7 ms·
Largest GDPR fines surpass $1.3B
- mritun 5y agoThe section on “ How to avoid GDPR fines in 2022” is naïve to a fault. My personal opinion is that after recent rulings startups need to be very careful. GDPR compliance is practically a nightmare for any entity that even so much implements visitor counter with default http logging turned on. It will be interesting to see how solutions and landscape evolves once GDPR fines come to smaller companies and startups.
- thaway2839 5y agoMaybe defaults should not be designed to capture personal information. This indicates a massive need for GDPR or something like it, as opposed to the opposite. The lack of disincentives to collect personal information is why so many softwares default to collecting it. GDPR flips the equation completely, where GDPR aware software (and lots of software now market their GDPR compatibility) will default to not collecting personal information.
- yawnxyz 5y agojust embedding a tweet from Twitter's official embed code makes you violate GDPR (e.g. if you have a blog and want to reference a tweet). Twitter injects a ton of cookies and there's not much you can do about it
- elygre 5y agoMaybe the trickle down economy will work. First some web site operators get fined for not realizing that their subcontractor (twitter) captures personal data. They stop using said subcontractor, and at some point this trickles down to twitter, who will provide a compliant solution.
- gundmc 5y agoUsing Google fonts is a violation now. It's a nightmare for web developers.
- throwaway2048 5y agoMaybe web devs should more carefully consider how much crap third party scripts and resources inject into their sites, rather than caring about a tiny bit of convenience.
- shukantpal 5y agoMaybe users should be responsible for what they intentionally run on their machines.
- Daishiman 5y agoNobody in their right mind is going to carefully peruse the cookies and injected JS scripts of every page they visit. No, the onus is clearly on the developers, who are the ones with the professional responsibility to make software that abides by the laws.
- hulitu 5y agoWhen the law is not enforced, there is no hope.
- Daishiman 5y agoClearly the GDPR is being enforced
- shukantpal 5y agoI’m talking at the meta level. The laws can start nationalizing every company. But I think it shouldn’t. The law can put the burden on developers — but shouldn’t. I shouldn’t have to abide by some stupid rules to plug my server onto the Internet and listen on port 80.
- white_dragon88 5y agoThat’s absurd. That’s like saying car owners should be held responsible for how safe their car is to drive. It makes unrealistic assumptions about the competency of the end user to judge such things.
- kungito 5y agoCan someone explain to me how GDPR makes you responsible for twitter collecting data? It's not your faukt if twitter has their own cookies... What matters is whi stores the data who in this case is not the person embedding twitter
- unicornporn 5y agoQuite simple. You just facilitated Twitter's data collection. Without you it would not have happened. Even worse, the user loading your page could probably not have known you embedded a Tweet (and sent their data to Twitter) before actually loading the page (if you didn't implement a consent dialog with a reject option).
- CodesInChaos 5y agoThe user only has a business relationship with the website they visit. The website is responsible for the services it employs, just like any other general contractor is responsible for their subcontractors.
- tluyben2 5y agoYou should not do any tracking (in which case you do not need any pop-up and approval dialog) and if you put things like twitter feeds, Google analytics and Adsense, you need to have a choice for the user which, if they do not want this, will not put them on your site. The thing is; most sites do not honour your choices or make them as hard as possible as analytics and Adsense are required for monetising. Analytics can be replaced by friendly versions that are gdpr compliant without personal info storage or cookie tracking, but then your monetising (Adsense) or internet marketing (AdWords and landing pages) are not integrated into funnels and a lot harder. I have tested it with some of our assets (most of which do no tracking at all and only have 1 necessary cookie for login without SaaS cannot work) but a few have Adsense and analytics; we have a small and simply bar; accept or not accept; both is one click. ~90% (not exact as we try to compare the Google analytics which means they did say Accept vs the none cookie analytics which means both accept and not accept) clicks Accept which is enough. We use [0] by the way. [0] https://plausible.io https://plausible.io
- atoav 5y agoGood. If you want to quote text, copy it. Has the advantage that it still will be around once the tweet is gone or Twitter is offline. With a little css it will look the same as the original tweet to which a simple link could lead you. This is what you do if you value your users privacy. If not, then you have (under GDPR) at least give them the choice not to get these cookies. Which destroys the usability of your site for your privacy conscious users.
- Schroedingersat 5y agoGood. Don't foist untrusted code onto your visitors' devices.
- jacquesm 5y agoGDPR compliance is totally doable, in fact, if you take 'don't screw your users and be careful with their data' as your guideline you will make almost all of the decisions the right way. Note that fines are almost exclusively for repeat offenders, and that were they were not there was clear evidence of malice rather than accident.
- m4l3x 5y ago"According to France’s privacy watchdog CNIL, Youtube users only had to click once to accept cookies, whereas refusing cookies took multiple clicks. CNIL’s complaint stated that Google purposefully made the consent mechanisms more complex to push consumers to accept cookies––a clear violation of the GDPR’s requirement that companies provide equally simple ways to opt into or out of data collection." So these dark patterns are officially violating GDPR. However there are still tons of websites implementing this.
- nicbou 5y agoThey were from the start and this was abundantly clear, but given the complete lack of enforcement, people just did whatever the big websites were doing. If these don't get caught, why would they go for random cooking blogs?
- unicornporn 5y agoWhat if they could go for the companies building these standardized GDPR cookie consent dialogs instead...
- csunbird 5y agoWhich, sometimes, also illegal. Trustarc for example.
- charcircuit 5y agoI wish Europe would undo these privacy laws so that the web can go back to normal before they ruined it for the entire world.
- Schroedingersat 5y agoThe only thing needed for it to go 'back to normal' is to treat the do not track flag as if you had automatically fucked around with their anti-cookie game for 10 minutes, and then also not use any server side tracking or half of the 'necessary cookies' and not bother you.
- jacquesm 5y agoNo, they should strengthen them instead and put a couple of offenders out of business that would definitely get a lot more companies to fall in line and stop abusing their users. Effectively you are arguing that the self regulation worked, but it really didn't. Hence the need for legislation and hence these (still pretty mild) fines. For starters: don't include third party resources in your offering. That already cuts down tremendously on your exposure under the GDPR.
- charcircuit 5y agoMe collecting data is not me abusing my users. I am simply recording facts about the world. Being forced to censor facts because the people the fact is about don't like it is plain censorship. Information should be free.
- chockchocschoir 5y agoIf you're not collecting personally identifiable information, you are not affected by GDPR and can proceed as normal. Not exactly sure what "recording facts about the world" means, but if it doesn't involve individuals and their data, you don't have to change anything. I agree that general information should be free, but there is a difference between general information and personal information. Personal information (like the photos I take in my bedroom) should not be free unless I agree to that.