22 ms·
Consent, GDPR and Google Analytics
- adithyasrin 5y agoThis is going to be a hot topic in Germany once the German courts rule it out. Should it say it's illegal to load, we have got loads of work in front of us. One simpler solution that I have seen Zaraz by Cloudflare, which seems to solve this issue. Has anyone had experiences with this? https://blog.cloudflare.com/keep-analytics-tracking-data-in-the-eu-cloudflare-zaraz/ https://blog.cloudflare.com/keep-analytics-tracking-data-in-...
- fenier 5y agoThe author of the blog apparently also wrote about Zaraz in this post: https://cunderwood.dev/2022/01/30/tag-management-is-no-longer-a-technical-only-decision/ https://cunderwood.dev/2022/01/30/tag-management-is-no-longe...
- speedgoose 5y agoCloudflare is from USA so it’s a quick decision to take.
- cassianoleal 5y agoStill an US corporation, subject to the CLOUD Act.
- shoto_io 5y agoI’m not the biggest fan of Ben Evans, but he’s right on “privacy fanatism”: > At a certain point EU privacy regulators will realise: When an EU citizen requests a US internet resource, they provide a US server with their IP address; An IP address is PII; The CIA could record that; Therefore it is illegal to provide any internet resource to anyone in the EU Source: https://twitter.com/benedictevans/status/1492102034409066504 https://twitter.com/benedictevans/status/1492102034409066504 PS: saying this a German citizen…
- marcosdumay 5y agoYes, taking it literally at the extreme case, the rule is unreasonable. But Google Analytics is the kind of thing the Law was created to stop, it's not an unreasonable unintended effect.
- kuschku 5y agoThere’s no issue with that. If a person manually takes their information and mails it to the CIA, that’s also fine. The issue is if a person visits a resource from a company in the EU, they should be able to expect that that information won’t be passed along to any third party that’s not absolutely necessary. Especially not to foreign governments. You wouldn’t expect a visit to latimes.com to leak your information to the Chinese Party either.
- throwhauser 5y ago> The issue is if a person visits a resource from a company in the EU Does it have to be a company in the EU? I thought the GDPR covered any website an EU citizen, resident, or visitor might use, in which case US-based websites might have contradictory obligations to the GDPR and US law.
- fenier 5y agoIt depends on Art 3. https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/ Just because a website exists and may be visited by a EU resident, does not mean that the site automatically has to comply.
- morelisp 5y agoIt will be hard for a lot of US media making deals with European advertisers to claim they’re not intended for use by European residents, though.
- ensignavenger 5y agoIs that not what 2(a) says- if a service is being provided to an EU data subject, that the regulation applies? At least, that is clearly what the EU seems to be claiming? Sure, if no EU data subject actually accesses the site, it doesn't apply, but the moment one does...
- anothernewdude 5y agoJust don't opt in to Google Analytics. I don't.
- SquareWheel 5y agoThere's an opt-out, but not an opt-in for Google Analytics. Unless you're referring to simply blocking it via a content blocker script.
- tremon 5y agoContent blocking is also opt-out, in the sense that no browser blocks this by default.
- noisem4ker 5y agoI think you meant opt-in. But it's actually opt-out in the case of Firefox, which has been shipping with Enhanced Tracking Protection enabled by default since 2019. https://blog.mozilla.org/en/products/firefox/firefox-now-available-with-enhanced-tracking-protection-by-default/ https://blog.mozilla.org/en/products/firefox/firefox-now-ava...
- throwaway932489 5y agoOpt-out means on by default, opt-in is off by default (sorry to state the obvious). The users above are referring to opting in/out of the tracking rather than the blocking of the tracking - so GA on Firefox by that standard is opt-in, even though in a Firefox specific context the setting is opt-out. Obviously the EU wouldn't be cool with "but a competing browser with a small market share blocks us by default anyway".
