home.social

#global-privacy-control — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #global-privacy-control, aggregated by home.social.

fetched live
  1. Global Privacy Control is actually being respected around the web?! This is too good. Now if we could just get... *the rest of the web* to do this...

    🎵Thank you @arstechnica for bein a friend.🎵

    #Privacy #Security #GPC #GlobalPrivacyControl

  2. Cookie-Banner

    Digitaler Omnibus: Neues Bündnis will das Ende der Cookie-Banner einläuten

    Mit ihrem Digitalen Omnibus will die EU-Kommission vor allem der Wirtschaft das Leben versüßen. Zu einem ihrer Vorschläge zählt jedoch auch, die vermaledeiten Cookie-Banner weitgehend aus der Welt zu schaffen. Dagegen läuft die Werbewirtschaft Sturm und bekommt nun ihrerseits Gegenwind zu spüren.

    Cookie-Banner sind nicht nur lästig, sie verschwenden auch Zeit und Geld. Jährlich könnten Nutzer:innen in der EU fast 200 Millionen Stunden sparen, wenn sie sich nicht mehr mit irritierenden Cookie-Abfragen herumschlagen müssten, rechnet die EU-Kommission vor. Dies würde rund 500 Millionen Euro pro Jahr entsprechen, die sich einsparen ließen.

    Regeln vereinfachen, Geld sparen und damit die Wettbewerbsfähigkeit der EU steigern: Mit dem im Vorjahr vorgelegten „Digitalen Omnibus“, wie das Gesetzespaket genannt wird, verfolgt die EU-Kommission eine Deregulierungs-Agenda, die vor allem der Wirtschaft das Leben einfacher machen soll.

    Während Kritiker:innen bemängeln, die meisten Vorschläge würden sich wie eine Wunschliste aus der Feder von Big Tech lesen, fällt ein Punkt aus der Reihe. So hatte die Kommission vorgeschlagen, die beinahe omnipräsenten Cookie-Abfragen weitgehend abzuschaffen.

    Nutzer:innen könnten dann etwa in ihrem Browser einstellen, ob sie von bestimmten Websites oder Anbietern getrackt werden dürfen oder nicht. Umgekehrt müssten die Anbieter solche „Privacy Signals“ respektieren und gegebenenfalls die Überwachung ihrer Nutzer.innen beenden.

    „Privatsphäre ist ein Grundrecht, und die Menschen sollten sich nicht durch endlose Banner kämpfen müssen, um dieses Recht wahrzunehmen“, sagt Itxaso Dominguez de Olazabal von der Brüsseler Digital-NGO EDRi (European Digital Rights).

    Ärgerliche Schlupflöcher

    Eigentlich schützen Gesetze wie die ePrivacy-Richtlinie und die Datenschutz-Grundverordnung (DSGVO) bereits die Privatsphäre von Menschen, denn grundsätzlich ist Tracking erst nach einer informierten Einwilligung erlaubt. Eine Hürde, die die Werbewirtschaft seit Jahren gekonnt unterläuft: „Die Branche hat Einwilligungsbanner in ein Labyrinth aus Klicks verwandelt“, sagt Dominguez de Olazabal.

    Kein Wunder, dass der Vorschlag der Kommission, mit dem Nutzer:innen Zeit sparen und zugleich den Schutz ihrer Privatsphäre erheblich verbessern könnten, auf Widerstand stößt. Neben Lobby-Organisationen der Tracking-Wirtschaft setzten sich EU-Länder wie Deutschland und Polen im EU-Rat dafür ein, die Idee möglichst vollständig abzusägen.

    Ihre Bilanz beim noch laufenden Prozess bleibt bislang durchwachsen. Im Sommer präsentierte die damalige zypriotische Ratspräsidentschaft einen Kompromissvorschlag, der den von der Kommission unterbreiteten Artikel 88b ersatzlos gestrichen hätte. Dieser soll die „Cookie-Revolution“ regeln.

    Beschlossen haben die EU-Länder ihre Position zum Omnibus letztlich nicht, da in einigen Punkten noch keine Einigung gefunden werden konnte. Derweil hat die seit Juli amtierende irische Ratspräsidentschaft angekündigt, das Omnibus-Paket zu einer ihrer Prioritäten zu machen.

    Appell an EU-Institutionen

    Diesen Moment will eine Reihe zivilgesellschaftlicher Gruppen nutzen. Als neu gegründete „Kill the Cookie Banner“-Koalition appellieren sie in einem offenen Brief an Kommission, Rat und Parlament, die „nervigen und irreführenden Cookie-Banner“ endlich zu Grabe zu tragen. Auch im Parlament steht noch eine finale Einigung auf eine Verhandlungsposition aus.

