My Samsung TV which I bought 8 years ago now suddenly asks me if it's okay they share data with their over 200 partners. They have the nerves to headline this with "protect your privacy". Generally not a big fan of EU policing but I wish somebody sued them over this.
> Improving Your Experience and Protecting Your Privacy on Samsung TV Plus
> Samsung and our 264 partners use information about you and your device in order to provide, analyse and improve the Samsung TV Plus app. This includes the processing of personal data such as unique IDs for personalised advertising.
eckelhesten 1 days ago [-]
If I got a dollar for every person suckered into buying Samsung products…
But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.
stvltvs 15 hours ago [-]
Putting on tinfoil hat... how do we know it isn't connecting to our neighbors' open WiFi?
BenjiWiebe 14 hours ago [-]
Do your neighbors have open Wi-Fi? I'm a country dweller, but when I'm in town I look at the Wi-Fi list (in horror) sometimes, and it's really rare to see an open Wi-Fi network.
stvltvs 13 hours ago [-]
Anecdotal but my laptop just found 2 open WiFi networks out of 20. One's enough though.
eckelhesten 9 hours ago [-]
That would be a lawsuit waiting.
philistine 12 hours ago [-]
It’s a common fear. People constantly mention it on HN every time the advice to keep a TV off the internet is mentioned. Yet we have never seen proof by anyone, not once, that it has happened. Extraordinary claims require extraordinary evidence.
NetOpWibby 1 days ago [-]
Exact same setup here. Ideally I'd buy a dumb TV but they don't exist in the modern era.
brador 22 hours ago [-]
Can a screen/monitor/TV send data back over HDMI through a connected computer or is that a 1 way connection?
I threw out a Samsung TV after they kept asking this shit. They'd provided a single button to accept but literally 200+ decline buttons, one for every partner, that I needed to scroll through a click with my remote. Fuck Samsung. Will never buy any Samsung product ever again.
UpsideDownRide 1 days ago [-]
Do you have a better system fix than what EU is trying to do?
Kovah 1 days ago [-]
There would be a few fixes, if the politics would be interested in actually fixing this loophole.
- deny is the default: one button to deny everything but one accept button for every partner
- respect DO NOT TRACK, and force software/hardware providers to enable it by default
- making payments for non-tracking illegal
- remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
orwin 23 hours ago [-]
> - deny is the default: one button to deny everything but one accept button for every partner
Yes, that's in the law. I you do not click on consent, the default is deny everything, and a button to refuse everything should be easy to access.
> - making payments for non-tracking illegal
In the law too.
> - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
True, this loophole was introduced by UK/US lobbyists at the time if I remember correctly. My (very small, 3 dev) company at the time worked on health data and managed to find itself in the arcanes of Brussels because anything related to PII security was good news for us.
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
This is the courts who can judge that.
The main issue with the gdpr law is local enforcement. It is honestly well written and easy to understand, which is why you have so much legal loopholes, but EU courts are RAI rather than RAW (our fast americanisation is changing that though).
danaris 10 hours ago [-]
> and a button to refuse everything should be easy to access.
Part of the problem with this is the website operators who maliciously interpret this to mean "also refuse the cookie that says what I selected", so you have to select it every time you visit. (I even hit a site a few weeks ago that required it on every page when I refused.)
AndroTux 1 days ago [-]
Respecting Do Not Track is the most important thing here. They absolutely could have forced all browser vendors to implement that feature, and force website owners to honor it. Instead, we got cookie banners.
lII1lIlI11ll 20 hours ago [-]
> making payments for non-tracking illegal
This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?
fwlr 20 hours ago [-]
I would have them make money by selling me products, rather than selling me as a product.
lII1lIlI11ll 18 hours ago [-]
How is "Payed subscriptions tier without tracking" not a product? Isn't it exactly what Instagram offers in Europe?
DemocracyFTW2 10 hours ago [-]
> entitled leftie thing ("Elon Musk should pay for my Instagram!")
