> Improving Your Experience and Protecting Your Privacy on Samsung TV Plus
> Samsung and our 264 partners use information about you and your device in order to provide, analyse and improve the Samsung TV Plus app. This includes the processing of personal data such as unique IDs for personalised advertising.
But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.
What happens if you say no?
- deny is the default: one button to deny everything but one accept button for every partner
- respect DO NOT TRACK, and force software/hardware providers to enable it by default
- making payments for non-tracking illegal
- remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
At least that is how I understood it
If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.
As such the conditions for data sharing are not met and it is likely to be illegal.
Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.
The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.
The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.
When you say no there's a huge list of partners you have to disable one by one, it's probably 15 minutes of work to go through them all.
I can't think of an example app right now, but usually it's on first install or something like that. Not sure GDPR applies to apps though.
Having personal information isn't always a bad thing, it would be really annoying if I had to fill out a form with my bank every couple of years to tell them my address, which hasn't changed and is a legitimate interest. Amazon telling everyone that I bought some athletes foot cream is not.
The G stands for General, and the EU means it.
10 years. It's been in force for 10 years. The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)
GDPR applies to we the people and the organizations who hold our data. Doesn't matter if it's morse code on paper strips.
If we can dictate warnings on tobacco packages, we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".
At least the banners that say "we value your privacy" are honest about it
You can usually check the ads.txt file on a website to see which companies are allowed to bid for ad space on there. For example, for dict.cc, the website in question:
The ones labelled "RESELLER" will probably share your data with even more ad companies.
analytics: A/B testing, "if x does user click y"?, unique page visits, etc.
ads: integrating with an ad provider comes with hundreds of trackers, because they want to - know if you bought a product after clicking on an ad - show you targeted ads for shoes after you googled shoes - build a profile of you (age, gender, location, profession) to show relevant ads across different websites
For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.
You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.
And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.
Or, if reforms do pass, they get reversed the next time the counter-party gains enough power in Congress to roll back the progress.
Most of EU laws are "these are sensible defaults and we expect you to behave like adults". As we've seen, digital services are anything but.
---
[0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...
[1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...
They're not even pretending anymore and are just trying everything they can't get consent for again via the "legitimate interest" route.
I was actually wondering if the mandated "refuse everything" button that revokes my consent in bulk (and then conveniently closes the window) also implies I objected to all "legitimate interest" claims, or if that is another malicious compliance trick...
Yes, that's in the law. I you do not click on consent, the default is deny everything, and a button to refuse everything should be easy to access.
> - making payments for non-tracking illegal
In the law too.
> - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
True, this loophole was introduced by UK/US lobbyists at the time if I remember correctly. My (very small, 3 dev) company at the time worked on health data and managed to find itself in the arcanes of Brussels because anything related to PII security was good news for us.
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
This is the courts who can judge that.
The main issue with the gdpr law is local enforcement. It is honestly well written and easy to understand, which is why you have so much legal loopholes, but EU courts are RAI rather than RAW (our fast americanisation is changing that though).
Presumably, if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, then such a thing could be done. I imagine a lot of people would click the “I’m not reading all that” button though.
You could even envision a simplified sort of 'tracking declaration' as is done with (for example) insurance products here in Australia, where a sort of statutory precis gives the reader a good, bullet-pointed outline of the policy
I would wager that with a well formatted precis like that, it may even be possible to consent to as many as half a dozen 3rd parties. I doubt many people would though, if it was spelled out that blatantly and clearly what it's all about.
And isn't that the point? Hide what's really happening in so many walls of text nobody could ever conceivably bother with them?
So I think the person filing this suit is correct. The behaviour on show here is an end-run around even the idea of informed consent, and needs to be squashed.
(Edit - instead of all these cold GDPR compliance boxes and walls of text, sites should be honest: letting advertisers track you is how we make money, please click yes and we can get paid for your visit”, but of course it’s much more effective just to confuse people into ignorant acquiescence, or try to get people riled up about “stupid gdpr compliance nonsense”)