49 comments

  • jtreitz an hour ago

    My Samsung TV which I bought 8 years ago now suddenly asks me if it's okay they share data with their over 200 partners. They have the nerves to headline this with "protect your privacy". Generally not a big fan of EU policing but I wish somebody sued them over this.

    > Improving Your Experience and Protecting Your Privacy on Samsung TV Plus

    > Samsung and our 264 partners use information about you and your device in order to provide, analyse and improve the Samsung TV Plus app. This includes the processing of personal data such as unique IDs for personalised advertising.

    • eckelhesten 41 minutes ago

      If I got a dollar for every person suckered into buying Samsung products…

      But to stay on topic: never! connect your tv to the internet. My LG has been offline for around 5 years now after automatically installing unwanted apps. Since then, I run everything via an Apple TV 4K which works way better than LGs own software does anyway.

      • NetOpWibby 17 minutes ago

        Exact same setup here. Ideally I'd buy a dumb TV but they don't exist in the modern era.

    • ifh-hn 40 minutes ago

      I threw out a Samsung TV after they kept asking this shit. They'd provided a single button to accept but literally 200+ decline buttons, one for every partner, that I needed to scroll through a click with my remote. Fuck Samsung. Will never buy any Samsung product ever again.

    • UpsideDownRide 30 minutes ago

      Do you have a better system fix than what EU is trying to do?

      • Kovah 21 minutes ago

        There would be a few fixes, if the politics would be interested in actually fixing this loophole.

        - deny is the default: one button to deny everything but one accept button for every partner

        - respect DO NOT TRACK, and force software/hardware providers to enable it by default

        - making payments for non-tracking illegal

        - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything

        - and probably: prohibit any other dark pattern, or at least make it extremely hard to implement

        • AndroTux 5 minutes ago

          Respecting Do Not Track is the most important thing here. They absolutely could have forced all browser vendors to implement that feature, and force website owners to honor it. Instead, we got cookie banners.

      • 2muchcoffeeman 22 minutes ago

        People aren’t rational. They want to have less regulations so there’s more freedom to do what you want and then in the same sentence complain about enshittification.

  • xg15 an hour ago

    Still wondering how "freely given, informed, specific and unambiguous" is fulfilled by "sure you can opt-out of tracking - by buying a premium subscription. Also, here are our 589 'partners' that all claim legitimate interest" but here we are.

    • consp an hour ago

      Legitimate interest does not exist and is a loophole in the law which should be killed. You can challenge it but the authorities who should handle that are grossly underfunded.

      • GordonS 28 minutes ago

        It does exist, but the allowable use cases that third parties can claim "legitimate interest" for need to be severely restricted. At present, it's a joke - a single site can have dozens or even hundreds of companies claiming "legitimate" interests, but which are anything but legitimate.

      • Mtinie 29 minutes ago

        Even if they were well-funded, I suspect the history of regulatory capture, at least in the U.S., shows that meaningful pro-consumer reforms get slow-walked until the underlying bills dilute and/or die in committee.

        Or, if reforms do pass, they get reversed the next time the counter-party gains enough power in Congress to roll back the progress.

      • troupo 39 minutes ago

        Legitimate interests exist, and the loophole exists because otherwise legitimate use cases like security audits or fraud detection would be impossible.

        Most of EU laws are "these are sensible defaults and we expect you to behave like adults". As we've seen, digital services are anything but.

    • CalRobert an hour ago

      Europe doesn’t enforce the law. Cookie banners are similarly pointless.

  • harrouet 39 minutes ago

    I see so many sites that pretend that they have 350 /legitimate interest/ partners. Time to crack down on abuses.

  • CodesInChaos 28 minutes ago

    EU should simply outlaw tracking for advertisement purposes. Let's return to context based ads.

    • loeg 27 minutes ago

      The rest of the world would be happier if websites geofenced the cookie consent banners to EU IPs only and just left the rest of us alone, with any combination of cookies/tracking.

      • duskdozer 24 minutes ago

        And we'd all be even happier with no banners and no tracking.

      • cryptonym 21 minutes ago

        The whole world would be even happier if websites stoped this nonsense tracking of every single action bloating a single webpage with 20Mb of JS, connecting to 50+ domains, impacting accessibility, data usage & interactivity.

  • robotswantdata 33 minutes ago

    Pihole / dns sink hole Or better yet , never connect it to the internet!

  • terabytest an hour ago

    Is the issue here a lack of “Reject All” button? Or strictly the number of partners?

    • Superleroy an hour ago

      I read the complaint and it seems to have nothing to do with the reject all button and is only about transparency and informed consent. They state that you cannot reasonably read all those privacy policies and thus you also cannot give informed consent.

      At least that is how I understood it

    • mschild an hour ago

      Probably both.

      If I understand it correctly giving informed consent for over 1700 tracking partners of a single page isn't realistic. You as a single person cannot be expected to truly understand what it is you are agreeing to when you click accept.