At least ever since Musk syphoned billions of dollars from the government, then illegally intervened in elections at home and abroad, then went on to destroy USAID, then went after pension funds I believe it would be just fair if he was made to pay personally for some expenses of private people, yes. You don't have to be particularly left to find that.
troupo 20 hours ago [-]
> I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise
Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.
lII1lIlI11ll 17 hours ago [-]
> Advertising does not require invasive and pervasive tracking.
Why are you so opposed to pay for a tier without tracking? I'm still not following.
> Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.
Stasi or KGB weren't "opt in" for their citizens while social networks definitely are. For example, Twitter won't allow me to access the images in the post you linked because I deleted my account as soon as Musk completely enshittified it and I'm doing just fine without it.
troupo 15 hours ago [-]
> Why are you so opposed to pay for a tier without tracking? I'm still not following.
Because advertising does not require invasive and pervasive tracking.
The better question is: why are you so happy defending 24/7 surveillance of everything you do?
> Stasi or KGB weren't "opt in" for their citizens
What you're proposing isn't opt in either. You're proposing "pervasive and invasive tracking, or pay an arbitrary sum randomly defined by the tracking industry". That is, literally pay for access to internet without tracking, or else. All based on a completely unproven assumption that tracking is required for ads to function. It's not.
> while social networks definitely are.
Indeed. Because tracking is happening only on social networks.
> For example, Twitter won't allow me to access the images
> Because advertising does not require invasive and pervasive tracking.
Okay, so just ignore tracking-advertisement supported option and sign up for payed account. What is your issue with this again?
> What you're proposing isn't opt in either. You're proposing "pervasive and invasive tracking, or pay an arbitrary sum randomly defined by the tracking industry". That is, literally pay for access to internet without tracking, or else.
This is incorrect. GDPR already forbids tracking without consent, so services you didn't sign up for (the whole internet) can't legally track you. Obviously, then everything would cost you actual money not just social networks.
This has nothing to do with the topic of this thread. GDPR already forbids random sites and ad networks from tracking you without your explicit consent.
troupo 14 hours ago [-]
> Okay, so just ignore tracking-advertisement supported option and sign up for payed account. What is your issue with this again?
Somehow the only option you propose and defend is: "pay, or be tracked".
Why would I want a world where the only way not to be tracked is to pay?
Moreover, your whole premise is based on the completely unsubstantiated claim that tracking is required for advertisment and for the poor hapless b2c companies.
> This has nothing to do with the topic of this thread. GDPR already forbids random sites and ad networks from tracking you without your explicit consent.
You're literally saying that in your vision you are either tracked, or have to pay for access.
lII1lIlI11ll 13 hours ago [-]
Besides paying or accepting being tracked you also have the option of not using web services that require that. Some things you can self-host (email, Mastodon instance, etc), others are sponsored (HN). I still don't get why you expect to dictate to businesses how to price their products - voting with your wallet has always been the way to express your disagreement, not "EU mAkE eViL Zuck serVE mE fOr fRee!!!11".
troupo 12 hours ago [-]
> Besides paying or accepting being tracked you also have the option of not using web services that require that.
Which is 90% of modern internet
> I still don't get why you expect to dictate to businesses how to price their products
I still don't understand why you keep defending pervasive and invasive tracking of everything you do 24/7 across every site, and device, and service you visit or use even in passing.
> voting with your wallet has always been the way to express your disagreement
No. It has rarely worked. Especially in the face of supranational corporations, and thousands of data brokers.
I mean, the top comment to the news is this: https://news.ycombinator.com/item?id=49106733 about a TV that the person already buys with their money, and that still tracks and sells their data to over 200 "partners". And every TV you can buy at the store these days does that. How can I "vote with my wallet"?
Literally no one is saying that. You are the only one pretending that invasive and pervasive tracking is the only way to serve ads or sponsor content and sites.
So, tell me, why is it you are defending tracking so much?
troupo 20 hours ago [-]
> deny is the default
Article 6 and 7 of the GDPR
> respect DO NOT TRACK, and force software/hardware providers to enable it by default
There is other software and other areas of human activity than just cookies and browsers.
