17 ms·
Statement on 4 Years of GDPR
- fsflover 4y agohttps://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- Ygg2 4y agoHonestly, never saw the point of GDPR. You add additional expenses for something big abusers will just bypass, ignore or even worse just retract from the market.
- varispeed 4y agoThe purpose of GDPR is to help abusers legitimise the data they collect. Before GDPR it was a grey area, because users didn't explicitly consent to anything - GDPR fixes that. Ubiquitous pop ups where you agree for your data to be collected and processed, trained users to consent to anything that comes their way and corporations now have legal basis to use, process and sell that data. It was quite clever - make people believe the legislation is for their benefit, whereas in reality it has been created to help with data abuse and make money off of it.
- MattPalmer1086 4y agoThat's an unduly cynical take in my opinion. GDPR isn't about web sites and cookie preferences, although that is the most visible effect to users. I'd happily replace that whole cookie mess.
- withinboredom 4y ago> trained users to consent to anything that comes their way and corporations now have legal basis to use, process and sell that data. Sorta? I don't consent to much when I get the pop-up. You can revoke consent at any time as well and you're entitled to the data the company has on you.
- varispeed 4y agoAverage person don't understand what they click on and they just want the pop up the get out of their way. You have a bias for being a tech person who understand this, but vast majority of people have no idea what it is about and they just consent because they don't care or know the impact of their decision.
- withinboredom 4y agoMost people I know are not tech savvy and from shoulder surfing, they click no to consent. One couple I know won’t even install an app if it asks for their location.
- SiempreViernes 4y ago> vast majority of people have no idea what it is about and they just consent Do you have a link to the study that shows this?
- Nextgrid 4y agoThe GDPR has strict regulations on what counts as valid data processing consent. 90% of the consent popups you see out there do not fit that criteria and any "consent" obtained via them doesn't count.
- deleted 4y ago[deleted]
- kreeben 4y agoThe point of GDPR is to smack companies that fail to meet it hard on the nose, so hard, in fact, that it might break. The maximum penalty is 2% of yearly turnover. That's hurtful even to megacorps. No one, not even them, needs a broken nose.
- retSava 4y agoIn theory yes, but so far they haven't brought the hammer onto anyone of formidable size.
- kreeben 4y ago[flagged]
- mhitza 4y agoAmazon Europe Core S.à.r.l. Industry and Commerce LUXEMBOURG 746,000,000 euro Non-compliance with general data processing principles 16 Jul 2021 WhatsApp Ireland Ltd. Media, Telecoms and Broadcasting IRELAND 225,000,000 euro Insufficient fulfilment of information obligations 02 Sep 2021 https://www.enforcementtracker.com/?insights https://www.enforcementtracker.com/?insights
- retSava 4y agoIn 2021, Amazon EU S.à r.l. had a revenue of over 51 billion euros Can't find numbers on profit, but companies such as amz are experts on creativity, as indicated by eg this quote: Amazon paid zero corporation tax in Luxembourg last year, despite seeing a record sales income of €44 billion. As first reported by The Guardian, accounts for Amazon EU Sarl published online showed that despite making billions of dollars in sales, the company's Luxembourg unit, which oversees retail in countries across Europe, made a €1.2 billion loss and therefore paid zero tax. Not only did the company not have to pay corporate tax, but it was also handed €56 million in tax credits to offset future tax bills in the event that it does turn a profit. That also comes on top of €2.7 billion in losses that have been carried forward and can be used to offset future tax bills. Ie, not a sledge hammer.
- Nextgrid 4y agoWell the idea is that with proper enforcement the big abusers shouldn't be able to bypass it. The legislation itself is sane, it's just that enforcement is lacking. > even worse just retract from the market I disagree that this is worse - if privacy-violating monopolies retract from the market then it opens the doors for privacy-respecting competition to take its place.
