Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Every law is made under some assumptions about the scale of things. For example, judiciary procedures were designed assuming certain number of active cases. Citizen services and bureaucracy around them is designed assuming some amount of work and staff size. Look at the US immigration / green card processes.

    The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.

  • > The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click.

    The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.

  • You can't number every limit and corner case. You come with precise terms and give a chance for people to defend their case in court.

    We'll now see if "thousands of partners" is considered as a good match for "informed consent". Doesn't mean there is a need for review, unless the legislator is not happy with the interpretation that will be provided.

  • I thought for sure this would be for f1tv.formula1.com but apparently that's only 134 and I thought that was ridiculous.
  • Those are rookie numbers. Here's 1498: https://pbs.twimg.com/media/GA5Z-ZgW4AAu1vn?format=jpg&name=... Can't remember where I ran into this.
  • Is the issue here a lack of “Reject All” button? Or strictly the number of partners?
  • It's the definition of "informed consent". Can I actually go through a couple of thousand 3rd parties and confirm that their policies all conform to my data handling requirements?
  • Probably both.

    If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.

  • The issue is that even if you click "Accept" there is no reasonable way to infer that the user has given informed consent, because becoming informed would likely take days or weeks.

    As such the conditions for data sharing are not met and it is likely to be illegal.

  • I read the complaint and it seems to have nothing to do with the reject all button and is only about transparency and informed consent. They state that you cannot reasonably read all those privacy policies and thus you also cannot give informed consent.

    At least that is how I understood it

  • Can someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?
  • Advertisement.
  • Likely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe".

    For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.

    You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.

    by timr
  • two main sources

    analytics: A/B testing, "if x does user click y"?, unique page visits, etc.

    ads: integrating with an ad provider comes with hundreds of trackers, because they want to - know if you bought a product after clicking on an ad - show you targeted ads for shoes after you googled shoes - build a profile of you (age, gender, location, profession) to show relevant ads across different websites

  • I am one of those.

    It generally goes like this:

    When we launch a site it is seldom more than perhaps Hotjar, Google Analytics, and two-three other services connected.

    And then through the years product managers and other stakeholders gets sold on adding LinkedIn, Instagram, Meta, and so on. So we add those.

    Next a specific service ”to better track the sales funnel from in-store salespeople to the web” gets added. Then another ”analyse the data quality versus bounce rate” tracker gets added. And so on.

    Before long the developers have streamlined the process of adding new scripts/analytics/trackers that editors can add them on their own, and that is when the floodgates open.

  • When you try to maximize ad revenue, you add multiple advertising SDKs to your website, each of which can often do live bidding with hundreds of ad/data brokers

    You can usually check the ads.txt file on a website to see which companies are allowed to bid for ad space on there. For example, for dict.cc, the website in question:

    https://dict.cc/ads.txt

    The ones labelled "RESELLER" will probably share your data with even more ad companies.

  • EU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.
  • The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.
    by loeg
  • I see so many sites that pretend that they have 350 /legitimate interest/ partners. Time to crack down on abuses.
  • A surprising number of sites that have consents do not actually do anything apart from set a flag.

    They are not actually connected to disabling analytics, just connected to the banner itself.

    It seems like no data privacy activists or automated scans actually look at whether the consents really work or not, just whether they have them!

  • These single click "informed" consent is akin to a bartender mixing you a drink with 30 different ingredients and hoping you don't notice they include cyanide and rohypnol.
  • I think it's closer to a bartender mixing you a drink with 30 (hundred) different poisons and hoping you get tired of saying "no" every time.
  • Just ban ads already. I don’t want ads. I don’t want to be tracked. I should have the right to never interact with either, unless explicit, informed and single-button-revocable consent is given.
  • Completely agree, the solution to so many privacy invasions and problems in tech is just because ads are allowed.

    Would love to see a society where ads are not allowed. Cannot really see any downsides personally, but I’m sure many will claim ”how will companies survive?!” Hard to see it would lead to the collapse of either companies or society, but maybe of capitalism as we know it (which I think given the current state of the world would be such a bad thing).

  • Half of the people in the world use facebook/ig every month and revealed preferences show they have no interest in banning ads
  • The EU just needs to make tracking of any kind full on illegal, especially targeted advertising. I don't give a shit if your business can't survive without invasive tracking of every single facet of your user's existence, you deserve to be shut down if that's your one and only viable business model.
  • Still wondering how "freely given, informed, specific and unambiguous" is fulfilled by "sure you can opt-out of tracking - by buying a premium subscription. Also, here are our 589 'partners' that all claim legitimate interest" but here we are.
    by xg15
  • Europe doesn’t enforce the law. Cookie banners are similarly pointless.
  • noyb calls these schemes "Pay or Okay"[0] and has filed complaints[1]. However, as far as I can tell no one has been forced by a court to stop.

    ---

    [0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...

    [1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...

  • Legitimate interest does not exist and is a loophole in the law which should be killed. You can challenge it but the authorities who should handle that are grossly underfunded.