5 ms·
1,741 "informed" consents with one click? GDPR complaint filed
- terabytest 2mo agoIs the issue here a lack of “Reject All” button? Or strictly the number of partners?
- Superleroy 2mo agoI read the complaint and it seems to have nothing to do with the reject all button and is only about transparency and informed consent. They state that you cannot reasonably read all those privacy policies and thus you also cannot give informed consent. At least that is how I understood it
- mschild 2mo agoProbably both. If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.
- Nursie 2mo agoThe issue is that even if you click "Accept" there is no reasonable way to infer that the user has given informed consent, because becoming informed would likely take days or weeks. As such the conditions for data sharing are not met and it is likely to be illegal.
- loeg 2mo ago> becoming informed would likely take days or weeks. Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.
- Barbing 2mo agoA simple diagram of them opening a user’s mouth and cramming 200 logos down our throats would inform pretty well, especially if (this being the greater fantasy) the corresponding opt-in was buried deep at the bottom of a list in an obscure settings menu.
- Nursie 2mo agoI'm not sure I agree that you couldn't become informed about a single one. I think one is probably reasonable. Presumably, if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, then such a thing could be done. I imagine a lot of people would click the “I’m not reading all that” button though. You could even envision a simplified sort of 'tracking declaration' as is done with (for example) insurance products here in Australia, where a sort of statutory precis gives the reader a good, bullet-pointed outline of the policy I would wager that with a well formatted precis like that, it may even be possible to consent to as many as half a dozen 3rd parties. I doubt many people would though, if it was spelled out that blatantly and clearly what it's all about. And isn't that the point? Hide what's really happening in so many walls of text nobody could ever conceivably bother with them? So I think the person filing this suit is correct. The behaviour on show here is an end-run around even the idea of informed consent, and needs to be squashed. (Edit - instead of all these cold GDPR compliance boxes and walls of text, sites should be honest: letting advertisers track you is how we make money, please click yes and we can get paid for your visit”, but of course it’s much more effective just to confuse people into ignorant acquiescence, or try to get people riled up about “stupid gdpr compliance nonsense”)
- troupo 2mo ago> if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, I've now bought two apartments and sold one. The whole process including reading the contract almost in its entirety out loud for both parties, and signing by the parties, and confirmation of the bank took less than an hour. There's almost no service important enough to spend a few hours reading through a contract. And those that are? They should not have contracts of that length. > letting advertisers track you is how we make money, please click yes and we can get paid for your visit” Ads don't require pervasive and invasive tracking. No one needs to store my precise geolocation for 12 years to serve me an ad: https://pbs.twimg.com/media/GTe23o5WwAACyNJ.png?name=orig https://pbs.twimg.com/media/GTe23o5WwAACyNJ.png?name=orig
- swiftcoder 2mo agoIt's the definition of "informed consent". Can I actually go through a couple of thousand 3rd parties and confirm that their policies all conform to my data handling requirements?
- loeg 2mo agoCan you with even a single 3rd party? It's a huge waste of your time.
- deleted 2mo ago[deleted]
- jcul 2mo agoI've seen similar on some android apps I think, where it will ask you if you consent to sharing data with partners or something similar. When you say no there's a huge list of partners you have to disable one by one, it's probably 15 minutes of work to go through them all. I can't think of an example app right now, but usually it's on first install or something like that. Not sure GDPR applies to apps though.
- holsta 2mo ago> Not sure GDPR applies to apps though. GDPR applies to we the people and the organizations who hold our data. Doesn't matter if it's morse code on paper strips. If we can dictate warnings on tobacco packages, we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".
- dwedge 2mo ago> we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit". At least the banners that say "we value your privacy" are honest about it
- Y-bar 2mo agoGDPR absolutely applies to apps, it applies to all manner of electronic and non-electronic means of data collection and processing. The G stands for General, and the EU means it.
- troupo 2mo agoGDPR is a General Data Protection Regulation. It applies to everything. 10 years. It's been in force for 10 years. The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)
- CodesInChaos 2mo agoThere is the ePrivacy directive as well, which mentions cookies (as a representative example), and I think it requires user consent in cases where GDPR doesn't.
- xg15 2mo agoStill wondering how "freely given, informed, specific and unambiguous" is fulfilled by "sure you can opt-out of tracking - by buying a premium subscription. Also, here are our 589 'partners' that all claim legitimate interest" but here we are.
- CalRobert 2mo agoEurope doesn’t enforce the law. Cookie banners are similarly pointless.
- bobim 2mo agoThey are useful as a deterrence system, can't decline in one click? I'm out thanks.
- robin_reala 2mo ago€6.3B cumulative fines says that they’re enforcing the law to at least some extent: https://www.enforcementtracker.com/statistics https://www.enforcementtracker.com/statistics
- CalRobert 2mo agoYet the pointless banners and illegal tracking remains. They do, sometimes, but rarely. And having Ireland's utterly toothless DPC handling so many big tech companies makes it even worse.
- account42 2mo agoYes, letting companies go regulatory agency shopping should not have been allowed. Legal disputes between companies and the customers need to be decided where the customers are.
- consp 2mo agoLegitimate interest does not exist and is a loophole in the law which should be killed. You can challenge it but the authorities who should handle that are grossly underfunded.
- zkmon 2mo agoEvery law is made under some assumptions about the scale of things. For example, judiciary procedures were designed assuming certain number of active cases. Citizen services and bureaucracy around them is designed assuming some amount of work and staff size. Look at the US immigration / green card processes. The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.
