Hacker News new | ask | show | jobs
by cakemuncher 2583 days ago
Just remember, you're accepting the agreement if you blocked the overlay because that's the default if you ignored it.
3 comments

You mean in the overlays that are required by law to have the default option be to opt out of tracking?
Actually, they're supposed to be opt-in. "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." [0]. I worked extensively on one of the big ad-network's GDPR compliance pub & advertiser tools and we took this seriously. If you blocked the message & you were detected to be in the EEA, that was "no consent" for data use. That said, I know many of the other players in the ecosystem actively overlooked or did not abide by this policy.

[0]https://www.gdpreu.org/the-regulation/key-concepts/consent/

Shoot, you are correct, and I misspoke. I meant to imply that the default must be assumed to be rejecting all tracking, and that all tracking applied must be explicitly accepted.
What's a shame is that most companies hide behind the claim that if users block IP tracking, since they "can't" get geo without IP, you're opt-in by default. They don't make the best effort attempt to, using the data they have, determine opt-in/out default behavior. The regulators seem OK with that argument. So your point sort of stands (and I wish it didn't)
No, GDPR requires explicit consent for data collection. Blocking the overlay crap is withholding consent.
But is that the case in practice? It's my experience that there are countless media outlets showing me popups that have the tracking options activated by default.
Most companies hide behind the claim that if users block IP tracking, since they "can't" get geo without IP, it's opt-out. Oath in particular will use any excuse to opt-in by default, but so will most news sites. Regulators seem OK with that.
GDPR should be opt-in only, not sure if it currently is or isn't, but in my opinion it should be...
It is, and few care. "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." [0] Problem is that the authorities are too underfunded and understaffed to actually handle this, and the wording in the regulation is vague enough that big company lawyers have hemmed them in. I've seen it happen.

[0] https://www.gdpreu.org/the-regulation/key-concepts/consent/