Also, with "deny is default" you shouldn't really nead the DNT. But tell that to the ad/tracking industry
People aren’t rational. They want to have less regulations so there’s more freedom to do what you want and then in the same sentence complain about enshittification.
chrisjj 23 hours ago [-]
> asks me if it's okay they share data with their over 200 partners. L
What happens if you say no?
rurban 18 hours ago [-]
If you manage to click through all >200 partners to say no, the TV startup will be significantly faster. Like 10x faster.
Cutting them off the wire and view through another dongle is easier though
chrisjj 17 hours ago [-]
Sounds like we need an app for that clicking.
Or maybe an extra smart remote.
Henchman21 17 hours ago [-]
How about open source firmware to replace the crap Samsung bundles?
1 days ago [-]
xg15 1 days ago [-]
Still wondering how "freely given, informed, specific and unambiguous" is fulfilled by "sure you can opt-out of tracking - by buying a premium subscription. Also, here are our 589 'partners' that all claim legitimate interest" but here we are.
consp 1 days ago [-]
Legitimate interest does not exist and is a loophole in the law which should be killed. You can challenge it but the authorities who should handle that are grossly underfunded.
GordonS 1 days ago [-]
It does exist, but the allowable use cases that third parties can claim "legitimate interest" for need to be severely restricted. At present, it's a joke - a single site can have dozens or even hundreds of companies claiming "legitimate" interests, but which are anything but legitimate.
xg15 23 hours ago [-]
It's almost hilarious how every cookie form now has a "legitimate interest" section that's just a copy of the "consent" section with defaults set to "allow".
They're not even pretending anymore and are just trying everything they can't get consent for again via the "legitimate interest" route.
I was actually wondering if the mandated "refuse everything" button that revokes my consent in bulk (and then conveniently closes the window) also implies I objected to all "legitimate interest" claims, or if that is another malicious compliance trick...
Mtinie 1 days ago [-]
Even if they were well-funded, I suspect the history of regulatory capture, at least in the U.S., shows that meaningful pro-consumer reforms get slow-walked until the underlying bills dilute and/or die in committee.
Or, if reforms do pass, they get reversed the next time the counter-party gains enough power in Congress to roll back the progress.
troupo 1 days ago [-]
Legitimate interests exist, and the loophole exists because otherwise legitimate use cases like security audits or fraud detection would be impossible.
Most of EU laws are "these are sensible defaults and we expect you to behave like adults". As we've seen, digital services are anything but.
Doxin 22 hours ago [-]
"legitimate interest" was supposed to be for things like remember-login cookies and the like. Not for advertisers going "my interest is legitimate because it's how I make money".
chrisjj 23 hours ago [-]
Legitimate interest does exist and is a specific purposeful provision in the law.
66fm472tjy7 24 hours ago [-]
noyb calls these schemes "Pay or Okay"[0] and has filed complaints[1]. However, as far as I can tell no one has been forced by a court to stop.
Yet the pointless banners and illegal tracking remains. They do, sometimes, but rarely. And having Ireland's utterly toothless DPC handling so many big tech companies makes it even worse.
account42 22 hours ago [-]
Yes, letting companies go regulatory agency shopping should not have been allowed. Legal disputes between companies and the customers need to be decided where the customers are.
bobim 1 days ago [-]
They are useful as a deterrence system, can't decline in one click? I'm out thanks.
sensanaty 23 hours ago [-]
The EU just needs to make tracking of any kind full on illegal, especially targeted advertising. I don't give a shit if your business can't survive without invasive tracking of every single facet of your user's existence, you deserve to be shut down if that's your one and only viable business model.
anon48293 23 hours ago [-]
Just ban ads already. I don’t want ads. I don’t want to be tracked. I should have the right to never interact with either, unless explicit, informed and single-button-revocable consent is given.
eproxus 16 hours ago [-]
Completely agree, the solution to so many privacy invasions and problems in tech is just because ads are allowed.
