fines start getting higher, I suppose).
- jacquesm 5y agoWell, me they've lost, I'm ad blocked to the hilt. But back in the day when tracking became pervasive the only thing that all that presumably smart coding did was irritate me, especially because I never saw a single ad that really appealed to me. This may well be because I'm weird, but even then: that's what tracking is for right, to personalize the experience.
- majewsky 5y agoUnfortunately, this is a Prisoners' Dilemma. If there were no personalized ads, regular ads would soak up all the ad budget and therefore be sustainable. But as soon as there are personalized ads, they quickly outcompete regular ads. Hence regulation is required.
- pseingatl 5y agoAmericans think they can ignore the GDPR because it doesn't apply to them. Guess again. Moreover, other countries outside the EU are modeling their own, new legislation on the GDPR. Eventually, the US private sector will be forced to implement the GDPR for convenience' sake. The only issue will be the finding that because of built-in,NSA/FBI backdoors, data sent to the US cannot be secured under any circumstances.
- legitster 5y agoCan someone explain to me what the actual ruling is? Is the agency in question out of compliance, their specific implementation of a consent pop up, or the entire concept of a consent popup? We use a consent pop up for non-advertising related cookies. And I'm trying to figure out if we are no longer in compliance.
- pixelkaiser 5y agoThis headline and article is a gross misrepresentation of the ruling. The ruling is that the TCF consent string contains personal data and that the IAB is the data controller for this bit of data. This ruling has no impact what so ever on consent popups. It basically "just" trashes the industry standard that is used to pass consent signals. There are plenty of custom or non TCF implementations (all equally awful) of consent dialogs. This ruling puts Google and FB in a much more powerful position - because they do not have to rely on standards like TCF to pass consent signals. Instead of going after publishers and website owners who integrate these popups in the first place - they went after the inventor of the spec.
- TotempaaltJ 5y agoNot quite. It does base some of its ruling on the consent string (it's the only personal data the IAB manages), but it does also conclude that the IAB is just as responsible as any complying participants. From what I understand, it argues that the IAB sets minimum requirements for the consent screens and ad serving, and those are not good enough. See also page 126 for a summary of the ruling. An editorial of my favourites: > order the defendant to > a. prohibit, via the terms of use of the TCF, the reliance on legitimate interests as a legal ground for the processing of personal data by organisations participating in the TCF > d. take technical and organisational measures to prevent consent from being ticked by default in the consent interfaces > e. force consent management platforms to adopt a uniform and GDPR-compliant approach to the information they submit to users
- pixelkaiser 5y agoThe whole thing is based on them declaring the IAB the controller of PII data (in this case the consent string). If upheld all the things you list will apply because these are the responsibilities of data controllers as per GDPR. If the TCF string was not deemed PII data then there would not be a controller because the GDPR would not apply. IMHO, if they were really serious about this, they would have to go after the actual controllers (not the inventor of the spec) - mainly the actual websites that implement these (misleading) banners in the first place. It's beyond me how they can qualify the IAB as a controller when they never collect, process or store any of TCF data. If this wasn't so politically charged I'd say the IAB has a solid shot of getting this overturned in court.
- throwawaymanbot 5y ago
- MockObject 5y agoI seem to be the only HN user who really does not care at all if I am tracked. Judging from the horrible quality of ads I get, they're infinitely far away from reaching an accurate model of my behavior.
- bradlys 5y agoJust because you get bad ads doesn’t mean you’re not getting tracked well. In fact, it might mean you’re tracked really well and the only ads you’re getting served are those that are by one bidder. Everyone else decided you weren’t worth advertising to - so you get generic mass appeal ads that are very low cost to the company. No different than getting spam snail mail that gets delivered to every house. Sure - you toss it in the recycling every week but someone will read it eventually and it’s basically nothing for the company to send out.
- pelorat 5y agoNo, I'm European and use a pixel phone with all data sharing enabled. I also enabled facial recognition in Google photos last time I was in the USA. I also share all my exercise data with Google, including heart rate via Google fit. I block most ads, except for Google ads and analytics. I always click on "accept all" when I get cookie and GDPR forms. My Google Drive is full of documents like scans of my passport, ESTA requests and some financial documents. I also have zero of the Google account privacy options enabled. I'm also a local guide on Google Maps with a real photo, and my real name on the profile.
- llampx 5y agoIts cute that people still think that all of the data that Google and Metabook are amassing is used to sell them toothpaste.