    „Der Vorschlag zu automatisierten Signalen ist der einzige Punkt im ‚Digitalen Omnibus’ der Kommission, der tatsächlich darauf abzielt, das Leben der Verbraucher zu vereinfachen“, sagt Cláudio Teixeira vom Dachverband europäischer Verbraucherschutzorganisationen BEUC. Der Verband hat den Brief mitgezeichnet, mit an Bord sind unter anderem auch EDRi und die österreichischen Datenschützer:innen von noyb (none of your business).

    Es sei „äußerst besorgniserregend“, sagt Teixeira, dass politische Entscheidungsträger erwägen, den Vorschlag der Kommission fallen zu lassen. Die Kampagne soll dem ein starkes Signal aus der Zivilgesellschaft entgegensetzen: „Vereinfachung darf nicht zulasten unserer Rechte gehen. Die Stärkung der Verbraucherrechte sollte für die Politik Priorität haben“, sagt Teixeira.

    Nicht der erste Anlauf

    Ähnliche Ansätze wie jener, den die Kommission vorschlägt, schwirren schon seit vielen Jahren herum. Verhältnismäßig weit war etwa der Versuch gekommen, mit dem „Do Not Track“-Standard Websites gegenüber zu signalisieren, dass man nicht verfolgt werden will. Obwohl viele Browser den freiwilligen Standard unterstützt haben, konnte er sich nicht durchsetzen: Die AdTech-Branche hat ihn schlicht ignoriert.

    Das dürfte in manchen Regionen künftig unmöglich werden. Automatisierte Opt-Out-Signale, etwa mittels Global Privacy Control (GPC) wären bereits standardisiert und seien in mehreren US-Bundesstaaten rechtlich bindend, führt die Koalition in ihrem Brief aus. Dazu zählt unter anderem Kalifornien, wo viele US-amerikanische Tech-Konzerne ihren Sitz haben.

    Zugleich werden derzeit weitere und umfassendere Ansätze entwickelt, insbesondere das Advanced Data Protection Control (ADPC) genannte Framework. Neben einigen europäischen Universitäten ist daran auch noyb beteiligt. Grundsätzlich würde dies gut zum Vorschlag der Kommission passen, die einen europäischen Standard etablieren will.

    „Alle Voraussetzungen dafür, dass Artikel 88b ein Erfolg wird, sind gegeben“, schreibt die Koalition. Automatisierte Signale seien nichts Neues, technische Konzepte für „Privacy Signals“ wurden bereits in den 2000er-Jahren entwickelt. Bislang fehlten in der EU jedoch der Rechtsrahmen und ein Standard.

    Win-win für Europa

    Genau das kann und muss die EU jetzt liefern, fordert die Koalition. Ein idealerweise noch weiter verbesserter Artikel 88b sollte die „Verwendung von Signalen zur Erteilung, zum Widerruf und zur Verweigerung der Einwilligung sowie für den Widerspruch gegen die Verarbeitung personenbezogener Daten vorschreiben“, verlangen die NGOs.

    Nicht zuletzt ließe sich daraus politisches Kapital schlagen, so die Initiative. Sollte erneut der Versuch scheitern, ein praktikables und verbindliches System für automatisierte Signale zu etablieren, bliebe es weiterhin bei den so verhassten Cookie-Bannern.

    Umgekehrt werde jedoch ein Schuh draus: „Die Europäer würden applaudieren, wenn ‚Brüssel’ endlich Maßnahmen ergreift, um ihr Leben zu erleichtern und ihre Entscheidungen zum Schutz der Privatsphäre zu wahren“, hängt der Brief der EU eine Karotte vor die Nase.

    Tomas Rudl ist in Wien aufgewachsen, hat dort für diverse Provider gearbeitet und daneben Politikwissenschaft studiert. Seine journalistische Ausbildung erhielt er im Heise-Verlag, wo er für die Mac & i, c’t und Heise Online schrieb. Kontakt: E-Mail (OpenPGP), Bluesky. Dieser Beitrag ist eine Übernahme von netzpolitik, gemäss Lizenz Creative Commons BY-NC-SA 4.0.

  3. ICYMI: Explaining GPC: GPC, or Global Privacy Control, is a browser signal telling sites not to sell or share personal data. How the header works, and where law makes it binding. ppc.land/explaining-gpc/ #Privacy #DataProtection #GlobalPrivacyControl #PrivacyRegulations #CyberSecurity

  4. TIL using Ghostery in Safari, the ‘Never Consent’ setting when enabled, send a GPC (Global Privacy Control) signal to auto-decline non-essential cookies on compliant sites.

