Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In 1y every website will have a click through EULA with 20 pages that loads before everything else and doesn't store IPs - and which no one is reading - privacy served. Just when they install from the App store or install Microsoft Office.


Forcing users to accept a 20 page EULA is not compliant, that's what's so great about this directive. If all you have to do to be compliant is add a new clause to your 20 page EULA, then the law would have no purpose - we're already trained to just click accept when presented with any kind of lawyerese. The whole point is to get away from that.


IANAL

I've not said that this is the only thing you need to do. EULAs don't make you compliant. I've said websites will have EULAs (and be internally compliant) and do everything - except selling - with your data that they do now.

The only real benefit of the GDPR for users is that old (e.g. 2y) data needs to be deleted and companies can't keep your personal data 10y for future use cases.

But you can do most of the things you like with consent and if you do not couple it to your offer.

But the GDPR does not prevent any business model or collecting any data as long as there is consent, you are transparent, you can export the data, consent can be revoked and data can be deleted on request.


That's not the only real benefit. The strongest benefit is that all tracking and sharing of collected data is made explicit to all users in plain language and now requires explicit opt-in. Before this directive, companies could just hide that shit somewhere in their EULA. It's this practice that's being regulated.


Except that won’t help them with the GDPR one bit.

They will worsen their experience and not be in compliance because they are unwilling to actually do the simple things needed.


IANAL but after working on GDPR topics for months with a lot of reading I'd say they would work.

Selling data is still hard to argue, I'd not do that for EU citizens ("tag EU citizens to opt out from selling data"). Everything else should be possible. Using Art 6/1(a) and Art. 7 GDPR you can store most of the data from your visitor. You need to make sure they can inform them about your usage, revoke their aggreement and make you delete it. Coupling ("click EULA or else") is a little bit more difficult, but with clever UI most visitors will accept the EULA instead of opting out, no coupling needed.

I'm sure in 1y publishing systems will provide all of this out of the box.


"Clever UI" (read: deceptive) tricks are obviously explicitely forbidden by the GDPR.


No, not a dark pattern, like LinkedIn, just a "yes" & "no", but if you place "yes" to the right side people will more likely click on "yes". If you space them at the bottom of the EULA, "no" to the left border, "yes" to the right border more people will click on "yes".

This is not something I would do, but my salary is not coming from placing ads on a site and selling personal data. But this is what will happen.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: