Europe is drawing fresh battle lines around the ethics of big data(techcrunch.com)
techcrunch.com
Europe is drawing fresh battle lines around the ethics of big data
https://techcrunch.com/2018/10/03/europe-is-drawing-fresh-battle-lines-around-the-ethics-of-big-data/
11 comments
What is the mechanics by which GDPR is enforced against companies that are US based? Like, you live in the US, your website is blatantly non-GDPR-compliant, you get a court summons from Europe, and ignore it, and then a bill for a fine, and you ignore that too, what happens?
Do they force European ISP's to blackhole traffic to your website's DNS / IP if you don't comply? If you're hosted on AWS, do the European authorities make Amazon an offer they can't refuse: Either Amazon takes down your GDPR-violating site, or every Amazon package everywhere in Europe becomes illegal? Can they force your bank to disgorge the fine directly from your bank account without your consent (e.g. by threatening to cut the bank off from any ability to legally transact with anyone anywhere in Europe)? Can they get an extradition warrant and have US police arrest you and send you to stand trial in Europe? If your company's CEO travels to Europe on vacation, does he risk having European police waiting to handcuff him as soon as he steps off the plane?
Do they force European ISP's to blackhole traffic to your website's DNS / IP if you don't comply? If you're hosted on AWS, do the European authorities make Amazon an offer they can't refuse: Either Amazon takes down your GDPR-violating site, or every Amazon package everywhere in Europe becomes illegal? Can they force your bank to disgorge the fine directly from your bank account without your consent (e.g. by threatening to cut the bank off from any ability to legally transact with anyone anywhere in Europe)? Can they get an extradition warrant and have US police arrest you and send you to stand trial in Europe? If your company's CEO travels to Europe on vacation, does he risk having European police waiting to handcuff him as soon as he steps off the plane?
Nothing of that sorts, but: The GDPR applies only to non-EU organizations when they specifically target people in the EU, e.g. local currency payment, shipment to the EU, local support hotline. This usually requires contracting services from EU companies. And while the violating company can ignore the legislation, their service providers might be fully liable for any damage in the chain, caused by gross negligence.
I think you need to have a European office. The issue is that many do - if not to have a legit satellite office, then because they moved their "official" HQs to Ireland to participate in tax shenanigans.
[deleted]
And yay to the Europeans! How long has the tech world complained, not entirely earnestly, that the ad-financed, private surveillance internet is broken? What has happened so far?
Sometimes a bit of well-placed regulation, which pretty clearly separates the ethical from the unethical in general and understandable terms can go a long way in getting action rather than just hand-wringing.
Those unethical things you are doing? Guess what, they're now illegal. So go figure out a different business model. It's not optional.
Sometimes a bit of well-placed regulation, which pretty clearly separates the ethical from the unethical in general and understandable terms can go a long way in getting action rather than just hand-wringing.
Those unethical things you are doing? Guess what, they're now illegal. So go figure out a different business model. It's not optional.
It's good to keep in mind that:
"big data" != "privacy sensitive data"
by definition.
"big data" != "privacy sensitive data"
by definition.
I'm a bit confused by your definition.
What if the data becomes privacy sensitive after big data methods are applied to it? Does your comment say it isn't possible or it's not big data when that happens?
What if the data becomes privacy sensitive after big data methods are applied to it? Does your comment say it isn't possible or it's not big data when that happens?
It's not a definition. I'm sorry, I should have said "per definition" instead of "by definition".
Slightly on topic, afaik, techcrunch does not adhere to GDPR rules. It forces me to consent to ads and ad tracking while denying me the option to withheld my consent.
I have avoided them for a few months for this exact reason.
I think once the different data authorities kick into action in Europe, many companies will get a nasty surprise.
I think once the different data authorities kick into action in Europe, many companies will get a nasty surprise.
It doesn't force you to anything unless you click OK. And even then you can manage your preferences then with Oath.
It forces you to accept cookies that aren't necessary for the functioning of the site to view the content.
According to the GDPR, you can't do that.
According to the GDPR, you can't do that.
I don't know where this misconception comes from.
Consent is totally different from contract - and both are part of reasons under the GDPR to use private data.
True, consent requires necessity, but contract is wide open. When you click accept you aren't consenting, you are (theoretically) forming a contract, not consenting.
Consent is totally different from contract - and both are part of reasons under the GDPR to use private data.
True, consent requires necessity, but contract is wide open. When you click accept you aren't consenting, you are (theoretically) forming a contract, not consenting.
> you are (theoretically) forming a contract, not consenting.
How is forming a contract different from consenting? Do you mean to imply that a contract can be formed without consenting to the contract terms?
