9 ms·
The article title is "Is Google reCAPTCHA GDPR Compliant?" And its a good point — broad data collection has always attracted the mire of European regulators, a
by nness 3y ago
The article title is "Is Google reCAPTCHA GDPR Compliant?"
And its a good point — broad data collection has always attracted the mire of European regulators, and in the decision they state that they find that reCaptcha serves as both a security and analytics tool (due to its broad data capture.) I can't argue with that definition.
The solution, for Google, is to only conduct telemetry after the user has authorised that telemetry, allowing reCaptcha to function without the data collection consent. They already have such functionality in Google Analytics, but arguably, might be less valuable for Google without that data.
For the businesses using reCaptcha, its a problem. The article makes a fair point that you can't use the service if the user declines consent. But it is a reminder that any business operating in the EU at this scale must incorporate a data privacy specialist into their requirements gathering and review processes. It's just the price of the ticket to play in the EU.
- miohtama 3y agoYou can argue the data collection is legit and does not need the user consent, because it is needed in order to perform the core function to separate bots from humans. Thus, no special consent is needed. The different question is that if Google uses this data for purposes it is not intended. In this case the service might be still GDPR compliant from the website implementor point of view, but Google would be doing fraud by breaking their Terms of Service how the data is handled.
- croes 3y agoIf a service doesn't work without respecting user rights, the service can't be used. What's next? Capture a picture of your webcam to check if a real person is sitting in front of the PC?
- mozman 3y agoThis is already happening, with some remote working platforms requiring the camera on during working hours Twitter also requires the employee to be in a dedicated room with a door that closes. At least they used to.
- manmal 3y agoSome KYC processes in the EU (and likely elsewhere) do involve a webcam interview with a 3rd party who checks the customer‘s face and passport.
- krzyk 3y agoThe question is also, why separate humans from bots? It makes creating useful scripts harder, doesn't it fall into "fair use" case which in EU is enforced even in software where you can modify it to be able to run it on your platform.
- dageshi 3y agoTo prevent or at least cut down on spam? Pretty much the entire reason captcha systems were created in the first place and an entirely legitimate reason?
- fkyoureadthedoc 3y agoIn addition to spam, preventing bots from buying up all the GPUs and PS5s in the recent past would have been nice.
- pph 3y agoThough in the end you're the one clicking busses and bikes and bridges and busses again and when you're through that charade, everything is gone anyway because the bots were faster/better at that..
- miohtama 3y agoIt is up to the website owner to decide how they want to distribute the content, not the reader. What you see as fair is often not fair from the website owner point of view. If you disagree with this you are always free to create a competing business without such captcha limitations for bots, and put your money where your mouth is.
- mozman 3y agoThink about why the bots exist - it's almost always data theft or other schemes to abuse your API to profit. Taking money from your pocket.
- rypskar 3y ago>>because it is needed in order to perform the core function to separate bots from humans The core function for most sites using recaptcha is not to separate bots from humans, so a consent is needed before sending data to a 3rd party not related to the core functions of the site or app
- jeroenhd 3y agoThis does seem like a good legitimate use case. However, if Google transfers the data collected to its American servers or daughter companies, that would still make for a massive GDPR violation, both for Google for breaking the law and, if the situation does not get resolved, possibly for the companies using Google's services while it knowingly violates the law.
- cassianoleal 3y ago> You can argue the data collection is legit and does not need the user consent, because it is needed in order to perform the core function to separate bots from humans. You would have a hard time arguing that. The core function to separate bots from humans is done by requiring the user to identify certain images. The only data that needs to be "collected" (and even that doesn't need to be kept) is whether they clicked the correct squares.
- jefftk 3y agoThat is not most of how it identifies bot traffic. The order you click them, how quickly you click, and where within each square you click for all ways humans and computers can be different. But the real work is not about your interaction at all: this is how the invisible version can perform almost as well as the one where you click things. This involves comparing information about your computer's JavaScript environment with what they have seen elsewhere, and if you are running a bot farm it's pretty hard to keep your statistical distribution for all of these different attributes from looking odd.
- cassianoleal 3y ago> how the invisible version can perform almost as well as the one where you click things I don't think it does for me. I run most websites in temporary containers, I do a lot of tracker blocking on DNS, uBo, etc., I clean cookies frequently. Either those CAPTCHAs are really bad and are considering me human when they shouldn't, or all those things you mentioned are not necessary for their core functionality.
- jefftk 3y agoSeveral of the non-interactive signals would still pass through in those sorts of situations. I don't know exactly what reCAPTCHA collects, but if you look at something like https://amiunique.org/fingerprint https://amiunique.org/fingerprint you can get a similar idea of what's possible.
- 3y ago
- hnbad 3y ago> But it is a reminder that any business operating in the EU at this scale must incorporate a data privacy specialist into their requirements gathering and review processes. It's just the price of the ticket to play in the EU. This sounds very American. You don't need a data privacy specialist to operate in the EU. You need to develop with privacy first by design. Treat all PII as radioactive. Literally. Yes, if you need to bolt this onto existing US software to make it "compliant", you're screwed and you'll need to call in a containment team like when you find radioactive cargo in your business that is not normally expected to handle it. A lot of times topics like GDPR and privacy are brought up on HN I'm seeing comments that act like it's black magic. It really isn't. It's trivial to be "good enough" as far as legislation is concerned. The problem is just that over the past decades and especially in the US we've seen myriads of online services sprout up that now often seem integral but were built with a complete disregard for privacy and now need to either be retrofitted or somehow contained to become compliant. It's like finding out paint is radioactive after it has been marketed for decades with no regulation or oversight. Internet companies have been playing it fast and loose with privacy well past the point that people started pointing out it's a (ethical if not legal yet) problem. That is now coming back to bite them. I'm okay with that. It's just a shame so many businesses are caught in the crossfire because those companies have also tried their best to make themselves integral and unavoidable. Good luck trying to migrate away from AWS/Azure/GCP for example.
- mbork_pl 3y ago> It's trivial to be "good enough" as far as legislation is concerned. I'd be very interested to read any tutorials/howtos/faqs/etc. about that. I might be tempted to create a (very small) side SaaS-type project (and I'm located in Europe), and the main reason I haven't done it yet is that GDPR compliance looks really, really scary to me.
- mozman 3y agoBeing compliant with regulations such as the GDPR is expensive. Lawyers, security, and annual third party testing. I don't profit off EU users so I block all non-USA traffic and avoid the issue entirely.
- jdietrich 3y agoIt's almost certainly possible to defend the use of a reCAPTCHA-like tool without user consent under article 6 para 1(f) (legitimate interests). My concern with using reCAPTCHA would be the track record of Google - they have a long history of testing the boundaries of data protection law and accepting fines as a cost of doing business. Google don't appear to even mention GDPR in the marketing materials or docs for reCAPTCHA; they do claim that reCAPTCHA Enterprise (a separate, paid-for product) can be GDPR compliant, but I'd take that with a big pinch of salt. Competing CAPCHA services make much stronger claims regarding GDPR compliance and are much more transparent about how the service uses personal information.