- Ygg2 4y ago> The legislation itself is sane On paper yes, great intentions[1], in practice no. E.g. Right to be forgotten. Implement RTBF in context of IPFS. [1] Second order effects like prevent rats/snakes by awarding award for rat/snake heads, lead to rat/snake farms. > if privacy-violating monopolies retract from the market You get Splinternet. Several independent Internets, walled from each other.
- Nextgrid 4y agoI find the right to be forgotten very valuable in a world where everything is permanent, searchable and every little mistake will be used against you in the future. > Implement RTBF in context of IPFS. How does IPFS deal with CSAM being published on it? Not saying it should detect CSAM, but once it is found, how does one go about having it removed? You use the same system to handle RTBF, and if you can't, then maybe a platform where it's literally impossible to delete something isn't a good idea (partly because undesirable content will ultimately outnumber legitimate content)? > You get Splinternet. Several independent Internets, walled from each other. If there's an internet where Facebook and Google can't spy on me, sign me up!
- Ygg2 4y ago> I find the right to be forgotten very valuable in a world So do people with skeletons in the closet. Not saying you do, but right to be forgotten can infringe on other people's right to be well informed. This is not a hypothetical. It has already happened. > How does IPFS deal with CSAM being published on it? Using CSAM to justify a law, is not a winning strategy. It would be tedious but probably destroying all nodes. Which means IPFS is not compatible with RTBF. > If there's an internet where Facebook and Google can't spy on me, sign me up! That does leave state actors though.
- arky527 4y agoGDPR also opened the door for the eprivacy directive that brought us cookie law
- Nextgrid 4y agoePrivacy was there way before the GDPR.
- diffeomorphism 4y agoDifferent order. That is also why the gdpr addresses some of the abuse of the cookie law.
- PartiallyTyped 4y agoGDPR prevents companies like "safe"graph [1] from selling mined data: >The GDPR (European Law) > As of May 25, 2018, a new data privacy law known as the EU General Data Protection Regulation (or the "GDPR") went into effect through the EEA countries. SafeGraph does not offer products or services involving the collection or sale of “personal data” in EEA countries. We likewise seek not to collect such personal data from our data providers. Should any of the foregoing change, we will update this section of our Privacy Policy. If this is not a net win, I don't know what is. [1] https://www.safegraph.com/privacy-policy https://www.safegraph.com/privacy-policy
- piva00 4y ago> even worse just retract from the market This is like saying that regulating damage to the environment is bad because would make businesses that can't exist without doing said damage would retract from the market. Good riddance, if a business can't or isn't willing to protect EU's citizens data they should go away, like many polluting industries that had to adapt or die.
- Ygg2 4y ago> This is like saying that regulating damage to the environment is bad because Sure if a global problem is only taken by a small subset of states. It's not solving a problem just essentially grandstanding. See climate change. But GDPR and related laws have been a mixed bag and a combination of neat and "why the hell do you think that will work?".
- maccard 4y agoCan you give any examples of abusers that have retracted from the market that actually provided a useful product?
- smitty1e 4y ago> Companies realize that competitors do not comply and that acting legally does not pay off. The wider non-compliance spreads, the harder it will get for authorities to gain back control with limited resources. This is what makes writing good/effective law a non-trivial undertaking. If the words on paper don't make positive sense, and negative behavior toward the words isn't backed up with punishment, then the effort corrodes and collapses.
- ckastner 4y agoThis is an excellent quote that reflects a notable share of opinions that I see in the comments here on HN whenever the GDPR is discussed: > Hardly any other area of law is politicized to that extent – at least I have never heard that building or tax codes were openly ignored with the argument that compliance would “undermine the business model” of a company. The privacy bubble accepts such narratives as a legitimate argument.
- solarkraft 4y agoNah, this type of argument is often brought up once someone (with a lobby) actually has to change their ways to comply. Safety features would make cars 3x as expensive, nobody in the world could feasibly implement such radical emissions standards ... All the time. It's just important to recognize this type of argument as pointless.
