Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

37 points by amelius ↗ HN
I'm curious if the GDPR is working as intended, and if it has actually reduced or eliminated online tracking of EU residents.

77 comments

[ 2.0 ms ] story [ 118 ms ] thread
Yes it has. Companies are now forced to build architectures that take data classification and privacy in mind. It's been a really great addition and a important check on the data economy.
Do you still receive targeted advertisements (assuming you have not opted-in to them)?
Unfortunately, yes. I haven't knowingly opted-in to anything. This may be a problem with the whole "click here to accept all these cookies" bullcrap that is on every site. I dont think this apparent benefit of the GDPR has worked - at all.

However, in the organisations I have worked with professionally, GDPR is absolutely working - user data collection, storage and security is now a leading conversation - whereas it was a afterthought before, at best. Of course, this isnt generally visible to the end user, and there are undoubtedly still businesses who ignore this - but i guess we wouldnt know unless there is an incident - in which case I would expect the EU to come down HARD.

I think its web-tracking and marketing in particular that still needs fixing.

Accept cookies has nothing to do with GDPR.

GDPR has to do that if you provide your phone/mail to some shop or other service they can only use it to contact you with information directly related to their business, like processing your order etc. They can not send you marketing stuff unless you explicitly consented and must remove you from lists if you ask. Even delete your account if you ask (not the data tho).

Accepting cookies is definitely related to GDPR. If a cookie can be used to identify you, that is personal information.
GDPR added the bit where you can opt out of cookie usage on a case by case basis (by use case or by data processor). American companies usually don't implement that part in a correct or legal manner (they have no incentive for doing so; they're only pretending "your privacy is so very, very important to them" for PR reasons). European companies doing it wrong are on shaky ground, since it's a matter of time until some regulator somewhere (which one depends on their country) slaps them with massive fines.

On data removal: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

I stopped receiving quite a bunch of various newsletters/proposals was kinda funny reading all the cries for "come give us your consent" few days before GDPR was fully enforced. Overall it is a lot less likely to start receiving various advertisement sms/email after providing your data in some new place.
Well, yes and no. You will always get ads, and targeted or not (based on tracking data) was only going to matter about 4%. Not sure when this was posted on HN, but multiple papers and researches have reached similar conclusions. It's not all that strange if you think about it, because the people that were going to click on ads were going to click anyway, and those who wouldn't aren't suddenly changed because the ads are targeted.
It has definitely reduced the tracking. Due to degraded usability I use European websites less, so fewer companies have my data.
I'd also be interested in knowing the tangible results on a individual level so far.
As an individual, closing accounts is much easier, including getting your data deleted or getting a copy of the data they have.
US expat in Berlin: I hate the cookie consent pop-ups. I wish it just banned cookies altogether. But that would probably break too much.

A friend of mine has used the GDPR give-me-my-data / delete-my-data email to expose companies doing shady stuff as they’re afraid of penalties under the law.

GDPR is trade restriction as the notion of "digital privacy" is perpetrated by those who want to restrain US tech companies.
considering these companies are spying on you with every available sensor to estimate your every thought and desire to then interrupt your thought process with an advertisement perhaps the notion of "digital privacy" has some merit?
Is it? Because if a consumer protection is a trade restriction, would requiring electric devices to be insulated so they don't electrocute the user be a 'trade restriction' as well?
I'm an EU resident with a SaaS business storing EU personal information.

It's forced us to think more carefully how we build systems to pick up, retain and scrub data. So all clients (>1,000) and their clients (likely in the millions) have benefited

They absolutely won't have noticed a difference - by design!

Unbeknownst to downstream users, there are now more rigorous systems in place to manage this information and reduce the surface area where it might be captured

I work with e-commerce in the EU and my experience mirrors yours.

Almost all clients took an honest look at data collection and retention policies.

Data was classified and tools built around the GDPR framework to allow customers to be able to fully retrieve, request changes to, or delete their information from servers.

Most clients ended up collecting less data and retaining it for a shorter time.

All in all from my perspective it seems the law did much of what it was designed to do.

Well, the cookie popups have helped me become more selective in my browsing. If they don't make it reasonably easy to opt out, I just don't open the site.

But the real benefit is this:

Some random online store that i bought something from once decided to send me a spam sms around black friday.

One email and 24 hours later, all the data they had about me was deleted.

Of course, this only works if you're in europe buying from an european store so they're subject to fines from some trigger happy privacy authority.

Assholes like Google still do not ask for consent. Guessing someone at the EU is working on gathering a mountain of documentation so they can fine them that famous 4%.