The GDPR does allow processing if "[it] is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract" ( https://gdpr-info.eu/art-6-gdpr/ ), but if you want to argue that tracking is necessary to fulfill the contractual obligation to display personalized ads, then first you'd need to get consent for that contract.
How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/ , which says e.g.: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
So is the contract with TechCrunch about reading articles or about looking at ads? And is the reading of articles conditional on the ads?
How is forming a contract different from consenting? Do you mean to imply that a contract can be formed without consenting to the contract terms?
The GDPR does allow processing if "[it] is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract" ( https://gdpr-info.eu/art-6-gdpr/ ), but if you want to argue that tracking is necessary to fulfill the contractual obligation to display personalized ads, then first you'd need to get consent for that contract.
How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/ , which says e.g.: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
So is the contract with TechCrunch about reading articles or about looking at ads? And is the reading of articles conditional on the ads?
GDPR doesn't change contract law - they're orthogonal. It is true that in the everyday meaning of the word "consent", you would "consent" to a contract, but that is not at all how it is being used in the GDPR - the consent is to the one-sided, without consideration use of your private information. It has nothing to do with consenting to anything else, whether the formation of a contract or the shaving of your dog.
While I applaud you going to the source, your reference: "How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/" does not mean what you think it means. It is simply a specific callout to emphasize the "freely given" aspect of consent (and NOT contracts) and remind enforcers that refusing to perform or taking some out from performing a contract should be considered undue pressure to get consent and therefore not "freely given". For instance, an extreme example would be if, after you ordered and paid for a pizza, and after I agreed to make and deliver you that pizza, I subsequently threaten to breach that pizza delivery contract if you don't "consent" to give me a complete list of movies you've watched this week. ALthough we do have a contract, we're not forming a new movie-history contract because I'm not offering anything for it or agreeing to do anything. I'm just using that pre-existing contractual relationship between us to threaten you into something that you may not want to do. They're completely separate concepts.
Note the phrase "inter alia" which means "among other things", which is a signal from the authors that this is not the only consideration on "freely giving" consent. It has nothing to do with consenting to form a contract. Note also the word "performance" as it relates to a contract, which is completely distinct from "formation" of a contract.
Furthermore, you've (theoretically) been forming contracts with these websites every time you visit them and accept their ToS and privacy policies and whatever else you click "OK" on - just go read them. They restrict you from many things that you could possibly do (reverse engineering, automated scraping, etc) in consideration for serving you up the content. GDPR is just another line item to add into that list for you to accept in the (theoretical) contract.
Lastly, I keep saying "theoretical" because at least in the US, I'm not aware of a direct case on the topic of whether website ToS are actually enforceable. There's a click-wrap case that is close, but other than that....
While I applaud you going to the source, your reference: "How to get that consent is outlined in https://gdpr-info.eu/art-7-gdpr/" does not mean what you think it means. It is simply a specific callout to emphasize the "freely given" aspect of consent (and NOT contracts) and remind enforcers that refusing to perform or taking some out from performing a contract should be considered undue pressure to get consent and therefore not "freely given". For instance, an extreme example would be if, after you ordered and paid for a pizza, and after I agreed to make and deliver you that pizza, I subsequently threaten to breach that pizza delivery contract if you don't "consent" to give me a complete list of movies you've watched this week. ALthough we do have a contract, we're not forming a new movie-history contract because I'm not offering anything for it or agreeing to do anything. I'm just using that pre-existing contractual relationship between us to threaten you into something that you may not want to do. They're completely separate concepts.
Note the phrase "inter alia" which means "among other things", which is a signal from the authors that this is not the only consideration on "freely giving" consent. It has nothing to do with consenting to form a contract. Note also the word "performance" as it relates to a contract, which is completely distinct from "formation" of a contract.
Furthermore, you've (theoretically) been forming contracts with these websites every time you visit them and accept their ToS and privacy policies and whatever else you click "OK" on - just go read them. They restrict you from many things that you could possibly do (reverse engineering, automated scraping, etc) in consideration for serving you up the content. GDPR is just another line item to add into that list for you to accept in the (theoretical) contract.
Lastly, I keep saying "theoretical" because at least in the US, I'm not aware of a direct case on the topic of whether website ToS are actually enforceable. There's a click-wrap case that is close, but other than that....
[deleted]
Again, Techcrunch doesn't force you to accept anything. They aren't obliged to show you any content they don't want to show you. Now they propose you accept tracking by the means of cookies in order to access their content and the purpose of those cookies is clearly stated: advertising. It's also clearly stated who has access to this data. It's up to you to decide whether it's worthy or not.