Would love to see a society where ads are not allowed. Cannot really see any downsides personally, but I’m sure many will claim ”how will companies survive?!” Hard to see it would lead to the collapse of either companies or society, but maybe of capitalism as we know it (which I think given the current state of the world would be such a bad thing).
HDThoreaun 15 hours ago [-]
Half of the people in the world use facebook/ig every month and revealed preferences show they have no interest in banning ads
tomkarho 24 hours ago [-]
These single click "informed" consent is akin to a bartender mixing you a drink with 30 different ingredients and hoping you don't notice they include cyanide and rohypnol.
mzajc 17 hours ago [-]
I think it's closer to a bartender mixing you a drink with 30 (hundred) different poisons and hoping you get tired of saying "no" every time.
harrouet 1 days ago [-]
I see so many sites that pretend that they have 350 /legitimate interest/ partners. Time to crack down on abuses.
CodesInChaos 1 days ago [-]
EU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.
loeg 1 days ago [-]
The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.
GJim 24 hours ago [-]
I'm again reminded that a significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic, like yourself, slants towards opposing decent privacy laws.
duskdozer 1 days ago [-]
And we'd all be even happier with no banners and no tracking.
account42 22 hours ago [-]
And even happier with no ads.
cryptonym 1 days ago [-]
The whole world would be even happier if websites stoped this nonsense tracking of every single action bloating a single webpage with 20Mb of JS, connecting to 50+ domains, impacting accessibility, data usage & interactivity.
cwillu 24 hours ago [-]
But how will my PM get his fancy overlay of our website with the heatmap of user clicks and dwells to grossly misinterpret?
Nursie 23 hours ago [-]
You don’t need to put up these banners if you aren’t doing dodgy shit with PII
thinkingemote 23 hours ago [-]
A surprising number of sites that have consents do not actually do anything apart from set a flag.
They are not actually connected to disabling analytics, just connected to the banner itself.
It seems like no data privacy activists or automated scans actually look at whether the consents really work or not, just whether they have them!
terabytest 1 days ago [-]
Is the issue here a lack of “Reject All” button? Or strictly the number of partners?
Superleroy 1 days ago [-]
I read the complaint and it seems to have nothing to do with the reject all button and is only about transparency and informed consent.
They state that you cannot reasonably read all those privacy policies and thus you also cannot give informed consent.
At least that is how I understood it
mschild 1 days ago [-]
Probably both.
If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.
swiftcoder 1 days ago [-]
It's the definition of "informed consent". Can I actually go through a couple of thousand 3rd parties and confirm that their policies all conform to my data handling requirements?
loeg 1 days ago [-]
Can you with even a single 3rd party? It's a huge waste of your time.
Nursie 1 days ago [-]
The issue is that even if you click "Accept" there is no reasonable way to infer that the user has given informed consent, because becoming informed would likely take days or weeks.
As such the conditions for data sharing are not met and it is likely to be illegal.
loeg 1 days ago [-]
> becoming informed would likely take days or weeks.
Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.
Barbing 1 days ago [-]
A simple diagram of them opening a user’s mouth and cramming 200 logos down our throats would inform pretty well, especially if (this being the greater fantasy) the corresponding opt-in was buried deep at the bottom of a list in an obscure settings menu.
Nursie 24 hours ago [-]
I'm not sure I agree that you couldn't become informed about a single one. I think one is probably reasonable.
Presumably, if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, then such a thing could be done. I imagine a lot of people would click the “I’m not reading all that” button though.
You could even envision a simplified sort of 'tracking declaration' as is done with (for example) insurance products here in Australia, where a sort of statutory precis gives the reader a good, bullet-pointed outline of the policy
I would wager that with a well formatted precis like that, it may even be possible to consent to as many as half a dozen 3rd parties. I doubt many people would though, if it was spelled out that blatantly and clearly what it's all about.
And isn't that the point? Hide what's really happening in so many walls of text nobody could ever conceivably bother with them?
So I think the person filing this suit is correct. The behaviour on show here is an end-run around even the idea of informed consent, and needs to be squashed.