The cookie pop ups were a thing before, I guess being able to opt-out is a neat feature but there are certainly companies who do not comply when you choose to opt-out. (Looking at you Verizon, yes I know it’s you behind “oath”.)
If i see the "oath" message when following a link, i close the browser tab :)
Same here, it's like they don't even bother getting their systems up to date.
Any opt-out popups anyway aren't caused by GDPR anyway, as consent is 'GDPR-kosher' only if it's explicitly opt-in.

If I take no action, accept the default conditions and don't opt out of anything, then that must be interpreted as me not granting permission to anything - there are a bunch of data use-cases that you're allowed to do without my consent, so you don't need the popups for that, but otherwise no informed explicit affirmative action means no consent.

That's how it should work, but in practice most popups are opt out. I've seen only one type of cookie popup that comes with default opt in, and even that one has a very proeminent 'opt in to all and save' button and a slightly harder to find 'just save' button that will actually allow the opt out to stay.
I find it interesting how Google still does this on sites like blogger. I ignore the banner covering 80% of my mobile screen and read the article but agree to nothing. They'll probably still process my data despite me not agreeing to it, and when the day comes, someone will sue them, an investigation will be held, and a large fine will be collected.

What I find strange is that google's army of lawyers doesn't seem worried about this.

A few notes:

> One email and 24 hours later, all the data they had about me was deleted.

You make it sound as if this is new, but this was also possible under the DPD from the late 90s. GDPR didn't improve that. (What helped is that GDPR isn't from the late 90s but was introduced in a year where privacy was already a hot topic, so it was picked up by the media and now companies actually know about it so you don't have to point out the law before they understand what you're talking about when you do an access/deletion request. But it technically hasn't changed.)

> this only works if you're in europe buying from an european store

Sort of. While the EU claims it applies to anyone, the Chinese government isn't going to give a rat's ass if you sue and win a court case against a Chinese company. However, if that Chinese company has assets in the EU, they can be seized, not to mention that they can probably be banned from the EU market altogether.

Anyone who wishes to continue selling to Europeans and not have any European assets seized would do well to comply with European law, also if their headquarters / choice of court / assets is/are outside the EU.

> You make it sound as if this is new, but this was also possible under the DPD from the late 90s. GDPR didn't improve that.

GDPR did improve it. Under the implementation by member states of the DPD many required that you can show "duress and/or distress" from continued processing to request erasure. GDPR made it so you don't have to show anything, you can just request it (or, more technically, you can withdraw consent).

And the DPD only said:

> as appropriate the rectification, erasure or blocking of data the processing of which does not comply with the provisions of this Directive, in particular because of the incomplete or inaccurate nature of the data;

Organisations often took a very conservative interpretation of this which wasn't enforced differently by many DPAs in EU states. GDPR Art. 17 is definitely stronger.

> Assholes like Google still do not ask for consent.

Google do ask for consent where required, but consent isn't required. There's various legal bases for the processing of data according to the GDPR (including for the performance of a contract and for legitimate business interests). Google just invested more in lawyers to use the GDPR strategically so they would have to change as little of their processes as possible.

Companies that don't understand the GDPR or privacy spent a fortune on consultants that milked them for money. Such companies seem to think the GDPR is a doomsday weapon and a revolution. It really isn't.

I'm positioned quite well to comment on this, our company looks at the back-end of various web services on a daily basis because we look at their infrastructure and associated bits and pieces prior to investment or acquisition.

In the run-up to the GDPR we saw an increase in companies that started to take security and privacy a lot more serious than before. Before the GDPR all data was viewed as an asset and more was better.

After the GDPR went live - and especially after the first fines were issued - this has substantially improved, most - but definitely not all - companies that can afford it now have their security at a reasonably high level, they've hired in-house specialists to help analyze the risks of their operation. Typically access to live databases is now far more restricted and so on.

There are some downsides as well, but that was to be expected (such as: the GDPR being used as an excuse to do things via web portals that used to be done via email, of course that same email can be used to reset the password to the portal...). Overall I'd say the improvement is vast.

After a data breach, a custodial cryptocurrency wallet site forced me to log in to change my password. I assumed it was a test account with no value inside, but wasn't sure. Upon login, they didn't let me access my account, asking me to fill in a KYC form with a lot of personal data. The form was empty, but I didn't know what data they had anyways, certainly wasn't going to give them more data, but couldn't see the wallet balances.