It'd be different if there was a cookie they didn't warn you about and isn't needed to view the content.
> It forces you to accept cookies that aren't necessary for the functioning of the site to view the content.
So, no. That's not what's happening here.
It'd be different if there was a cookie they didn't warn you about and isn't needed to view the content.
> It forces you to accept cookies that aren't necessary for the functioning of the site to view the content.
So, no. That's not what's happening here.
The law pretty much rules out advertising as a valid reason, and that they can't discriminate on showing content based on opting out of the non-valid reasons (like ads).
Excuse my ignorance, but I'm interpreting this to mean that under GDPR users should be able to opt out of cookies and still view the content?
That doesn't seem right. Shouldn't I, the creator, be able to say "consent to having cookies or don't use my site?"
That doesn't seem right. Shouldn't I, the creator, be able to say "consent to having cookies or don't use my site?"
Some US newspaper do this, block EU access, What people criticize in this case is where the site does not block us EU citizen because they want to track us, so they kinda implement GDPR by using the worse UX possible that probably is illegal.
If you want to say that they need the ads to function then they should not provide the convoluted way to decline tracking from 30+ trackers but just block us.
What we want is put a big Decline button near the Accept button, or put the full list of trackers directly on the popup and not send me to a Privacy Policy or a settings/configuration page. But this sites want it all, they want the EU readers and also their data and user the bad UX to make you just accept.
I just close the tab, I do not bother with workarounds.
If you want to say that they need the ads to function then they should not provide the convoluted way to decline tracking from 30+ trackers but just block us.
What we want is put a big Decline button near the Accept button, or put the full list of trackers directly on the popup and not send me to a Privacy Policy or a settings/configuration page. But this sites want it all, they want the EU readers and also their data and user the bad UX to make you just accept.
I just close the tab, I do not bother with workarounds.
Shouldn't I, the creator, be able to say "consent to having cookies or don't use my site?"
No, especially not if you're a monolopoly like Facebook or Google. For non - monopolistic sites the GDPR encourages other monetization business models such as subscriptions instead of collecting and then profiling user data.
No, especially not if you're a monolopoly like Facebook or Google. For non - monopolistic sites the GDPR encourages other monetization business models such as subscriptions instead of collecting and then profiling user data.
Facebook and Google are not monopolies. There are good and plentiful alternatives to both.
At any rate, seems like GPDR punishes the freemium model which in turn punishes the poor. If I make my site subscription only then I either have to have the subscribers subsidize the free users, or bar non-paying users from my site...
At any rate, seems like GPDR punishes the freemium model which in turn punishes the poor. If I make my site subscription only then I either have to have the subscribers subsidize the free users, or bar non-paying users from my site...
Or you might have the affluent subsidize the poor. Or come up with something entirely new. And they are monopolies in that between them they are advertising on the internet. Also using social media that is like a Facebook property in function but isn't Facebook places the user into a social media desert. Gmail in its domain is similar.
That's a moral argument, not a legal argument. GDPR codifies through law that you are unable to, legally.
That makes about as much sense (to me) as:
"Fill out this survey and you can have a candy bar"
"Nope, I won't fill out the survey but I'll still take the candy bar"
"Fill out this survey and you can have a candy bar"
"Nope, I won't fill out the survey but I'll still take the candy bar"
Fill out this survey, while I surreptitiously inject this GPS tracker under your skin, and you can have a candy bar.
Don't mind you noting down I stopped by, or these product posters you have up, but I'd rather not have that embedded tracker, thanks.
Don't track you? Already jabbed you, LOL...
And so the law stepped in.
Don't mind you noting down I stopped by, or these product posters you have up, but I'd rather not have that embedded tracker, thanks.
Don't track you? Already jabbed you, LOL...
And so the law stepped in.
Yeah but now the law creates the opposite problem:
Me: Let me serve you targeted ads and you can stream this video you want to watch, deal?
You: Nope, I'm just going to stream your video without the ads, LOL
Me: That's stealing my bandwidth
You: Nope, the EU made it legal so it's not stealing, LOL
Me: withdraws from EU
Me: Let me serve you targeted ads and you can stream this video you want to watch, deal?
You: Nope, I'm just going to stream your video without the ads, LOL
Me: That's stealing my bandwidth
You: Nope, the EU made it legal so it's not stealing, LOL
Me: withdraws from EU
I cannot imagine being so enmeshed in the world of targeted advertising that I would care about this analogy.
The point is, it's stealing to forego the targeted ads in order to consume the content anyway.
