It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.
The 996 partners banner is just the piss take that supposedly makes this legal.
This is where you should apply eng principles. If something adds complexity without solving a problem, start by removing the complexity rather than tweaking
For someone who isn't aware of the scale, seeing such numbers can be enough to build interest in advocating for privacy laws.
What people are missing is that before GDPR the threat of sharing data with 3rd party wasn’t seen as serious by most of the population. GDPR establishes clear rights people have, and a framework for companies to work in this new space, which changed the assumptions people have regarding their own data and privacy, in a positive way. People now in the EU have an explicit concept of consent for the use of personal data. That’s a really big deal
I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".
No one is surprised that anyone is annoyed by the banners. But it doesn’t make sense to be annoyed at the law¹ instead of the perpetrators. If someone is deliberately putting pebbles in your shoes you should get annoyed at the person doing it, not the pebble.
The GDPR doesn’t require websites to have those banners², nor do they require them to be annoying³. That’s a choice the websites make. Every time you are annoyed at the GDPR because of those banners, you have been manipulated by the website to be mad at the wrong thing.
Imagine restaurants are pissing in their soup. This has become so rampant that a law comes out saying that if you pee in soup, you must warn your customers and give them the option for a pee-free soup. Restaurant then start serving you soup but before letting you eat force you to unwrap hundreds of layers of cellophane. You get so mad at it, “I just want to eat my soup, I don’t care about the pee, what a stupid law”. You should instead be mad that they were pissing in your soup in the first place, and when you see a restaurant doing the cellophane shenanigan you should leave in search of another which doesn’t pee in your soup.
¹ Unless you are annoyed that it is too lenient and think there should’ve been no option at all and that data collection should’ve been outright forbidden, not given a “consent” option that is abused.
² You can choose to not disregard people’s privacy.
³ Quite the contrary, the law requires that rejection be as easy as acceptance.
Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.
Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.
All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.
Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship.
Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned.
Or mandatory USB-C charge socket. God bless EU regulations!
I very much support their ideals and their people-centered mindset.
But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.
Billions of people are getting access to information through it.
If you agree with that meme, you’ve fallen for the manipulative narrative of lobbyists¹. Bottle caps are a massive problem (as is plastic in general) on the environment (you know, the thing we all live in) and the regulation is already having an impact. There will be more regulating the uses of plastic. If you don’t know why the bottle caps are so problematic, you live a privileged life and are being shielded from the reality your fellow human beings have to endure (but will eventually feel the effects just the same).
We don’t fucking need rockets right now, what we need is to stop poisoning ourselves. True progress is not inventing new technology, it’s understanding how to properly use what we have and reject what is harmful.
¹ Which is not a dig on you; we’re all susceptible to be tricked by these massive corporations whose only goal is to extract value from us. I’m on your side.
Yes: I have the privilege of living in a developed 21st century world where I don't need to deal with stuff like this. Proud of it.
I'm well past being told to eat my vegetables because children in Africa are starving.
The solution is to expand the pie for everybody, not to throw our arms up and return to living in caves in harmony with "nature". Technology and progress solve this.
If I made millions, sure, pay someone to figure it out.
But I was not going to waste design time early on.
I can't imagine how much this affects small business in Europe.
Also, their other posts suggest they are in the US: https://news.ycombinator.com/item?id=49477186
In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.
https://www.facebook.com/ads/library/report/?source=onboardi...
Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious
Same goes for data harvesting in tech
Was it a PITA? Sometimes, yes.
Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.
But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.
For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.
successful person → unusual trait And infer: unusual trait → success
The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.
FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.
If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."
Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.
> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.
I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.
If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.
If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.
As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.
No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.
You do if you want to track your users. Very different thing.
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested.
If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested.
No consent needed.
On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed.
Javascript measuring which sub-parts of the page they lingered on -- consent needed.
Tracking how often they come back without buying anything -- consent needed.
Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED.
See the difference?
GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.
Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.
The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.
The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"
https://web.archive.org/web/20190627174442/http://www.hse.go...
https://web.archive.org/web/20200131200512/https://blogs.ec....
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
Because if it is, I also want to do it that way.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB).
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
https://commission.europa.eu/resources/europa-web-guide/desi...
So in the interest of legitimacy, the EU institutions should really fix that and remove the banners from their sites.
The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.
The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.
Shame on the people making stuff like this.
SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.
That said I am generally happy with GDPR.
> If the rules are so terrible, why did nobody choose market exit?
Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.
The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.
EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.
essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.
Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect
That seems more of a German bureaucracy thing rather than GDPR specifically.
The UK, which does still implement GDPR from its time as a member state, does not require this level of officiousness.
E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.
EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.
You’ll be glad to know that the EU is working on a proposal to do just that. Look for EU Digital Omnibus article 88b.
You’ll also be unsurprised to know that companies like Google are already lobbying hard to prevent it.
1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.
2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.
In general defining laws technology neutrally is bread and butter of legislation, there are just a lot of misconceptions that laws are about specific techniques.
2) you can easily make a non-intrusive UI for that.
At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.
I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...
It is all working as intended.
The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.
The web has gotten so much uglier as a result of GDPR.
We measure our success based on enquiries, orders and so on, not the number of hits to the website.
I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.
GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.
The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.
The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.
I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"
Nope
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
If it wasn't cookies it would be something else.
I know this sounds all lofty and Brussels ivory-tower-ish, but I'm absolutely convinced it's the only sensible way to deal with personal information - even if American companies insist on forcing a new normal of lacking privacy on all of us.