- troupo 2mo ago> The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.
- cryptonym 2mo agoYou can't number every limit and corner case. You come with precise terms and give a chance for people to defend their case in court. We'll now see if "thousands of partners" is considered as a good match for "informed consent". Doesn't mean there is a need for review, unless the legislator is not happy with the interpretation that will be provided.
- wyager 2mo agoCan someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?
- timr 2mo agoLikely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe". For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition. You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.
- happymellon 2mo ago> or had an especially conservative corporate counsel And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.
- timr 2mo agoYeah, but again, see the other part of what I wrote -- doing it "right" can be insanely expensive, and so you get an incentive to be conservative.
- happymellon 2mo agoI read what you wrote. Ultimately that is what they are having to do though, it's just costing them twice as much by pretending that being conservative and not actually looking at the problem saved them.
- fuzzy2 2mo agoOh yeah, that combination of fear and lack of knowledge probably plays a big part. I was once involved with creating a privacy policy for a B2B(!) web application. What a farce. In the end, the process was cut short (counsel too expensive and not nearly familiar enough with tech). The resulting document was at least 50 % stuff the app simply does not do.
- andrewstuart2 2mo agoI thought for sure this would be for f1tv.formula1.com but apparently that's only 134 and I thought that was ridiculous.
- troupo 2mo agoThose are rookie numbers. Here's 1498: https://pbs.twimg.com/media/GA5Z-ZgW4AAu1vn?format=jpg&name=medium https://pbs.twimg.com/media/GA5Z-ZgW4AAu1vn?format=jpg&name=... Can't remember where I ran into this.
- jtreitz 2mo agoMy Samsung TV which I bought 8 years ago now suddenly asks me if it's okay they share data with their over 200 partners. They have the nerves to headline this with "protect your privacy". Generally not a big fan of EU policing but I wish somebody sued them over this. > Improving Your Experience and Protecting Your Privacy on Samsung TV Plus > Samsung and our 264 partners use information about you and your device in order to provide, analyse and improve the Samsung TV Plus app. This includes the processing of personal data such as unique IDs for personalised advertising.
- eckelhesten 2mo agoIf I got a dollar for every person suckered into buying Samsung products… But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.
- NetOpWibby 2mo agoExact same setup here. Ideally I'd buy a dumb TV but they don't exist in the modern era.
- brador 2mo agoCan a screen/monitor/TV send data back over HDMI through a connected computer or is that a 1 way connection?
- eckelhesten 2mo agoTechnically yes, hdmi supports transmitting Ethernet. Realistically no.
- stvltvs 2mo agoPutting on tinfoil hat... how do we know it isn't connecting to our neighbors' open WiFi?
- harrouet 2mo agoI see so many sites that pretend that they have 350 /legitimate interest/ partners. Time to crack down on abuses.
- robotswantdata 2mo agoPihole / dns sink hole Or better yet , never connect it to the internet!
- loeg 2mo ago[flagged]
- robin_reala 2mo agoNo, you just hit the deny all button, or wait for GPC to become a legally required thing.
- AndroTux 2mo agoThat’s the most malicious take in the whole thread. Good job!
- CodesInChaos 2mo agoEU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.
- loeg 2mo agoThe rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.
- duskdozer 2mo agoAnd we'd all be even happier with no banners and no tracking.
- account42 2mo agoAnd even happier with no ads.
- cryptonym 2mo agoThe whole world would be even happier if websites stoped this nonsense tracking of every single action bloating a single webpage with 20Mb of JS, connecting to 50+ domains, impacting accessibility, data usage & interactivity.
- cwillu 2mo agoBut how will my PM get his fancy overlay of our website with the heatmap of user clicks and dwells to grossly misinterpret?
- GJim 2mo agoI'm again reminded that a significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic, like yourself, slants towards opposing decent privacy laws.
- 2mo ago
- tomkarho 2mo agoThese single click "informed" consent is akin to a bartender mixing you a drink with 30 different ingredients and hoping you don't notice they include cyanide and rohypnol.
- mzajc 2mo agoI think it's closer to a bartender mixing you a drink with 30 (hundred) different poisons and hoping you get tired of saying "no" every time.
- anon48293 2mo agoJust ban ads already. I don’t want ads. I don’t want to be tracked. I should have the right to never interact with either, unless explicit, informed and single-button-revocable consent is given.
- eproxus 2mo agoCompletely agree, the solution to so many privacy invasions and problems in tech is just because ads are allowed. Would love to see a society where ads are not allowed. Cannot really see any downsides personally, but I’m sure many will claim ”how will companies survive?!” Hard to see it would lead to the collapse of either companies or society, but maybe of capitalism as we know it (which I think given the current state of the world would be such a bad thing).
- HDThoreaun 2mo agoHalf of the people in the world use facebook/ig every month and revealed preferences show they have no interest in banning ads
- anon48293 2mo agoWhat about the other half?
- thinkingemote 2mo agoA surprising number of sites that have consents do not actually do anything apart from set a flag. They are not actually connected to disabling analytics, just connected to the banner itself. It seems like no data privacy activists or automated scans actually look at whether the consents really work or not, just whether they have them!
- sensanaty 2mo agoThe EU just needs to make tracking of any kind full on illegal, especially targeted advertising. I don't give a shit if your business can't survive without invasive tracking of every single facet of your user's existence, you deserve to be shut down if that's your one and only viable business model.
- consentkeep 2mo ago[flagged]