The fair thing to do would be:
"I don't consent to targeted ads, so I'm clicking the back button and using an alternative"
Not:
"I don't consent to targeted ads, so I'm opting out of them and by the way, you get to foot the bill for whatever I decide to do next"
The fair thing to do would be:
"I don't consent to targeted ads, so I'm clicking the back button and using an alternative"
Not:
"I don't consent to targeted ads, so I'm opting out of them and by the way, you get to foot the bill for whatever I decide to do next"
You can use advertisements. You can even use targeted advertisements if you're halfway smart.
What you can't use is targeted advertisement where the targeting is based on tracking.
If your business model absolutely must resort to tracking users to be successful, it's probably best and easiest to withdraw from the EU market.
What you can't use is targeted advertisement where the targeting is based on tracking.
If your business model absolutely must resort to tracking users to be successful, it's probably best and easiest to withdraw from the EU market.
GDPR recital 43.2 establishes that you may not make provision of a service conditional upon someone granting consent for processing of personal data if the personal data is not required to provide the service.
> if the personal data is not required to provide the service
I guess TechCrunch would argue the tracking is required to enable the ad rates that pay the writers who write the content.
I guess TechCrunch would argue the tracking is required to enable the ad rates that pay the writers who write the content.
If they can make that argument, then they do not require consent. They can collect information on the basis of Article 6 1.f:
>Processing shall be lawful only if and to the extent that at least one of the following applies:
>(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Since they're not doing that, either they haven't read the law, or they have and don't agree with your interpretation.
>Processing shall be lawful only if and to the extent that at least one of the following applies:
>(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Since they're not doing that, either they haven't read the law, or they have and don't agree with your interpretation.
That is not what is meant in the GDPR writeup. I think we can all agree that it's clearly aimed at whether something is technically required for a service, as for example a cookie is required for a login (not the best of examples, but eh).
> I think we can all agree
There are twenty-eight countries whose regulators and courts will interpret this law differently. I don’t think we can say “we can all agree” about anything at this point.
There are twenty-eight countries whose regulators and courts will interpret this law differently. I don’t think we can say “we can all agree” about anything at this point.
Yeah. I am waiting for the first trial to see how companies are going to defend the "ads are needed to finance the content" argument.
Wait a minute. I am thinking of a webserver that would make each visitor/client pay a fee to maintain the connection (or the socket). The server would be connected to a feedback infrastructure (a service provided by another company) that would only allow individual connections to be maintained if it's fed with data from tracking.
So the tracking would actually technically be needed to provide the service (the connection) if the company hosting the content chooses to use that web server service from that other company. Eh.
Wait a minute. I am thinking of a webserver that would make each visitor/client pay a fee to maintain the connection (or the socket). The server would be connected to a feedback infrastructure (a service provided by another company) that would only allow individual connections to be maintained if it's fed with data from tracking.
So the tracking would actually technically be needed to provide the service (the connection) if the company hosting the content chooses to use that web server service from that other company. Eh.
Have you tried managing your preferences? It's a circular hellscape.
Indeed, it is. That's a problem because giving consent should be as easy as withdrawing it and right now it's slow, clunky and I am pretty sure it's also unreliable.
I don't allow cookies, unless I whitelisted your website.
Presumably that's because techcrunch doesn't operate in the EU and aren't bound by their regulations.
If Techcrunch/Oath is selling/collecting Europeans' data, they are bound by the GDPR.
Whether they have enough operations in the EU for the EU to enforce it is another matter.
Whether they have enough operations in the EU for the EU to enforce it is another matter.
That is not true at all. I'd encourage you to generally make sure you understand an issue before making pronouncements like this.
https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...
> The organization would have to target a data subject in an EU country. Generic marketing doesn’t count. For example, a Dutch user who Googles and finds an English-language webpage written for U.S. consumers or B2B customers would not be covered under the GDPR. However, if the marketing is in the language of that country and there are references to EU users and customers, then the webpage would be considered targeted marketing and the GDPR will apply.
If Techcrunch has offices or business partners in the EU, or targets EU users for example by having a Dutch-based version of their site, then they would need to comply with GDPR. But if they don't have any of that, then they don't need to comply.
https://www.forbes.com/sites/forbestechcouncil/2017/12/04/ye...
> The organization would have to target a data subject in an EU country. Generic marketing doesn’t count. For example, a Dutch user who Googles and finds an English-language webpage written for U.S. consumers or B2B customers would not be covered under the GDPR. However, if the marketing is in the language of that country and there are references to EU users and customers, then the webpage would be considered targeted marketing and the GDPR will apply.