- JumpCrisscross 4y ago> compliance would “undermine the business model” of a company This is a disingenuous framing of the argument as it commonly appears on HN, sometimes by me. The complaint isn't with respect to what the rules permit and prohibit. (Some people complain about that, but it's not the common mode.) It's the enforcement mechanism. Complaint initiated. Multi-forum and portable. Imprecise on implementation details. Those factors make compliance, even for someone looking to do everything right, expensive. Which raises barriers to entry. (And creates room for mischief.) The closest similar thing in the U.S. is our approach to securities regulation. Complaint initiated. Each state has its own forum. Each side can complain and defend in different forums and then expensively argue over arcane rules for forum selection. Details hashed out through enforcement actions versus ex ante published rules. Now imagine there was no SEC corralling the mess. That's GDPR.
- MichaelZuo 4y agoWhen you put it that way, it does sound pretty onerous...
- ckastner 4y agoI have to disagree with that. I'd wager that even if with a hypothetical perfect GDPR, you'd still have the major advertisers fighting it tooth and nail. Because when "you're the not the customer, you're the product" applies, then the GDPR does effectively undermine the business model. Targeted advertising appears to be immensely profitable; raising boundaries on how you process subject's data, and how/to what extent you profile them, cuts into those profits. The GDPR recognized the protection of PII as a fundamental right. The way I read the argument I quoted, the problem is not that e.g. Facebook would like to comply with the GDPR but cannot do so for e.g. imprecise implementation details. The problem is the GDPR significantly impairs Facebook's ability to generate revenue. And to that end, it appears that Facebook is indeed "openly ignoring" the GDPR to some extent, at least from what I recall from the ongoing complaints by NOYB and others. [To clarify, I don't disagree with your particular argument; on the contrary, the flaws you pointed out are evident. I just don't think that is was the argument being made here.]
- largbae 4y agoGDPR is a good idea, but it seems to be top-down and pushing against megacorp and user alike. As it stands, the law is only making it more expensive to be in the data harvesting business. These extra risks and requirements raise the barrier to entry for new firms and so just ends up cementing the market position of existing players. If people start caring enough to actually cancel services that harvest their data, then the harvesting would stop. But it is very easy to underestimate the power of machine learning and correlation, especially when the data being correlated is gently sipped over years.
- AndrewDucker 4y ago"As it stands, the law is only making it more expensive to be in the data harvesting business" That's at least partially the intention, and I'm entirely in favour of it.
- maccard 4y agoAgreed. At my 25 person company it gives me a lever to pull in conversations about data - when someone asks can I have X, I can pull the GDPR card as a reason not to do it.
- rendall 4y ago> the law is only making it more expensive to be in the data harvesting business Great. "Data harvesting" without explicit consent should not be a thing. > If people start caring enough to actually cancel services that harvest their data, then the harvesting would stop. I think that's quite naive. Much harvesting comes from websites that share data with each other about individual user behavior. There is no service to cancel unless you mean "browsing the web". NOYB has more information, it seems: https://noyb.eu/en/projects https://noyb.eu/en/projects
- adhesive_wombat 4y ago> pushing against megacorp and user alike No, it's pushing against megacorps (and corps) and they're trying to gaslight everyone into thinking it's pushing against users by annoying the users on purpose and telling them the GDPR forced them do it (while also breaking the law and still hovering up as much data as they can while they think they can get away with it).
- PaulKeeble 4y agoThe data protection act before it was not enforced and wildly broken by businesses as well. The law is always in at least two parts, the text as written and the enforcement. If the enforcement is mostly via government funded bodies then one way a government can undermine that aspect of law is simply to under fund the public organisation and that has been happening throughout Europe with strongly right wing governments. Many of these organisations have not been effective since the data protection act was introduced. The law is reasonable but the enforcement doesn't function and never has.
- TekMol 4y agoGDPR broke one of my websites that had tens of thousands of happy users. Users loved it and expressed their delight that the website exists on a daily basis. But when I tried to monetize it without ads and via Patreon instead, nobody paid. Nobody. Recently, Google said they don't think my cookie banner is GDPR conform. But gave no info why and how I could fix it. And turned off Adsense. So I finally took the plunge and turned the site off. My feeling is that the GDPR plays into the hands of the big web players. They have the resources to deal with it. While small one-man shows don't.