So I sent them a GDPR request, and they told me exactly what data they had and which data they didn't have (confirming that it was next to nothing, and thus that I didn't have to worry about the breach too much). They also confirmed which wallets are in the account (allowing me to confirm that they were empty, as expected, thus giving me no reason to fill ou the KYC).

Without GDPR, I'd be faced between the choice of giving them more data, or not being able to confirm that the wallet is empty (thus potentially losing out on cryptocurrency that I had forgotten about). In the end, I'd have probably provided the information, potentially exposing it when they will inevitably have the next breach.

Before that, Germany already had GDPR-style laws. I get very little spam, because people don't sell my address. I think there was one case where my address was passed along - I demanded to be told who passed it along, deleted, and the deletion request be passed on too, and the spam stopped. Doesn't work for completely fly-by-night companies and proper spammers, but does work for the ones who try to stay on the shady-but-not-illegal side (losing one address doesn't matter to them, and is certainly not worth the trouble of not complying with the deletion request).

I'm literally not using a spam filter.

It has given you a quite powerful lever against unsubstantiated paymant demands. It happens quite often that company A has a (debatable) claim to person B but ends up demanding money from person C. Happened to me once because B used my address and twice because A thought we had a contract, which we did not.

In each case, A had no legitimate reason to store or process my data. In particular the GDPR forbids them explicitly to exchange C's data with any third party. Doing so could lead to severe penalties.

In all three cases I only had to point out these facts once to stop the whole claim. Very comfortable.

Professionally, I have not had to deal with a GDPR request luckily, as we have a lot of anonymized legacy data that is hard to track back to specific participants in our studies.

Personally, I feel the conversation on data in many organizations has helped me feel more secure in my privacy considerations. Although it may not be because of the GDPR, I feel I can make facebook/google/<data_aggregator> accountable about my personal information, if I really wanted to. Although I have not done it yet.

Popups everywhere. Insane bureaucracy, even at the doctor. And when it matters, it's just being ignored. Most (medium-sized) companies haven't even realized there is a new law.
I haven't noticed any "insane bureaucracy" at the doctor, but there's a new box to tick in the signup forms

> And when it matters, it's just being ignored.

Where is that? Though you're welcome to point those out to your country regulator.

> Most (medium-sized) companies haven't even realized there is a new law.

Actually they have, I was surprised at getting emails from medium sized, non-online business about it

> > And when it matters, it's just being ignored. > Where is that? Though you're welcome to point those out to your country regulator.

Blanket forced consent in terms "we need to track you because we have a business need, take that or leave", despite being explicitly prohibited in all GDPR-related guidelines is still something you get away with.

Also one word: Facebook.

Yes, I agree that most websites continue to do that, though to be honest the cookie management works in several websites

But I use ad blocking/cookie blocking so I guess it works the way I want regardless of what they think

Popup situation is really bad

There should be a standard implementation of these popups so that I don't have to do it for each new website on each new browser again and again.

That would not be legally valid: you can't give a blanket consent for an unspecified party to do anything with your personal data.

Also, as I mentioned in another comment just now (https://news.ycombinator.com/item?id=21857843), the banner means they want to do something that you probably don't want, because that's why they have to ask consent. The banner is not needed for things like visitor counting, browsing products in a webshop, or other expected operations that involve personal data. It's only necessary when they do something that requires consent (see the link for an example).

We make file sharing and sync platform with GDPR specific functionalities. In high level GDPR and the fines have forced companies to take inventory of PII data they have and also limit the collection and storage of them. Also companies have started appointing DPOs. Thats a welcome addition.
Yes - from inside knowledge, the lead/customer data being sold from business to business has either massively changed or completely stopped.

Personally, I barely receive any out of the blue marketing calls or texts anymore. If someone dubious market’s me via phone or email, I know my rights and I can follow how they acquired my data and who sold them my personal details.

As a software developer/entrepreneur, it made me think more about personal data and has affected my architectural decisions.

> I barely receive any out of the blue marketing calls or texts anymore

That's strange, as anti-spam legislation is completely separate from GDPR and has been in place for much longer. The only connection I see is that data brokers got a harder time selling your data to these third parties that would call or text you, but what those third parties were doing was already illegal and still is for the same reason (so not because of GDPR).

In the Netherlands it hasn't been legal to cold call someone that opted out of cold calls (using a national register of phone numbers that don't want to be called) since 2009. Any marketing call you do receive has to offer enrolling you on this list to prevent future calls.

For email, again speaking of Dutch laws, companies are not allowed to send you unsolicited, promotional messages. Not sure as of which year this is, but it has been the case for as long as I remember.

I assume most EU countries have similar constructions (I'm not sure if our laws are based on a EU directive).