If Techcrunch has offices or business partners in the EU, or targets EU users for example by having a Dutch-based version of their site, then they would need to comply with GDPR. But if they don't have any of that, then they don't need to comply.
Given the number of events Techcrunch sponsors in Europe I find that a hard argument for them to make.
[deleted]
Please, stop linking to Techcrunch on HN if you respect privacy. For those in located Europe you have to go through a disrespective process to read a story.
Normally you can get around that by disabling js. Alternatively I have pocket installed and just save in that.
But we seriously need a browser standard header that says no to that, along with a requirement that the only necessary cookie to read a website is GDPR with the value 0.
I think tc is at more than 50.
But we seriously need a browser standard header that says no to that, along with a requirement that the only necessary cookie to read a website is GDPR with the value 0.
I think tc is at more than 50.
With my JS blocker in-place and Reader View, it's actually fine :-)
That'd be my thought too. Does this difficulty persist when you employ Ublock Origin, Privacy Badger, Ghostery, etc? And a browser that doesn't override the user's wishes, like Firefox or Opera?
Without defenses like these, for example, reuters.com is intolerably spammy. But with them it's a delight. Same goes for TechCrunch.
Without defenses like these, for example, reuters.com is intolerably spammy. But with them it's a delight. Same goes for TechCrunch.
Disrespective process?
Try it through europe vpn. Long list of many pages of third party sharing leeches and dark ui techniques (you only see accept button and have to click on the non underlined normal looking text to see the list of oartners; no “select/deselect all” button means you have to click off each checkbox)
> Long list of many pages of third party sharing
Aren't they required to do this by European law?
Aren't they required to do this by European law?
[deleted]
[deleted]
The EU's war on big companies with big data feels too much like the opposite of "focus on your users instead of your competitors". EU has been quick to throw around a lot of fines and new regulations. But I what I don't see is any European governments or companies offering superior alternatives to customers, or any vision of what superior systems would look like.
The EU is too focused on figuring out what's wrong with the technology that was invented 10-15 years ago to be the birth place of the next big alternative.
The EU is too focused on figuring out what's wrong with the technology that was invented 10-15 years ago to be the birth place of the next big alternative.
I think all this GDPR bullshit is just nonsense. The more acts like that we get, the worse for real users, and especially developers it will be. Just think about it for a second. Large companies have large departments full of lawyers responsible just for that kind of thing. Yes, they might be resistant to change, but if they're forced to change, they will either change or figure out a way to not change while still staying compliant. Law is usually full of loopholes and the bigger you are, the easier it is for you to abuse them. The more law restricting what tech companies can or can't do we get, the harder it will be to create a startup. Imagine being a twenty-something biologist and creating a startup that's going to sell some medicines you created in the garage because your grandma is sick and she can't afford the ones on the market. The idea just sounds ridiculous. The number of certifications, clinical trials, approvals and other regulatory hurdles you need to overcome is just too high for someone without a full fledged legal department. I think the same thing will happen in tech, eventually. There will be no more startups made by two roommates at college who have just thought about some revolutionary idea. If someone even tries, they will instantly shut him down for not complyying with this or that regulation in some foreign country he hasn't even visited. Wise founders might try to find a lawyer or two and make their startup compliant with one country's laws and then do georestrictions. Big companies, with their legal departments, however, will be able to navigate that tangled mess much more easily. As a result, we will get big companies tracking us anyway and no way for small startups to rival them, much slower progress in countries with overly paranoid privacy regulations, which will cause economic development of such countries to be slower, and a worse quality of life for citizens in general.
What I've read on this seems to point to how European laws tend to be enforced to the intent of the law rather than the letter. So it's harder for loopholes to be explored in ways common to US law. Further, I think (though could be getting GDPR and the copyright laws confused) there is a clause that says the law should not be enforced in a way that is onerous to small and medium businesses. Which, again, as I understand EU judges to act, should actually mean it's still easy to start a company, but once you're pulling in sizeable revenue you must invest some of that in ensuring compliance.
Take all of this with a huge grain of salt since I learned it from comments on HN. I'd love it if anyone can lend a more experienced take on this to either confirm or definitely what I've said here.
Take all of this with a huge grain of salt since I learned it from comments on HN. I'd love it if anyone can lend a more experienced take on this to either confirm or definitely what I've said here.
Particularly with upcoming legislation regarding 'link taxes' etc. , we're already seeing hints of problematic issues.
Moreover, I think the end result will be just problems for Europeans and frankly very little improvement in material identity protection and basically no improvement in terms of quality of life for Europeans.
What's needed is another model for all of this, but it's way beyond the EU commission to come up with that, as exemplified by the odd 'link tax' rules, which hopefully will be amended.