You Know GDPR Is Good Based on Who Hates It(matduggan.com) |
You Know GDPR Is Good Based on Who Hates It(matduggan.com) |
It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.
No one is surprised that anyone is annoyed by the banners. But it doesn’t make sense to be annoyed at the law¹ instead of the perpetrators. If someone is deliberately putting pebbles in your shoes you should get annoyed at the person doing it, not the pebble.
The GDPR doesn’t require websites to have those banners², nor do they require them to be annoying³. That’s a choice the websites make. Every time you are annoyed at the GDPR because of those banners, you have been manipulated by the website to be mad at the wrong thing.
Imagine restaurants are pissing in their soup. This has become so rampant that a law comes out saying that if you pee in soup, you must warn your customers and give them the option for a pee-free soup. Restaurant then start serving you soup but before letting you eat force you to unwrap hundreds of layers of cellophane. You get so mad at it, “I just want to eat my soup, I don’t care about the pee, what a stupid law”. You should instead be mad that they were pissing in your soup in the first place, and when you see a restaurant doing the cellophane shenanigan you should leave in search of another which doesn’t pee in your soup.
¹ Unless you are annoyed that it is too lenient and think there should’ve been no option at all and that data collection should’ve been outright forbidden, not given a “consent” option that is abused.
² You can choose to not disregard people’s privacy.
³ Quite the contrary, the law requires that rejection be as easy as acceptance.
The 996 partners banner is just the piss take that supposedly makes this legal.
What people are missing is that before GDPR the threat of sharing data with 3rd party wasn’t seen as serious by most of the population. GDPR establishes clear rights people have, and a framework for companies to work in this new space, which changed the assumptions people have regarding their own data and privacy, in a positive way. People now in the EU have an explicit concept of consent for the use of personal data. That’s a really big deal
This is where you should apply eng principles. If something adds complexity without solving a problem, start by removing the complexity rather than tweaking
I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".
Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.
All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.
Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.
Same goes for data harvesting in tech
Surveillance capitalism might die or become unprofitable -- that sounds great.
Was it a PITA? Sometimes, yes.
Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.
But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.
For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.
The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.
Shame on the people making stuff like this.
That said I am generally happy with GDPR.
> If the rules are so terrible, why did nobody choose market exit?
Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.
The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.
EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.
essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.
Create a problem, the "dark pattern", and then offer a "solution"
The source for the "solution" is also the source of the original problem
This is one of the various tactics in the SillyCon Valley playbook
Use the "solution" or else suffer the problem
Consent immediately or suffer the cookie banner
Lowbrow, mafia-style persuasion but with cowardly annoyance in place of direct confrontation
I never see any cookie banners when there is no Javascript interpreter. No cookies get through the local forward proxy anyway. But that's not SillyCon Valley's "solution" to the annoyance, it's mine
SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.
Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect
That seems more of a German bureaucracy thing rather than GDPR specifically.
The UK, which does still implement GDPR from its time as a member state, does not require this level of officiousness.
At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.
I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...
It is all working as intended.
The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.
E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.
EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.
You’ll be glad to know that the EU is working on a proposal to do just that. Look for EU Digital Omnibus article 88b.
You’ll also be unsurprised to know that companies like Google are already lobbying hard to prevent it.
The web has gotten so much uglier as a result of GDPR.
We measure our success based on enquiries, orders and so on, not the number of hits to the website.
I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.
GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.
The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.
The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.
the primary goal of anonymizing users, pushed down the throat of otherwise very oblivious service providers (such as your website selling dick enlargement machinery), is just not never going to work.
on the other hand, provider such as telecoms are now, being GDPR-compliant, absolutely in their right to sell the aggregated data. so are rail services, and bus, and everything that touches IDs and alike. even your gov. cheers.
Try to do marketing ad campaign as small eshop owner in EU!
I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules
Fun fact: the OP blog doesn’t display a GPDR banner.
I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".
Reminds me of 9/11 security theater
successful person → unusual trait And infer: unusual trait → success
The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.
FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.
If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."
Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.
Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship.
Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned.
Or mandatory USB-C charge socket. God bless EU regulations!
The GDPR is strictly about data privacy, and it deserves defense on its real merits: it made data collection illegal by default without an explicit legal basis, banned deceptive tracking patterns, and introduced turnover-based fines large enough that tech companies actually had to re-engineer their systems around privacy by design. EU consumer protection directives are great, but it's worth crediting the right ones.
I very much support their ideals and their people-centered mindset.
But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.
If you agree with that meme, you’ve fallen for the manipulative narrative of lobbyists¹. Bottle caps are a massive problem (as is plastic in general) on the environment (you know, the thing we all live in) and the regulation is already having an impact. There will be more regulating the uses of plastic. If you don’t know why the bottle caps are so problematic, you live a privileged life and are being shielded from the reality your fellow human beings have to endure (but will eventually feel the effects just the same).
We don’t fucking need rockets right now, what we need is to stop poisoning ourselves. True progress is not inventing new technology, it’s understanding how to properly use what we have and reject what is harmful.
¹ Which is not a dig on you; we’re all susceptible to be tricked by these massive corporations whose only goal is to extract value from us. I’m on your side.