Immediately many EU companies just dumped their data that they were arbitrarily collecting because it became a liability overnight instead of something that may be an asset in the future.

Many of these companies didn't have consent to have the data to begin with or at least no way to show that they collected it.

A good example is Wetherspoons Pub chain dropping their email database they used to spam people with. I've noticed I'm not caught in any more breaches according to Troy Hunt whilst before I was getting my email breached once a year by some company. According to Troy Hunt's breach DB, over a dozen companies with my credentials have been breached forcing me to never use those email/password combinations again.

All marketing email has an unsubscribe link if it didn't before, and you know it actually works now to stop the emails, not just confirm your email address works.

You also know you can get all the information a company has on you, and get them to delete it if you need to. I haven't made use of it yet, but I've read of people who have.

From inside the business side, I see most companies thinking about GDPR compliance when developing new products and features. What was never the case before and you notice now is they try to minimize PII collected to avoid headaches, and they are very careful about how data is shared with 3rd parties, asking for consent before doing it, etc.

> All marketing email has an unsubscribe link if it didn't before

GDPR says nothing about marketing emails. I can only speak for the Netherlands, but our laws about unsolicited commercial communication is what applies there.

What GDPR has to do with it is that they need your contact details to send you anything, so they process personal data. The predecessor to GDPR (called DPD, from the late 90s) also required companies to ask consent if there was no need to process your data for things like fulfilling a contract (same as with GDPR: they only need consent if it's not for a certain set of exceptions).

> You also know you can get all the information a company has on you

This was also the case under the previous law.

I don't know about privacy, but it certainly increased the amount of popups I have to click through daily. Thanks, wise European bureaucrats.
Blame the content providers who are unnecessarily tracking you, and not the legislators that force them to now tell you.
Do you really think people on HN are scared of cookies? Ha. Save it for the CNN comments pages ok.

edit: If you're not worried about the cookies then can you take the requirement for state mandated popups on any site that uses cookies out of the GDPR, thanks.

edit 2: (due to being throttled for wrongthink)

According to the GDPR website to comply you must "Receive users’ consent before you use any cookies except strictly necessary cookies." How do you suggest websites get users consent other than popups? I'm sure everyone who is sicking of clicking through them and everyone who is sick of implementing them would love to hear about it. Why don't you "Show HN"?

It's not the cookies we're concerned about.
There is no mandate for pop ups on any site. Blame the content providers who are doing it wrong.
No,it has not, just made things annoing and complicate for companies. I think it's a goal of supervised EU communists to make our business less effective and competitive.
I operate a B2B SaaS. We sell a service to other SaaS companies. To deliver our service, we are sent PII from our customers which we process as a subprocessor under GDPR.

From the perspective of selling a B2B SaaS service, GDPR has been incredibly successful at making Security & Compliance an important discussion that is had during the sales process. Most leads will have security/compliance as an agenda item during sales calls, while before GDPR this was much less common.

GDPR has effectively turned Security & Compliance into a selling point and a point of competitor differentiation (it was this way in the past too, but much more so after GDPR). I think in the long run, this has/will result in companies having a heightened awareness of security/privacy and budgeting more time and money on security, simply because GDPR has connected it more directly to the business's bottom line.

I think it's good in the long run. In practice, the result is probably a decrease in risk of data breaches (less companies have your data, and the ones that do are more aware of their responsibility to treat it properly).

It's important to note that this benefits everyone (not just people of the EU). Very few companies will go through the trouble of treating EU data differently than non-EU data. Everyone is benefitting.

We're not a SaaS - but we noticed GDPR appearing as a requirement in RFx's

Our software does contain customer information, but isn't the focus. As somebody actually designed it properly, compliance wasn't particularly arduous. Huge sections simply didn't apply, and where it did we could just link each requirements to the relevant details, API, logs etc.

As you mention, I think the main benefit is just formalizing something that should already have been designed.

Another benefit is that it's driven 'bottom up' - Customer doesn't have to pay every vendor to provide them a new feature for say "scrubbing a customer". All their providers supply "here's how you scrub in my product" and customer just needs to stitch these mechanisms together to give their customers the ability to be scrubbed.

It does give you a (perhaps false?) sense of having some level of control over what is stored where and how much tracking happens. Also, as an unintended side-effect, it helped boost my productivity a bit, as when I open some link and the page keeps twisting my arm to accept all the cookies, I just close the whole tab and go do something more useful instead. And lots of sites, especially news and media related, do this - I skip like 1 in 5 pages because of badly implemented or hostile privacy dialogs.
I've used the new laws twice now to close online accounts with companies that were uncooperative or too 'clingy' (looking at you, OVH and Microsoft). Much easier to send a registered letter than waiting on hold or searching for an online option that was deliberately made hard to find, or which may not exist at all.

