HN user

privacylawthrow

120 karma
Posts0
Comments34
View on HN
No posts found.

This is factually incorrect. The "Cookie Directive" wasn't from 2003, it was an amendment to the ePrivacy Directive. The ePrivacy Directive came into effect in 2002, and it was amendend in 2009. That amendment is what people generally call the "Cookie Directive" because it required consent for storage of information on end user devices.

It did not specify cookies, and did not actually specify any technical means. The ePrivacy Directive requires that companies get consent from users before storing information or gaining access to information stored on end user devices. This includes every kind of cookie you can think of, including LocalStorage. There is an exception for cookies necessary for the service requested, which typically includes things like auth cookies or shopping cart cookies, so long as that data is not used for anything else.

The FTC has been begging the complain-for-profit sector to give it a formal path to regulate AI. The FTC's only enforcement hook in this area is that it can take action against companies that have unfair or deceptive trade practices. This is how the FTC began regulating privacy and security in the US, and it's been waiting to use it for AI.

It comes as no surprise that this complaint is from Mark Rotenberg, former head of EPIC. He's very well aware of the boundaries of the FTC's power, and this complaint effectively serves as a letter to the FTC from an expert about how the FTC can position itself to begin regulating AI.

You asked the wrong lawyers, at least for the US. The FTC's case against Sears in 2009 made it clear that consent to a privacy notice isn't valid if the privacy notice is buried deep in a licensing agreement, even if the notice is correct.

You're wrong. The ePrivacy Directive does require that a website get consent before storing information on the end-user's device. Prior to GDPR, the local country implementations of the ePD allowed for implicit consent in some EU countries, and opt-out consent in other EU countries. GDPR redefined what constitutes legitimate consent to process personal data. Consent that was previously valid under the ePD was no longer valid under GDPR, which is why GDPR is about cookies, and every other processing of personal data.

I'm a privacy lawyer that has worked on cookie consents for a number of commercial websites. Everything you said here is all too true. The real legal answer in a lot of cases is "Do what everyone else is doing. Don't be an outlier. Use industry tools because if there's a problem with an industry tool, they'll go after the tool and not its users."

The comments about cookies not being part of GDPR are grossly wrong. One of the early discussions in the privacy law community was how to handle the collision of the new consent requirements under GDPR with the fact that the ePrivacy Directive requires consent for cookies. Prior to GDPR, a large number of EU jurisdictions allowed for implicit consent through a variety of actions, like scrolling a page, or non-actions, like seeing a banner and not clicking "no". GDPR redefined consent and that's why cookie banners pop up.

EU governments are exempt from the requirements of GDPR. In some countries police can access large amounts of data without the need for a warrant. For example German police do not need a warrant to get passwords to email account, PIN numbers for mobile phones, mobile usernames, birthdates, telco information, or hospital data.

6 months is not compliant. Employees have to be made aware of the posting on the same calendar day the job is posted. For jobs that are in constant demand, the company has to either send a daily email or have some kind of banner on its corporate intranet.

There is also no geographic restriction so if a company has any offshore service centers, it would need to post any promotional jobs to its Colorado employees as well.

The law also requires that Colorado employees be informed of all promotional opportunities. A promotional opportunity is "a vacancy in an existing or new position that could be considered a promotion for one or more employees in terms of compensation, benefits, status, duties, or access to further advancement."

If a company doesn't already have Colorado employees, they may not be interested in having a remote employee in CO that requires special treatment.

I am a privacy lawyer that has spent far too many hours on cookie issues. It is disappointing that your correct answer was downvoted. It goes to show just how much misinformation is out there about GDPR.

The top comment in this thread demonstrates that as well as the Data Protection Directive of 1995 had a functionally identical requirement allowing users to opt out of completely automated decisions for credit purposes.

If it's the TrustArc Ads Compliance Manager, it makes a call to all the ad networks requesting the network's opt out cookie. The opt out cookie prevents the user from being tracked by that ad network across all sites. Cookie banner opt outs usually only prevent tracking from the site you are one.

Unlike GDPR, which uses a website as the gate for all cookies, the ad industry also has self-regulatory programs. Participation in these programs require that a website allow a user to opt out of all ad networks present on their site. TrustArc built a module to do that: https://preferences-mgr.truste.com/.

If you run the tool there, it will make a call to the ad networks listed. Of course if you're running an ad blocker, the call will get blocked and it will look like the tool doesn't do anything.

It was never going to be the privacy savior Google billed it as, so why push forward with the concept?

Because these users are still anonymous to companies using Google services. Uniquely identifying users, and the liability for doing so, falls to intermediary services. I expect it will be the domain of data brokers like LiveRamp, Epsilon, and others.

"Use Google and be compliant" is a good sales tool and good value for companies that use Google services. Companies that don't want to sell data to brokers will stick with Google.

The law cares about intent and outcome. If you intended to publish Bill Gates' credit card number and did so, and if doing so was a crime, you'd be guilty of that crime. This is true regardless of how you published the information. There is no "out" for putting it behind a pretext.