(Edit - instead of all these cold GDPR compliance boxes and walls of text, sites should be honest: letting advertisers track you is how we make money, please click yes and we can get paid for your visit”, but of course it’s much more effective just to confuse people into ignorant acquiescence, or try to get people riled up about “stupid gdpr compliance nonsense”)
troupo 12 hours ago [-]
> if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party,
I've now bought two apartments and sold one. The whole process including reading the contract almost in its entirety out loud for both parties, and signing by the parties, and confirmation of the bank took less than an hour.
There's almost no service important enough to spend a few hours reading through a contract. And those that are? They should not have contracts of that length.
> letting advertisers track you is how we make money, please click yes and we can get paid for your visit”
Every law is made under some assumptions about the scale of things. For example, judiciary procedures were designed assuming certain number of active cases. Citizen services and bureaucracy around them is designed assuming some amount of work and staff size. Look at the US immigration / green card processes.
The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.
cryptonym 21 hours ago [-]
You can't number every limit and corner case. You come with precise terms and give a chance for people to defend their case in court.
We'll now see if "thousands of partners" is considered as a good match for "informed consent". Doesn't mean there is a need for review, unless the legislator is not happy with the interpretation that will be provided.
troupo 1 days ago [-]
> The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click.
The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.
jcul 1 days ago [-]
I've seen similar on some android apps I think, where it will ask you if you consent to sharing data with partners or something similar.
When you say no there's a huge list of partners you have to disable one by one, it's probably 15 minutes of work to go through them all.
I can't think of an example app right now, but usually it's on first install or something like that. Not sure GDPR applies to apps though.
happymellon 1 days ago [-]
Why wouldn't GDPR apply to apps? It's not a cookie banner requirement, it is a regulation for data protection because companies were (are) selling harvested personal details and saving it for eternity.
Having personal information isn't always a bad thing, it would be really annoying if I had to fill out a form with my bank every couple of years to tell them my address, which hasn't changed and is a legitimate interest. Amazon telling everyone that I bought some athletes foot cream is not.
Y-bar 1 days ago [-]
GDPR absolutely applies to apps, it applies to all manner of electronic and non-electronic means of data collection and processing.
The G stands for General, and the EU means it.
troupo 1 days ago [-]
GDPR is a General Data Protection Regulation. It applies to everything.
10 years. It's been in force for 10 years. The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)
CodesInChaos 1 days ago [-]
There is the ePrivacy directive as well, which mentions cookies (as a representative example), and I think it requires user consent in cases where GDPR doesn't.
troupo 20 hours ago [-]
ePrivacy is now mostly about the requirement to notify the user that cookies are set, and what they are used for. But you are correct: https://gdpr.eu/cookies/
holsta 1 days ago [-]
> Not sure GDPR applies to apps though.
GDPR applies to we the people and the organizations who hold our data. Doesn't matter if it's morse code on paper strips.
If we can dictate warnings on tobacco packages, we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".
dwedge 1 days ago [-]
> we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".
At least the banners that say "we value your privacy" are honest about it
robotswantdata 1 days ago [-]
Pihole / dns sink hole
Or better yet , never connect it to the internet!
wyager 1 days ago [-]
Can someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?
flexagoon 1 days ago [-]
When you try to maximize ad revenue, you add multiple advertising SDKs to your website, each of which can often do live bidding with hundreds of ad/data brokers
You can usually check the ads.txt file on a website to see which companies are allowed to bid for ad space on there. For example, for dict.cc, the website in question:
The ones labelled "RESELLER" will probably share your data with even more ad companies.
forestry 23 hours ago [-]
How have I not heard about this. I am both impressed and horrified.
Y-bar 22 hours ago [-]
I am one of those.
It generally goes like this:
When we launch a site it is seldom more than perhaps Hotjar, Google Analytics, and two-three other services connected.
And then through the years product managers and other stakeholders gets sold on adding LinkedIn, Instagram, Meta, and so on. So we add those.