    • swiftcoder an hour ago

      It's the definition of "informed consent". Can I actually go through a couple of thousand 3rd parties and confirm that their policies all conform to my data handling requirements?

      • loeg 31 minutes ago

        Can you with even a single 3rd party? It's a huge waste of your time.

    • Nursie an hour ago

      The issue is that even if you click "Accept" there is no reasonable way to infer that the user has given informed consent, because becoming informed would likely take days or weeks.

      As such the conditions for data sharing are not met and it is likely to be illegal.

      • loeg 30 minutes ago

        > becoming informed would likely take days or weeks.

        Then it is basically impossible to consent to any kind of tracking, because users cannot become informed for any number of 3rd parties -- even a single one.

        • Barbing 15 minutes ago

          A simple diagram of them opening a user’s mouth and cramming 200 logos down our throats would inform pretty well, especially if (this being the greater fantasy) the corresponding opt-in was buried deep at the bottom of a list in an obscure settings menu.

  • zkmon an hour ago

    Every law is made under some assumptions about the scale of things. For example, judiciary procedures were designed assuming certain number of active cases. Citizen services and bureaucracy around them is designed assuming some amount of work and staff size. Look at the US immigration / green card processes.

    The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click. The next review of the legislation would probably pick it up.

    • troupo 37 minutes ago

      > The designers of GDPR would have not expected thousands of partners sharing the data collected in a single click.

      The designers of GDPR (and most other EU regulations) expect businesses to behave like adults, not like petulant children.

  • jcul an hour ago

    I've seen similar on some android apps I think, where it will ask you if you consent to sharing data with partners or something similar.

    When you say no there's a huge list of partners you have to disable one by one, it's probably 15 minutes of work to go through them all.

    I can't think of an example app right now, but usually it's on first install or something like that. Not sure GDPR applies to apps though.

    • happymellon 27 minutes ago

      Why wouldn't GDPR apply to apps? It's not a cookie banner requirement, it is a regulation for data protection because companies were (are) selling harvested personal details and saving it for eternity.

      Having personal information isn't always a bad thing, it would be really annoying if I had to fill out a form with my bank every couple of years to tell them my address, which hasn't changed and is a legitimate interest. Amazon telling everyone that I bought some athletes foot cream is not.

    • Y-bar an hour ago

      GDPR absolutely applies to apps, it applies to all manner of electronic and non-electronic means of data collection and processing.

      The G stands for General, and the EU means it.

    • troupo 37 minutes ago

      GDPR is a General Data Protection Regulation. It applies to everything.

      10 years. It's been in force for 10 years. The tracking/ad industry has really managed to brainwash everyone into thinking it's about cookies (even though GDPR doesn't even mention cookies except as an example of tracking)

      • CodesInChaos 15 minutes ago

        There is the ePrivacy directive as well, which mentions cookies (as a representative example), and I think it requires user consent in cases where GDPR doesn't.

    • holsta an hour ago

      > Not sure GDPR applies to apps though.

      GDPR applies to we the people and the organizations who hold our data. Doesn't matter if it's morse code on paper strips.

      If we can dictate warnings on tobacco packages, we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".

      • dwedge 29 minutes ago

        > we can dictate the wording on consent banners to not be "We care about your privacy" but instead "We want to track you for profit".

        At least the banners that say "we value your privacy" are honest about it

  • wyager 43 minutes ago

    Can someone who works in commercial web dev explain how companies even end up with this much crap pulled into their websites?

    • flexagoon 29 minutes ago

      When you try to maximize ad revenue, you add multiple advertising SDKs to your website, each of which can often do live bidding with hundreds of ad/data brokers

      You can usually check the ads.txt file on a website to see which companies are allowed to bid for ad space on there. For example, for dict.cc, the website in question:

      https://dict.cc/ads.txt

      The ones labelled "RESELLER" will probably share your data with even more ad companies.

    • xdertz 34 minutes ago

      two main sources

      analytics: A/B testing, "if x does user click y"?, unique page visits, etc.

      ads: integrating with an ad provider comes with hundreds of trackers, because they want to - know if you bought a product after clicking on an ad - show you targeted ads for shoes after you googled shoes - build a profile of you (age, gender, location, profession) to show relevant ads across different websites

    • timr 39 minutes ago

      Likely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe".

      For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.

      You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.

      • happymellon 24 minutes ago

        > or had an especially conservative corporate counsel

        And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.

    • CodesInChaos 35 minutes ago

      Advertisement.

  • andrewstuart2 an hour ago

    I thought for sure this would be for f1tv.formula1.com but apparently that's only 134 and I thought that was ridiculous.

  • loeg 32 minutes ago

    What, is "accept all" somehow not acceptable to GDPRers anymore? We'll have to manually click through multiple forms of cookie allowance just to get to the damn website? What a mess.

    • AndroTux 2 minutes ago

      That’s the most malicious take in the whole thread. Good job!

    • robin_reala 28 minutes ago

      No, you just hit the deny all button, or wait for GPC to become a legally required thing.