Try to do marketing ad campaign as small eshop owner in EU!
GDPR is easy to implement once, but it is constantly changing every year. Keeping up with regulations is constant energy drain. And small mistakes are punished by heavy fines (thousands of EUR). If you compare fines Meta is getting by revenue, small business should get maybe 10 euro fine for violations (not thousands).
You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.
We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.
If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .
> You also have to keep up with other regulations; that’s the price of doing business
Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)?
Keep on mind I get lower salary than garbage man!
> they absolutely value if you’ve tried your
I do not "store data",. I have a free gmail account, I do not have a "data retention policy". But by GDPR i have to follow the same rules a s facebook!
> they absolutely value if you’ve tried your best....
My absolute best is to check once every a few years. That is not going to fly with goverment!
The only real help I got in past 5 years was AI! It can explain new changes, and audit my workflow, without paying 100x my salary to some consultant!
You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality here, right? Or do you consider filing your taxes as unpaid regulatory bullshit work too?
> Keep on mind I get lower salary than garbage man!
It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite, but if you don’t have a reasonably good income from your company, why do you put up with all the hassle in the first place..?
> I do not "store data",.
Sure you do, if you sell anything. You need to know where to ship stuff, customers contact you, pay you, all that. And as your customer, I don’t want you to store that longer than necessary or sell it to someone else.
But I do need dedicated comliance officer! The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!
And if do notmp comoly goverment will fine me to oblivion!
> So unpaid doesn’t really match the reality here, right?
It absolutely matches the reality. You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?
Luckily AI can now automate this shit, so now I spend cents instead of dozens hours of labour!
> It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite,
Because I have social responsibility to make some rare stuff available, as you would put it! But EU is not making it any easier!
> If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best
So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!
There is no compliance officer required by law, at least not in any regulation introduced by the EU.
> The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!
If you have more than 250 employees, you really should have both a higher salary than a garbage man and be able to afford someone to take care of your compliance duties.
> You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?
I don't expect anything. You run a business. Anything you do related to that business is your own working time, just as anything I do in regard to compliance or data protection is of course billed working time. You file your taxes in your working time, you pay your bills in your working time, and of course you also read up on laws you need to comply to in your working time. Those are table stakes for doing business everywhere. Do you think American companies don't have to comply to regulations?
> Because I have social responsibility to make some rare stuff available, as you would put it!
All props to you for making that choice, then, but it's still your decision to have a company and that means you have to abide the law.
> But EU is not making it any easier!
The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of, because you never cared to look.
Just because you have a responsibility to think about and extra work to enable handling data your customers entrust you with carefully doesn't invalidate all of these efforts.
> So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!
You should try to think about protecting the personal data you handle responsibly and be ready to demonstrate that when somebody asks. Again, I am in the same spot and have been for years. This is doable.
> And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?
You were very clear as a business owner i have tons of extra responsibilities. I should go extra mile to "demonstrate". I am single guy, with a few houndred euro a month (lower salary than garbage man), and I have the same obligations as company of 249 people!
> There is no compliance officer required by law
> and be ready to demonstrate that when
> they absolutely value if you’ve tried your best as opposed to not caring at all;
Again, most companies hire an office to "demonstrate best efford" and to offload personal responsibility from company owner. This still applies to one person business!
> The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of
Are you even in EU my friend? I was unable to sell into germany becauee of some local BS. Every country has their own taxes, localization and regulations, there is no single market! EU has several currencies! EU does not protect from foreign traders, it pushes contaminated chicken from outside EU that contains salmonela!
Public infrastructure, education and art is responsibility of national goverment, EU sponsors maybe 2% of that!
> just as anything I do in regard to compliance or data protection is of course billed working time
Here is the core problem! You are not eshop owner! You are consultant who directly benefits from more regulations!!!
Of course you will push for more regulations and more "social responsibility"!
Luckily normal people can replace consultants with AI!
The profits at all cost mentality is a criminal mentality. Maybe it gets away with not being formally criminal because laws or enforcement are weak (as is the case in the USA) but that doesn't justify the mentality.
Exactly! But there is a fixed cost of doing a right think! It is much easier for facebook to do the "right think", than some single guy with no employees!
> just like buying drywall.
I do not have a dry wall. Houses in EU usually do not have a dry wall.
No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that.
If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if you’re informed they changed.
For store analytics, your cookie banner covers you, the major players all integrate into standard tools, and they keep their compliance up to date, so you’re fine there.
Small mistakes are very much not punished. Your country’s Data Commissioner equivalent will want to see you try to be compliant first. You’re only going to get put out of business on a first offence if you’re taking the piss. I guarantee any example you provide me as evidence will be exactly that, but feel free to try.
I am not major player! I do not have dedicated team of people to keep "compliance up to date".
> if you’re informed they changed
Yet more extra work!
> see you try to be compliant first
Sounds like work for extra GDPR officer! I do not have that kind of money!
> Yet more extra work!
If “customer asks me to update my records on them, so I do it,” is too much work then you really shouldn’t be in the business that requires it.
> Sounds like work for extra GDPR officer!
Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”
Seriously, all your answers here tell me you’re trying to do some shady shit and not even making money from it. If you were a simple retailer, as your original post implied, you would not be worried about the complexity of handling GDPR.
I have my own eshop, i do not use "major player"! Too expensive.
> Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”
And than you get different offical, with different opinion. Their advice have same weight as weather forecast!
If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.
This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.
All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules
Fun fact: the OP blog doesn’t display a GPDR banner.
I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".
Reminds me of 9/11 security theater