- lars512 4y agoGDPR aside, I had similar shock after getting a few million users for a viral language game, but finding that basically nobody was willing to sponsor it on Patreon, even to a level to cover the basic hosting costs. It was a little hard to process at the time.
- raverbashing 4y agoYeah Patreon won't cut for those cases (unless there are good perks). Maybe it's easier to sell merch.
- TekMol 4y agoHave you done that?
- solarkraft 4y agoSponsorship (including merch) works for things people love - not stuff they casually use. In that case ads are probably the best option - but that's easily possible GDPR compliantly.
- TekMol 4y agoWhat did you ultimately do with it?
- arc-in-space 4y ago
- fbn79 4y agoCookie banner has ruined the whole web. - Does not protect people (99% are just fake. If you reject cookies you keep get them) - Cost money to company (so cost to customers). A simpler browser extension where you manage your preference once far all (default) with the possibility to personilize x site (think like you do for camera permission) would have solved the problem in a real way and without all the hussle.
- croon 4y ago> Cookie banner has ruined the whole web. No, all websites that have cookie banners do so because they were already ruining the web, the only thing you can blame GDPR for in that regard is visualizing it.
- Radim 4y agoThat's something the article should have mentioned: 4 years on, and people still think GDPR is about cookies – and even responsible for the intrusive consent pop-ups! It is a testament to the power of the adtech giants and all the other shitty shady businesses, how they managed to twist the narrative. And that's on HN, a presumably tech savvy audience. What chance does the "normal" population stand?
- jacquesm 4y agoLots of people on HN work for advertising companies such as Google, Facebook etc, tech savvy or not has little to do with it.
- GiorgioG 4y agoI don't work for an adtech company and I think GDPR has made the web demonstrably worse for everyone. I'd rather void EU clients altogether than put up a cookie banner/popup.
- dmitriid 4y ago1. GDPR isn't about cookies, or cookie banners 2. It's not GDPR that made it worse but ad-tech and similar leeches who want to continue vacuuming up all available data without reprecussions
- deleted 4y ago[deleted]
- solarkraft 4y agoBackground info: Noyb is the GDPR fan club (run by Max Schrems), trying to get governments to do their jobs to get proper enforcement. And you can join them! https://support.noyb.eu/join https://support.noyb.eu/join
- bjelkeman-again 4y agoAny opinions on how they are working as an organisation? Good, bad, indifferent?
- paol 4y agoThis article is excessively negative on the effectiveness of the law. I would say the biggest issue is inconsistent enforcement by DPAs. The other problems are overstated. Believe me, as someone who sees things from the inside of european companies, compliance is still taken very seriously.
- lupire 4y agoNote that is this an activist website, not an EU government web site.
- vesinisa 4y agoI hear you. These so-called "privacy activists" seem to have no clue how much European corporations are spending on data management, privacy controls, legal due diligence and finally serving the customers' GDPR requests. The last one is the publicly visible part, but it really is just the tip of an iceberg in investment on compliance. This is made even more frustrating by that at least I find GDPR to be not very precise. There are lots of corner cases where it's not clear if some data is covered or not. The strictest interpretations would easily obsolete / criminalize vast majority of ALL software that people today absolutely depend on for their daily lives - like various financial backbone systems - and which largely predate the GDPR. It's hard to not find the regulation a joke - sadly. While GDPR is not precise, I won't even go into the details about the ridiculous cookie law and the braindead portions of the new 2019 digital copyright directive (that French publishers lobbied in to hurt Google News). If GDPR left you in doubt, that idiocy really showed that these EU bureaucrats are completely out of touch with the reality in the field of technology they want to control.
- matthewmacleod 4y agoIf GDPR left you in doubt, that idiocy really showed that these EU bureaucrats are completely out of touch with the reality in the field of technology they want to control. Honestly, the main thing it revealed is how little value a particular segment of the technology community places on protection of individuals' data. It's actually hard for me to think of any better example of regulation that is designed and written to be in-tune with the technology involved.