Next a specific service ”to better track the sales funnel from in-store salespeople to the web” gets added. Then another ”analyse the data quality versus bounce rate” tracker gets added. And so on.
Before long the developers have streamlined the process of adding new scripts/analytics/trackers that editors can add them on their own, and that is when the floodgates open.
xdertz 1 days ago [-]
two main sources
analytics: A/B testing, "if x does user click y"?, unique page visits, etc.
ads: integrating with an ad provider comes with hundreds of trackers, because they want to
- know if you bought a product after clicking on an ad
- show you targeted ads for shoes after you googled shoes
- build a profile of you (age, gender, location, profession) to show relevant ads across different websites
timr 1 days ago [-]
Likely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe".
For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.
You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.
fuzzy2 1 days ago [-]
Oh yeah, that combination of fear and lack of knowledge probably plays a big part. I was once involved with creating a privacy policy for a B2B(!) web application. What a farce. In the end, the process was cut short (counsel too expensive and not nearly familiar enough with tech). The resulting document was at least 50 % stuff the app simply does not do.
happymellon 1 days ago [-]
> or had an especially conservative corporate counsel
And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.
CodesInChaos 1 days ago [-]
Advertisement.
andrewstuart2 1 days ago [-]
I thought for sure this would be for f1tv.formula1.com but apparently that's only 134 and I thought that was ridiculous.
> Improving Your Experience and Protecting Your Privacy on Samsung TV Plus
> Samsung and our 264 partners use information about you and your device in order to provide, analyse and improve the Samsung TV Plus app. This includes the processing of personal data such as unique IDs for personalised advertising.
But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.
- deny is the default: one button to deny everything but one accept button for every partner
- respect DO NOT TRACK, and force software/hardware providers to enable it by default
- making payments for non-tracking illegal
- remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
Yes, that's in the law. I you do not click on consent, the default is deny everything, and a button to refuse everything should be easy to access.
> - making payments for non-tracking illegal
In the law too.
> - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
True, this loophole was introduced by UK/US lobbyists at the time if I remember correctly. My (very small, 3 dev) company at the time worked on health data and managed to find itself in the arcanes of Brussels because anything related to PII security was good news for us.
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
This is the courts who can judge that.
The main issue with the gdpr law is local enforcement. It is honestly well written and easy to understand, which is why you have so much legal loopholes, but EU courts are RAI rather than RAW (our fast americanisation is changing that though).
Part of the problem with this is the website operators who maliciously interpret this to mean "also refuse the cookie that says what I selected", so you have to select it every time you visit. (I even hit a site a few weeks ago that required it on every page when I refused.)
This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?
At least ever since Musk syphoned billions of dollars from the government, then illegally intervened in elections at home and abroad, then went on to destroy USAID, then went after pension funds I believe it would be just fair if he was made to pay personally for some expenses of private people, yes. You don't have to be particularly left to find that.
Advertising does not require invasive and pervasive tracking. There's no world in which a b2c company needs my precise geo location for 12 years: https://x.com/dmitriid/status/1817122117093056541
Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.
Why are you so opposed to pay for a tier without tracking? I'm still not following.
> Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.
Stasi or KGB weren't "opt in" for their citizens while social networks definitely are. For example, Twitter won't allow me to access the images in the post you linked because I deleted my account as soon as Musk completely enshittified it and I'm doing just fine without it.
Because advertising does not require invasive and pervasive tracking.
The better question is: why are you so happy defending 24/7 surveillance of everything you do?
> Stasi or KGB weren't "opt in" for their citizens
What you're proposing isn't opt in either. You're proposing "pervasive and invasive tracking, or pay an arbitrary sum randomly defined by the tracking industry". That is, literally pay for access to internet without tracking, or else. All based on a completely unproven assumption that tracking is required for ads to function. It's not.
> while social networks definitely are.
Indeed. Because tracking is happening only on social networks.
> For example, Twitter won't allow me to access the images
Here's a direct link. And no, this pop up wasn't on an "opt out social network". It was on a random site (can't remember now which one): https://pbs.twimg.com/media/GTe23o5WwAACyNJ?format=png&name=...