- tremon 5y agoYeah, I guess it depends on what the opting is for. I could have phrased that better. What I meant to say: third-party tracking is still opt-out, since you need to actively enable the content blocking to avoid being tracked. The blocking of said content trackers is opt-in of course, but that's not what I was referring to.
- nonrandomstring 5y agoWhat a tangled web of legal niceties and hypothetical interpretations we've woven here. But the moral arithmetic, toward which European thought is tending, is more brutal and something to which American corporations had better pay serious attention to if they want to keep playing this game. In general; we hold that "ignorance of law is no excuse", yet in contract law _capacity_ is a key construct, and ignorance very much _does_ play a part. It's not just minors, the mentally-ill, or those incapacitated by drugs or alcohol, discombobulated or bamboozled by other means, who cannot give consent in a contractual relation. In an age where most lawyers and judges, like everyone, mindlessly click-through "agreements" and shrink-wrap EULAs, there's a strong and growing argument to be made that non-expert adults lack genuine capacity to understand technologically mediated relations. In other words, it's the contract law that underlies this stuff that's coming up for revision, not the surface interpretations. The important matter now is not deliberating whether the letter of the law creates "consent" on this or that occasion, but whether the spirit of the law allows for consent even in principle, given societal standards of digital literacy and the complexity of modern digital interactions.
- foxfluff 5y ago> In an age where most lawyers and judges, like everyone, mindlessly click-through "agreements" and shrink-wrap EULAs .. That's an interesting problem. I'm a little disappointed that the route we've gone is having courts decide that this or that bit of EULA isn't binding, but people are still expected to read them and be somehow bound by them. It's kind of difficult for the common man to find out which parts of an EULA are or can be legally binding, so why should they ever be read? For a while now I've been thinking that EULAs should also be made simple and clear and understandable, kinda like they're forced companies to do now with consent dialogs. No walls of text, no small print, no legalese, and definitely no tons of obviously unenforceable but chilling terms (that the poor reader might think are enforceable). It does not feel right that people are "agreeing" to something they didn't read anyway (and which if they did, most people wouldn't really understand anyway), and they can only find out what their rights are after the fact.. so maybe we should just say that such agreements are not okay, stop it. It should be easy to understand exactly what you are agreeing to (or possibly we could just have the terms in law and stop this silly game altogether).
- Janiya 5y ago[dead]
- deleted 5y ago[deleted]
- EtienneK 5y agoGood article. We need more of these. GDPR and integrating with 3rd party services can be quite a legal minefield. I would like to see an article regarding Google Recaptcha. I am currently considering Recaptcha during a login process as a means of protecting against credential stuffing and password brute forcing. But I do not know if this counts as "legitimate interest" as defined by GDPR. And if it doesn't, there really isn't any way to ask for consent in this case, because "denying" consent sidesteps the entire security measure...
- zeepzeep 5y ago> I am currently considering Recaptcha during a login process Please don't, think about your users. Just use normal rate limiting instead of forcing me to select more god damn street signs.
- Spivak 5y agoThat makes no sense, one is not a replacement for the other. Spam bots can be slow, and human users can hammer your API. You need both.
- zeepzeep 5y agoYou don't. If you want to prevent credential stuffing rate limiting is perfectly fine and that was the only reason EtienneK wanted to use captchas. Spam bots can be slow yes, but this is about credential stuffing, that can not be done slowly or else it'd take years.
- Spivak 5y agoRate limiting doesn't protect against credential stuffing either -- it doesn't manifest as a brute-force attack, they rarely originate from a single ip/network you could reasonably rate limit against, and even if you could magically rate limit them you've already lost because you let the bots try their stolen credentials in the first place. Your only real defense is to have a system that identifies bots directly to make it so attackers can't automate spamming credentials across a bunch of different sites. If you let attackers have like 10 attempts per ip per minute and you're a site where a bunch of people have accounts then you're gonna become an instant favorite for testing stolen creds.