- pmontra 4y agoThere are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.
- CaptainZapp 4y agoEven YouTube now has a REJECT ALL button. Which is quite nice for folks like me, who always clear browsing data upon exit.
- jaywalk 4y agoIf you always clear browsing data on exit, then what difference does having a reject all button make?
- Nextgrid 4y agoIn theory, declining data processing consent means they should not be using other kinds of tracking (that you can’t block/clear client-side) either. This of course relies on sufficient enforcement of the regulation to act as a deterrent which is currently not the case.
- coffeeblack 4y agoIf you have a /etc/hosts file that redirects 10000 tracker domains to 0.0.0.0 then you don’t even need to clear any browsing data. Plus, you don’t see ads anymore without any browser plugins.
- 2Gkashmiri 4y agopi-hole is much better and easier to maintain than a per device hosts file
- coffeeblack 4y ago
- anovikov 4y agoGDPR is just about one more annoying popup you need to click away on each site you visit, and that some U.S. website became inaccessible without VPN at all. Good job.
- aidanhs 4y agoIn the context of the GDPR, I just want to remind people of this thread where a HN user invokes their rights in order to make Spotify back down on a change that would have locked user playlists into their service for no good reason - https://news.ycombinator.com/item?id=24764371 https://news.ycombinator.com/item?id=24764371 (can't be 100% sure this is what made Spotify change direction, but it seems likely)
- sethammons 4y agoThat was a great thread, thanks for surfacing it. My gut reaction was that there was no way the thread could be involved in changing spotify's mind. Color me convinced
- superkuh 4y agoYikes, what an enlightening demonstration of how bad GDPR and it's users really are. Instead of taking control of their own music by having it on disk this user decided to rely a third party service and then became so upset when the service changed they threatened legal attacks. Services like this should probably block all nation states that support GDPR.
- criddell 4y agoSpotify is based out of Sweden.
- l33t2328 4y agoThey paid a service and expect that service to follow the law. That’s not bad at all.
- Reubachi 4y agoGatekeeping music availability is weird. In most places, the idea of having all this music locally on a disk is impossible. How can someone in mongolia get a lossless, flac based discography of their favorite band from the 80s? The music industry purposelessly makes it harder and harder to get lossless file based music for the first world, save for indie bands on bandcamp and the occasional release by a triple A band/label.And again, this is next to impossible in developing nations. I don't have hundreds of hours and thousands of dollars to dedicate t getting every song I want to listen to on a whim in the above mentioned format, and I have much less time and money to manage those across my devices in a format that is anything short of maddening.
- elisbce 4y agoCookie banner alone has probably done more harm in terms of wasted human life than anything else combined. 4.66 billion active internet users, 92% of which are web users, spending 5 secs per day on clicking all cookies allowed. That's 680 human years wasted per DAY on these banners.
- SiempreViernes 4y agoSure you're not actually thinking of preroll ads?
- oblio 4y agoUmmm.. you know why? Because big companies with deeply unethical business practices are basically saying: "if we annoy you to death, maybe you get governments off our backs and let us make even more money". They're like Big Tobacco when tobacco ad regulations were introduced.
- parasense 4y agoI completely reject the premise of this, that one is somehow EU citizens are not personally responsible for the information they themselves put online. The most hilarious thing is cookies! For example, cookies exist, and they work a certain way... and despite not liking how they work.. they are here, and not going away, and imposing some kind of contract-law of cookies being accepted or rejected totally ignores that the user has, and always had, the ability to reject cookies at the browser level, unilaterally or with policies, without any contract laws.
- avmich 4y agoThe idea of cookies was to establish sessions - something which can be done by other means, so cookies aren't needed. It would be good to have browsers which would clean all cookies every browser restart. Not enough though, some browser sessions can last months, so a better solution is needed.
