DE version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
51% Positive
Analyzed from 3831 words in the discussion.
Trending Topics
#data#gdpr#consent#banner#cookie#business#cookies#small#need#companies

Discussion (97 Comments)Read Original on HackerNews
It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.
The 996 partners banner is just the piss take that supposedly makes this legal.
I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".
Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.
All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.
Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.
I very much support their ideals and their people-centered mindset.
But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.
If I made millions, sure, pay someone to figure it out.
But I was not going to waste design time early on.
I can't imagine how much this affects small business in Europe.
In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.
https://www.facebook.com/ads/library/report/?source=onboardi...
Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious
successful person → unusual trait And infer: unusual trait → success
The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.
FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.
If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."
Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.
Same goes for data harvesting in tech
Was it a PITA? Sometimes, yes.
Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.
But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.
For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.
Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect
The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.
Shame on the people making stuff like this.
That said I am generally happy with GDPR.
E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.
EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.
1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.
2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.
> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
You do if you want to track your users. Very different thing.
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
Because if it is, I also want to do it that way.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
https://european-union.europa.eu/
The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.
> If the rules are so terrible, why did nobody choose market exit?
Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.
The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.
EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.
essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.
At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.
I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...
It is all working as intended.
The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.
The web has gotten so much uglier as a result of GDPR.
We measure our success based on enquiries, orders and so on, not the number of hits to the website.
I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.
GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.
The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.
The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.
I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"
Nope
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
Try to do marketing ad campaign as small eshop owner in EU!
GDPR is easy to implement once, but it is constantly changing every year. Keeping up with regulations is constant energy drain. And small mistakes are punished by heavy fines (thousands of EUR). If you compare fines Meta is getting by revenue, small business should get maybe 10 euro fine for violations (not thousands).
You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.
We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.
If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .
The profits at all cost mentality is a criminal mentality. Maybe it gets away with not being formally criminal because laws or enforcement are weak (as is the case in the USA) but that doesn't justify the mentality.
If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.
This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.
All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules
Fun fact: the OP blog doesn’t display a GPDR banner.
I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".
Reminds me of 9/11 security theater