If I made millions, sure, pay someone to figure it out.
But I was not going to waste design time early on.
I can't imagine how much this affects small business in Europe.
In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.
https://www.facebook.com/ads/library/report/?source=onboardi...
Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
https://commission.europa.eu/resources/europa-web-guide/desi...
> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
You do if you want to track your users. Very different thing.
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
Because if it is, I also want to do it that way.
The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.
I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"
Nope
If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.
This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.
All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
I thought that was not complicated, but then there was that post here a while back where someone asked McDonald's for their data.
It included a vast amount of things that the company had inferred from the data. I hadn't realized that would be in scope, and did some Googling on just what has to be included.
According to a few sites I found, and Google's LLM concurred, it is basically everything I have about them, regardless of if I got it from them, a third party, or produced it internally.
Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them? That should be in the GDPR response (I can redact the names of the rep and supervisor).
I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists. That's supposed to be in the GDPR data, if the sites I found are to be believed.
Heck...if some customer calls to update their credit card and calls the wrong number, and leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data. (If they call customer support and leave such a message it would go to a number handled by the expensive outsourced customer service system, which has voice transcription software that looks for things like that and deals with it, but the internal phone system used by other departments doesn't so if the wrong number went to some random person in some other department it won't have that automated handling of this).
If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer.
I'm hoping the sites I found and the LLM were wrong and it is not this bad.
The power to delete your data with them would actually result in exactly the situation you described, likely without the requester knowing that’s what’ll happen!
One of the greatest achievements of America was killing smoking as a pastime even if that trend is reversing.
He was an asshole who did rich person bullshit to park in handicap parking spaces without consequences, he was also hated by people who were not his competition.
For someone who isn't aware of the scale, seeing "we sell your data to >1000 companies" can be enough to build interest in advocating for privacy laws.
You’re only half right. If you habitually store data and never delete it from those stores, yes, you have to find and provide it. If they’re temporary (voicemail, fixing a specific issue) and you remove it as soon as it’s no longer needed, you’ll be fine.
> It included a vast amount of things that the company had inferred from the data.
If you’ve tied it to that person, it’s in scope. It’s literally part of GDPR.
> Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them?
Possibly but you could argue not because that could be business risk.
> I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists.
No, you have a valid reason to not share that, as long as you remove the PII once you’re done.
> leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data.
If you’re deleting voicemails as you address them you’re fine, you won’t need to include this just because you didn’t get round to deleting it yet.
So in the interest of legitimacy, the EU institutions should really fix that and remove the banners from their sites.
In the end i think Azure got to host of all French health data a year later despite the lobbying. Maybe with how the US look with Trump at the helm it will change (to be clear, it was a really weird lobbying in any case, our project was to test pseudonymation algorithms (and probably others) made by our researchers on our platform before selling them to scaleway or OVH depending on who won the project)
1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.
2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.
In general defining laws technology neutrally is bread and butter of legislation, there are just a lot of misconceptions that laws are about specific techniques.
2) you can easily make a non-intrusive UI for that.
The question is how do you prevent the annoying UX without making overly technology-specific rules. Just adding a do-not-track header does not stop websites from ignoring the header and showing a pop up to ask you if you want to override your default settings.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB).
Yes: I have the privilege of living in a developed 21st century world where I don't need to deal with stuff like this. Proud of it.
I'm well past being told to eat my vegetables because children in Africa are starving.
The solution is to expand the pie for everybody, not to throw our arms up and return to living in caves in harmony with "nature". Technology and progress solve this.
The solution to children in Africa suffering isn’t me living worse or even me beating myself up for “my privilege”.
Are you unfamiliar with the concept of rotating an object?
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
If it wasn't cookies it would be something else.
I know this sounds all lofty and Brussels ivory-tower-ish, but I'm absolutely convinced it's the only sensible way to deal with personal information - even if American companies insist on forcing a new normal of lacking privacy on all of us.
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested.
If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested.
No consent needed.
On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed.
Javascript measuring which sub-parts of the page they lingered on -- consent needed.
Tracking how often they come back without buying anything -- consent needed.
Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED.
See the difference?
GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.
It may very much be, to be honest. The causalities aren't that mysterious.
Billions of people are getting access to information through it.
You mean millions. As in 12 million subscribers.
Which includes people who have it as a backup.
Thats a lot of taxes for a few cities worth of people. Especially since Americans already paid for fibre to be laid to everyone in to US' home until the fund was embezzled.
Not much tax money was spent on it either.
Also, their other posts suggest they are in the US: https://news.ycombinator.com/item?id=49477186
Non-malicious compliance with privacy laws would mean respecting people's privacy.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.
For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.
I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.
If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.
If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.
As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.
Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.
The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.
The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"
https://web.archive.org/web/20190627174442/http://www.hse.go...
https://web.archive.org/web/20200131200512/https://blogs.ec....
[1] https://en.wikipedia.org/wiki/Digi_Communications
On the other hand, SpaceX did receive a lot of money from the state.
And then all the government contracts.
Their entire business plan is based off taxes.
He is the biggest leach on state benefits.
> Not much tax money was spent on it either.
A lot of tax money has been given to him.