- red_trumpet 4y ago> something which can be done by other means, so cookies aren't needed How does one actually do that? Embed a session id in every request/response?
- avmich 4y agoYes, each request can explicitly (well, not for the end user) carry the session id - or, say, one of the previous request ids. Cookies do that automatically, but have side effects by remaining in the system.
- lukeramsden 4y agoIs there any way of maintaining session IDs across requests without JavaScript other than cookies? My understanding is, the whole point of cookies is that they're automatically sent by the user agent, anything else that was stored (such as in LocalStorage) could only be used by JS scripts.
- throwaway182754 4y agoAs someone working in ad tech but not rooting for it to win at all costs: the biggest positive I see from GDPR is the fact that many ad tech data vendors have left Europe. I'm talking about vendors that aggregate personal data, track your location and the places you visit, the web sites you visit across multiple devices, etc. i.e. https://www.adexchanger.com/data-exchanges/tapad-is-shutting-down-its-business-in-europe/ https://www.adexchanger.com/data-exchanges/tapad-is-shutting...
- nullbytesmatter 4y agoI don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR. I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests. They can't fine me, I don't have a physical or business presence in Europe, though I do have European customers. The only reason I handle requests is to protect my customers, not myself.
- pc86 4y agoThis is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so.
- stevenjgarner 4y agoIs that really true? My understanding for example in the USA is that if you violate the laws in another country, you automatically violate the laws in the USA (under the Foreign Corrupt Practices Act - https://www.justice.gov/criminal-fraud/foreign-corrupt-practices-act https://www.justice.gov/criminal-fraud/foreign-corrupt-pract...) - or is that really just limited to bribery? AFAIK some other countries have similar provisions.
- pc86 4y agoThe FCPA is incredibly specific. What US law requires a US citizen to comply with EU law?
- stevenjgarner 4y agoYes thank you, a more detailed read of FCPA would indicate it is primarily restricted to bribery (or at least payments that could be interpreted as bribery). But could a non-EU website operator still be fined for non-compliance with GDPR if it were to collect personal data on EU citizens? Do website analytics constitute personal data?
- nannePOPI 4y ago[dead]
- mmarq 4y agoWe should get to a point where tracking requires users to install an app or a browser extension, I’m thinking of something similar to the ads toolbars of the 90s. I shouldn’t have to tell people I don’t want to be spied, nor I should have to install privacy extensions and PiHoles and whatever.
- axg11 4y agoIsn't this a matter of someone developing a browser that implements this? There are a few privacy focused browsers out there. As long as the most popular browser is developed by the company that benefits the most from tracking, there will always be browser-based tracking.
- none_to_remain 4y agoIs anyone maintaining some custom NoScript or anything like that I could use to block GDPR/cookie law popups and such EU nonsense? I'm not even a subject of Brussels
- slock83 4y agoIn my experience, the annoyances list in ublock orogin (and possibly others), which is disabled by default, drastically reduces the amount of such pop-ups. The only remaining ones are unfortunately among the worst, which is to be expected since they went through the trouble to setup anti-adblock measures ...
- deleted 4y ago[deleted]
- stevenjgarner 4y agoWhat I do not understand about GDPR is analytics. If you are operating a website outside the US and EU citizens access that website, my understanding is that applicability of GDPR is limited to only uses where the site is capturing data from EU citizens. If the server statistics include standard analytics (e.g. client IP address, client browser, client screen size, etc), are not those analytics the capture of personal data from EU citizens? In this regard, don't EU visits to all non-EU non-GDPR-compliant websites involve a violation of GDPR simply through accumulation of server analytics? Is there an exclusion for this? Or can any website operator anywhere in the world be fined for non-compliance on this basis?
- XCSme 4y agoI think the law is not well-defined because, as you mentioned, any visit to a country that doesn't provide that same data protection rules should be blocked based on the current law. Also, I still find it weird that the EU (GDPR) laws apply at the client (visitor) rather than at the source (server). The question is: is the server providing a service in EU (sending a webpage) or is the client "going" to a server in the US?