Okay, so just ignore tracking-advertisement supported option and sign up for payed account. What is your issue with this again?
> What you're proposing isn't opt in either. You're proposing "pervasive and invasive tracking, or pay an arbitrary sum randomly defined by the tracking industry". That is, literally pay for access to internet without tracking, or else.
This is incorrect. GDPR already forbids tracking without consent, so services you didn't sign up for (the whole internet) can't legally track you. Obviously, then everything would cost you actual money not just social networks.
> Here's a direct link. And no, this pop up wasn't on an "opt out social network". It was on a random site (can't remember now which one): https://pbs.twimg.com/media/GTe23o5WwAACyNJ?format=png&name=...
This has nothing to do with the topic of this thread. GDPR already forbids random sites and ad networks from tracking you without your explicit consent.
Somehow the only option you propose and defend is: "pay, or be tracked".
Why would I want a world where the only way not to be tracked is to pay?
Moreover, your whole premise is based on the completely unsubstantiated claim that tracking is required for advertisment and for the poor hapless b2c companies.
> This has nothing to do with the topic of this thread. GDPR already forbids random sites and ad networks from tracking you without your explicit consent.
You're literally saying that in your vision you are either tracked, or have to pay for access.
Which is 90% of modern internet
> I still don't get why you expect to dictate to businesses how to price their products
I still don't understand why you keep defending pervasive and invasive tracking of everything you do 24/7 across every site, and device, and service you visit or use even in passing.
> voting with your wallet has always been the way to express your disagreement
No. It has rarely worked. Especially in the face of supranational corporations, and thousands of data brokers.
I mean, the top comment to the news is this: https://news.ycombinator.com/item?id=49106733 about a TV that the person already buys with their money, and that still tracks and sells their data to over 200 "partners". And every TV you can buy at the store these days does that. How can I "vote with my wallet"?
Or do you think fifa.com (referenced in the article under which we discuss this) needs money to run their site? FIFA has a revenue of $15 billion dollars from the World Cup alone: https://www.theguardian.com/football/2026/jul/18/fifa-record... And yet: https://www.fifa.com/ads.txt
> EU mAkE eViL Zuck serVE mE fOr fRee!!!11
Literally no one is saying that. You are the only one pretending that invasive and pervasive tracking is the only way to serve ads or sponsor content and sites.
So, tell me, why is it you are defending tracking so much?
Article 6 and 7 of the GDPR
> respect DO NOT TRACK, and force software/hardware providers to enable it by default
There is other software and other areas of human activity than just cookies and browsers.
Also, with "deny is default" you shouldn't really nead the DNT. But tell that to the ad/tracking industry
> making payments for non-tracking illegal
Generally derived from GDPR. See e.g. recital 43 https://gdpr-info.eu/recitals/no-43/
> remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
It's there because actual legitimate activities like security audits or fraud detection would not be possible.
EU expects companies to act as adults, but here we are.
> prohibit any other dark pattern, or at least make it extremely hard to implement
This cannot be properly specified. And existing laws and regulations already cover that.
See the article we're commenting under. And noyb's previous cases: https://noyb.eu/en/where-did-all-reject-buttons-come
What happens if you say no?
Cutting them off the wire and view through another dongle is easier though
Or maybe an extra smart remote.
They're not even pretending anymore and are just trying everything they can't get consent for again via the "legitimate interest" route.
I was actually wondering if the mandated "refuse everything" button that revokes my consent in bulk (and then conveniently closes the window) also implies I objected to all "legitimate interest" claims, or if that is another malicious compliance trick...
Or, if reforms do pass, they get reversed the next time the counter-party gains enough power in Congress to roll back the progress.
Most of EU laws are "these are sensible defaults and we expect you to behave like adults". As we've seen, digital services are anything but.
---
[0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...
[1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...
Would love to see a society where ads are not allowed. Cannot really see any downsides personally, but I’m sure many will claim ”how will companies survive?!” Hard to see it would lead to the collapse of either companies or society, but maybe of capitalism as we know it (which I think given the current state of the world would be such a bad thing).