I have also used it to stop unwanted postal ads from local companies. I get to find out how they obtained my info, and also stop some junk mail.

For the sibling comments mentioning the GDPR popups / cookie notices, why not add a blocklist for these to your adblocker? At this point adblockers should be considered basic security software, like a firewall or antivirus. These lists exist are are pretty comprehensive.

As an American living in Europe I think it's a great law and I wish there was something comparable to protect my friends and family stateside. And as someone who administers a fair amount of business and client data, I do not find the law inconvenient to comply with. I am very pro-privacy and protective of user data, and I didn't have to make any major adjustments.

> Much easier to send a registered letter than waiting on hold or searching for an online option that was deliberately made hard to find

This hasn't changed. Every EU country implemented the Data Protection Directive and you could just have sent a letter since the late 90s (the exact date depending on your country).

In terms of what a company has to do, not that much changed since GDPR's predecessor. The difference between the previous law from the 90s and GDPR is mainly publicity (privacy wasn't as big a topic in the 90s) and higher fines, so what I notice as an EU resident is that more companies implement it. (Also companies abroad, but I can't say that e.g. Google's update impacted me beyond annoying banners: they still say "you consent to us doing anything we like" and that is probably legal.)

The previous law was optional to implement for member states but I lived in a member state (the Netherlands) that did (as "Wet Bescherming Persoonsgegevens") and I think most other states did as well. Any company that wants to do business in the Netherlands had to comply with that law already (just like you can't come here to do business that is illegal for any other reason).

The main features as I see them are that companies have to obtain consent or have a valid reason for processing personal data, and you have a right to view your data. That was the case and is still the case. I've done data access requests prior and post GDPR and the responses are identical.

A number of details changed, but if you complied with the previous law and you're not a personal data broker, then you have to do very little to comply with GDPR. To give an example, consent now has to be "freely" and unambiguously given, whereas before it just had to be unambiguously given, which means that an employer can't ask you for consent due to the power relation and it's popularly interpreted to also mean that you can't bundle it ("consent or don't get the service") because then it's not "freely" given.

But it did change for everyone else that didn't have those laws. Also, the impact of a brach is much bigger now.
> it did change for everyone else

OP was asking for EU residents to comment on how it impacted them. This is how it impacted me. If someone else is very happy with GDPR because their country didn't implement the previous law (DPD), they should comment separately.

Edit: actually, all EU member states implemented the DPD: https://en.wikipedia.org/wiki/Data_Protection_Directive#Impl...

So this is actually representative for everyone else.

> Also, the impact of a [breach] is much bigger now

Indeed, as I mentioned, the fines are higher, and that's the only change in that regard.

Note that the requirement to report data breaches to the authorities is not a GDPR thing. The Netherlands introduced a separate law for that prior to GDPR.

And the reason you can be fined for a breach is not because you had a breach. It's not a crime to become the victim of criminal activity, so that's also not new with GDPR. The reason for it resulting in a fine is that it often highlights inadequate security of personal data, which was also illegal under the previous law.

I was able to get my account and data deleted from a crypto exchange with relatively little fuss.

Had I not been protected by GDPR I would have had to submit documents to prove my identity, none of which was even required to operate the account in the first place.

I had high hopes for the GDPR, a 4%-of-turnover fine would get any company’s attention, but in practice the regulators are completely toothless and bad actors such as Google and Facebook continue completely unchecked.
This has improved privacy awareness, curbed data hoarding and reduces tracking across the board. It also made people aware of which companies don't have their IT in correct order. (i.e. those that outright ban EU traffic, or don't prompt to ask if they can hoard your data)
> [those that] don't prompt to ask if they can hoard your data [don't have their IT in correct order]

It's kind of the opposite: if they need to ask for your consent, that means they're doing something that is not part of the standard exceptions.

For example, if they only use your data to do what you asked them to do, they don't need consent. If I ask Contoso to ship me a horse, they don't need my consent to process my address.

Every time you see a cookie banner, the message is: we want to invade your privacy.

If you want to find those that don't have their data protection in order, look for sites without privacy policy, or policies that were updated prior to ~2016 (that's when the GDPR text was finalized, i.e. the earliest time they could have updated it to be compliant with new requirements). A cookie wall is a signal that it's bad, not that it's good.