As a government you should not be putting your stuff in an environment under control of some other nation, period. That is a completely different issue and does not really relate to making backups.
- They are not asking for consent, there is just an ok button.
- They assume consent when you navigate further on the site, this is not valid consent.
- Consent needs to be for specific, well defined purposes. “help personalize content, tailor and measure ads and provide a safer experience” are three purposes in one and none of them are well defined.
- They are probably already setting the cookies in your first request, when you have not seen any information yet (did not check)
Lovely that their blog with privacy propaganda has a cookie banner that is not compliant with any privacy law in any way. Says everything about their efforts, I guess.
> Imagine 2007 and the following years already with the EU act in full effect. AppStore would be dead on arrival.
No, it wouldn't have been, as the DMA only applies to 'gatekeepers' and if you're new, you're simply not a gatekeeper. You need at least 45 million monthly active users and 7,5 billion of revenue for three years.
> So EU should change Apple’s and Google’s status from producer to provider of essential service like electricity for example.
That's the whole point of the DMA: designate these parties as 'gatekeepers', providing essential services ('core platform services' in terms of the DMA). Once you are, you have certain obligations that should allow proper interoperability with other/smaller parties.
> Hotels are concerned that direct booking clicks are down as much as 30% since our compliance changes were implemented. These businesses now have to connect with customers via a handful of intermediaries that typically charge large commissions, while traffic from Google was free.
That's because your search engine results are a joke, not because of the DMA.
If I search for 'hotel <city>', I get an ad from Booking.com, then some hotel ad, then an ad from Trivago, then some Google map with hotels (make sense, but all results there are sponsored by intermediaries), then Booking.com, then Booking.com again, then Expedia, then Tripadvisor, then Trivago.
If you only present me sponsored results from intermediaries, then don't be surprised that people only click on sponsored results of intermediaries.
You're talking about the Digital Markets Act (DMA) which will come into effect in the EU in about two weeks. It does exactly what you say, although Apple is still actively trying to sabotage it with a sloppy implementation.
There is nothing in there about retroactively applying laws. If there is anything, it may be that the laws were(/are) unclear.
The Irish DPC states they never approved anything (but there has been discussions between various European data protection authorities and the EDPB during the investigation). See for example 2.44 or 2.46 of the report [1]:
> It is factually not the case that the Commission endorsed or approved of the Terms of Service and Data Policy of Facebook or indeed of any other organisation
and
> To the extent that Facebook seeks to rely on or has ever relied on any consultative process with the Commission in order to defend the lawfulness of a particular practice, this has been in error. More pertinently, for present purposes, Facebook makes no such argument in the context of this Complaint. This is because the Commission never provided any such approval in this case nor does it do so in the context of its engagement and consultation role more generally
If you look at the final decision on Meta, you'll see that most of the fine (80+70=150 million) is for the fact that Meta was not clear on what they were doing with user's data. Only the last 60 million is about the actual legal ground of the processing. So the past that Ben Thompson mentions essentially skips 70% of the fines.
And yes, the data protection authorities are acting like a fair player and they are not the referee. We have courts for that (and this will find it's way through the courts, no worries).
It's great that you have a non-publicly available newsletter as a source, but if you read the DPC item [1] you'll see that it's just about the GDPR. What Ben probably does not understand, is that the fine is not about the TOS change _before_ the GDPR came in effect, but about the fact that data was processed without valid legal basis _after_ the GDPR came in effect as the TOS change and an 'I accept' button was simply not sufficient.
> Anomyous telemetry is not PII. GDPR is personal data.
How are you exactly going to submit it anonymously? Will it connect over Tor?
Because if you just send it over your internet connection, it arrives with your IP address on the packets, which is PII, which makes it data processing of PII, which makes it require a legal basis to process. And it is legally uncertain that 'legitimate interest' is a valid ground for telemetry data, leaving only opt-in consent.
Expect 50 to 200% price increases within a year or so, it is what TWS has been doing with all hosting parties they acquired.
For example, PCExtreme had simple dynamic hosting for 1.95 EUR/month before acquisition [1]. Current pricing after a rebrand is 4.99 EUR/month [2] and in turn you get 1/10th of the storage and traffic.
As a small developer, you wouldn't fall under the DMA.