They are not actually connected to disabling analytics, just connected to the banner itself.
It seems like no data privacy activists or automated scans actually look at whether the consents really work or not, just whether they have them!
At least that is how I understood it
If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.
As such the conditions for data sharing are not met and it is likely to be illegal.
Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.
Presumably, if your service was important enough to the user and the third party tracking integration important enough to you that you're willing to ask the user to spend a few hours reviewing their 'contract' with the third party, then such a thing could be done. I imagine a lot of people would click the “I’m not reading all that” button though.
You could even envision a simplified sort of 'tracking declaration' as is done with (for example) insurance products here in Australia, where a sort of statutory precis gives the reader a good, bullet-pointed outline of the policy
I would wager that with a well formatted precis like that, it may even be possible to consent to as many as half a dozen 3rd parties. I doubt many people would though, if it was spelled out that blatantly and clearly what it's all about.
And isn't that the point? Hide what's really happening in so many walls of text nobody could ever conceivably bother with them?
So I think the person filing this suit is correct. The behaviour on show here is an end-run around even the idea of informed consent, and needs to be squashed.
(Edit - instead of all these cold GDPR compliance boxes and walls of text, sites should be honest: letting advertisers track you is how we make money, please click yes and we can get paid for your visit”, but of course it’s much more effective just to confuse people into ignorant acquiescence, or try to get people riled up about “stupid gdpr compliance nonsense”)
I've now bought two apartments and sold one. The whole process including reading the contract almost in its entirety out loud for both parties, and signing by the parties, and confirmation of the bank took less than an hour.
There's almost no service important enough to spend a few hours reading through a contract. And those that are? They should not have contracts of that length.
> letting advertisers track you is how we make money, please click yes and we can get paid for your visit”
Ads don't require pervasive and invasive tracking. No one needs to store my precise geolocation for 12 years to serve me an ad: https://pbs.twimg.com/media/GTe23o5WwAACyNJ.png?name=orig
The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.
We'll now see if "thousands of partners" is considered as a good match for "informed consent". Doesn't mean there is a need for review, unless the legislator is not happy with the interpretation that will be provided.
The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.
When you say no there's a huge list of partners you have to disable one by one, it's probably 15 minutes of work to go through them all.
I can't think of an example app right now, but usually it's on first install or something like that. Not sure GDPR applies to apps though.
Having personal information isn't always a bad thing, it would be really annoying if I had to fill out a form with my bank every couple of years to tell them my address, which hasn't changed and is a legitimate interest. Amazon telling everyone that I bought some athletes foot cream is not.
The G stands for General, and the EU means it.
10 years. It's been in force for 10 years. The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)
GDPR applies to we the people and the organizations who hold our data. Doesn't matter if it's morse code on paper strips.
If we can dictate warnings on tobacco packages, we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".
At least the banners that say "we value your privacy" are honest about it
You can usually check the ads.txt file on a website to see which companies are allowed to bid for ad space on there. For example, for dict.cc, the website in question:
https://dict.cc/ads.txt
The ones labelled "RESELLER" will probably share your data with even more ad companies.
It generally goes like this:
When we launch a site it is seldom more than perhaps Hotjar, Google Analytics, and two-three other services connected.
And then through the years product managers and other stakeholders gets sold on adding LinkedIn, Instagram, Meta, and so on. So we add those.
Next a specific service ”to better track the sales funnel from in-store salespeople to the web” gets added. Then another ”analyse the data quality versus bounce rate” tracker gets added. And so on.
Before long the developers have streamlined the process of adding new scripts/analytics/trackers that editors can add them on their own, and that is when the floodgates open.
analytics: A/B testing, "if x does user click y"?, unique page visits, etc.
ads: integrating with an ad provider comes with hundreds of trackers, because they want to - know if you bought a product after clicking on an ad - show you targeted ads for shoes after you googled shoes - build a profile of you (age, gender, location, profession) to show relevant ads across different websites
For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.
You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.
And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.