It's why sharing child pornography is illegal, even though all the creators are really doing is sharing a set of instructions for someone's else's computer to generate the image/video.

These were already violations of the TCPA in the 9th Circuit under the 9th Circuit's previous ruling in Marks where the court found that an autodialer is any equipment that dials a number from a stored list.

Marks was used as precedent for this lawsuit. Facebook argued that this case was different from Marks. The Ninth Circuit found otherwise. SCOTUS appears to have shot down the ruling from Marks.

Marks was widely regarded as a terrible decision because it made no sense at the time. It's nice to see SCOTUS return some common sense to the law.

Note also that the TCPA allows for statutory damages of up to $1500 per violation, so it takes less than 675 calls/texts to rack up $1M in liability. Class action attorneys love it because they don't have to show damages. They only have to show that the call or text was sent using an autodialer.

The opt out cookie was created by ad networks prior to GDPR when many EU countries allowed for opt in by default. The opt out cookie was the tool to allow users to opt out. It still has value today as it allows an ad network to remember a user's choice not to be tracked.

The opt out cookie is set by the advertiser, not the publisher, and the contents of the cookie have generic text like "OPT OUT".

Facebook, as a data controller, is required to provide all information specified in GDPR Article 13 regardless of whether its legal basis for processing that data is consent or contract.

Article 13 is a long list of mandatory disclosures that data controllers have to provide to data subjects, informing them of the identity of the data controller, categories of data collected, data retention periods, etc.

Consent is not, and has never been, the only legal means by which personal data can be processed. When the article says:

This would mean that the company does not have to give users a free choice and obtain a separate and unambiguous consent.

it neglects to mention that using Facebook and entering into a contract with Facebook is optional.

One issue is that anti-trust has moved from being concerned about harm to consumers (great!) to being focused on harm to other businesses (not so great).

The first thing listed in the Federal Trade Commission Act from 1914 is empowering the FTC to "prevent unfair methods of competition". This is a business protection to ensure that businesses fairly compete with each other.

No Cookie for You 6 years ago

Much of the statements about cookie requirements in this thread are wrong.

The rule is simple: If a website uses non-essential cookies, it must inform users and, in most EU jursidctions, collect consent prior to placing a cookie on the user's machine.

The rationale behind the rule is that companies should not store company information on end-user devices without the user's consent. The rule applies to all non-essential cookies regardless of whether the cookies collect personal data or are used for tracking. The rule does not cover cookieless server-side tracking of users. Sites do not violate the law when they track users without consent using server-side tools. Sites do violate the law even without tracking users if the site does not collect consent for non-essential cookies.

GDPR enhanced the cookie rules by applying GDPR consent requirements to all cookies that involve personal information. Many sites ignored the old cookie rule because EU law did not give data protection authorities much enforcement power. GDPR increased the power of the DPAs to issue fines of up to 4% of annual turnover. Sites previously ignoring the rules put out cookie banners once GDPR came into effect.

edit: To be clear, Github isn't saying that it stopped tracking users. It's saying that it doesn't do cookie-based tracking and therefore it does not need a banner.

No Cookie for You 6 years ago

Fun fact: the e privacy directive (which defines the cookie rules) isn't actually passed yet and technically you don't need cookie banners how they are now. Purely informational banners would be enough, but the directive already _should_ have passed but was delayed, and since gdpr spooked everyone, everything and everyone is using cookie banners now anyway

The ePrivacy Directive passed in 2002. It was amended in 2009 to include the cookie rule. The ePrivacy Regulation which would codify cookie requirements as an EU-wide regulation has not passed yet.

No Cookie for You 6 years ago

This is wrong. EU law absolutely does require cookie banners if a website uses non-essential cookies, even if those cookies are not used to harvest data.

1) Cookie notifications are not required by GDPR. They are required by national level implementation of the ePrivacy Directive.

2) Data portability is already a requirement under GDPR Article 20. The problem is that it requires competing services to work together to create interoperable systems or formats. That's really unlikely to happen without addition regulatory action mandating that competitors cooperate.

People will always gloss over privacy policies, privacy tools, and privacy disclosures. The reality is that people are concerned about privacy, but not concerned enough to make any changes. People concerned about the environment still get on planes and fly all over the world.

In my experience, this is a question of interpretation (see e.g. Recital 26 and the question of what is "reasonably likely").

This is absolutely true. The hard part is that was it "reasonably likely" changes as technology changes. It's entirely possible that a data set that qualifies as anonymous today will not be anonymous in 5 years. Organizations are responsible for the data they publish. If data loses its anonymity in the future due to release of other data sets and/or improved technology, the organization releasing the data will be responsible for the release of personal data, even if it wasn't personal data at the time of release.

For data to be anonymous under GDPR, it is not enough that individuals cannot be identified from the anonymized data set. If individuals can be identified when the anonymous data set is compared with the source data set, the anonymized data is not "anonymous".

For data to be truly anonymous under GDPR. there must be no other additional data that would allow for reidentification. If there is any other data that, when combined with the anonymous data, allows for reidentification, the data set is only pseudonymous and must be treated as personal data under GDPR.