    Certainly see a lot less of those banners now!

    #privacy #globalPrivacyControl

  5. If you “honour” my #DoNotTrack* signal, why don't you just shut the fuck up, dear docs.spring.io? 🙄

    * More accurately: #GlobalPrivacyControl header or #GPC

  6. Efekt Kalifornii. Jak jedna ustawa zmusi Google i Microsoft do zmiany przeglądarek dla milionów

    Na pierwszy rzut oka wygląda to na lokalną regulację, ale eksperci są zgodni: to prawo, które właśnie weszło w życie w Kalifornii, prawdopodobnie ustali nowy, ogólnokrajowy standard prywatności dla całego internetu w USA.

    Mowa o ustawie Assembly Bill 566, która wymusza na twórcach przeglądarek, takich jak Google i Microsoft, wprowadzenie jednej, kluczowej funkcji.

    Chodzi o uniwersalny „sygnał” opt-out, który automatycznie informowałby każdą odwiedzaną stronę, że użytkownik nie życzy sobie sprzedaży ani udostępniania jego danych osobowych. Giganci technologiczni mają czas do początku 2027 roku, aby zaimplementować tę funkcję w swoich flagowych produktach, takich jak Chrome czy Edge.

    Dlaczego Kalifornia znów rządzi internetem?

    Eksperci, tacy jak Emory Roane z organizacji Privacy Rights Clearinghouse, przewidują, że zmiana będzie miała „wpływ ogólnokrajowy”. Powód jest prosty: firmom technologicznym znacznie łatwiej będzie wdrożyć tę funkcję dla wszystkich użytkowników w USA, niż tworzyć skomplikowany system, który udostępniałby ją tylko mieszkańcom Kalifornii.

    Co więcej, kalifornijskie prawo dotyczy mieszkańców stanu, niezależnie od tego, gdzie fizycznie się znajdują. Próba wykrycia, czy kalifornijczyk na wakacjach w Nowym Jorku nadal jest chroniony, byłaby dla firm prawnym i technicznym koszmarem. Dlatego najbezpieczniejszym i najtańszym wyjściem jest wprowadzenie tej funkcji jako standardu dla wszystkich.

    Koniec z irytującym klikaniem na każdej stronie

    Kalifornia już wcześniej, dzięki ustawie CCPA, dawała mieszkańcom prawo do rezygnacji ze sprzedaży ich danych. Problem w tym, że obowiązek ten leżał po stronie użytkownika. To użytkownicy musieli na każdej pojedynczej stronie szukać linku „Nie sprzedawaj moich danych” i klikać w niego ręcznie.

    Nowa ustawa AB 566 przerzuca ten obowiązek na technologię. Zamiast setek kliknięć, Kalifornijczycy (i zapewne nie tylko oni) dostaną jeden przełącznik w ustawieniach przeglądarki.

    „Jeśli musisz wchodzić na każdą stronę z osobna, aby kliknąć link, to tak naprawdę nie masz żadnych realnych praw do prywatności” – skomentowała Caitriona Fitzgerald z Electronic Privacy Information Center.

    Warto zaznaczyć, że nie jest to technologia z kosmosu. Przeglądarki takie jak Mozilla Firefox już dobrowolnie oferują podobną funkcję (w ramach standardu Global Privacy Control), która wysyła witrynom sygnał „nie śledź”. Nowe prawo po prostu zmusza do tego samego największych graczy, którzy do tej pory nie byli tym zainteresowani.

    Google po cichu walczyło z ustawą

    Co ciekawe, choć Google publicznie nie sprzeciwiało się ustawie, dziennikarze śledczy z CalMatters i The Markup ujawnili we wrześniu, że firma działała aktywnie za kulisami procesu legislacyjnego. Google miało organizować sprzeciw wobec ustawy, wykorzystując do tego grupę biznesową, którą finansuje.

    Teraz, gdy ustawa została podpisana, aktywiści już patrzą w przyszłość. Skoro udało się to w przeglądarkach, następnym krokiem może być podobne prawo zmuszające inteligentne urządzenia (Smart TV, głośniki) oraz nowoczesne samochody do respektowania sygnału opt-out i zaprzestania zbierania danych o użytkownikach.

    Koniec z prywatnością? Modyfikacja za 60 dolarów pozwala wyłączyć diodę nagrywania w okularach Meta

    #AB566 #CCPA #GlobalPrivacyControl #GoogleChrome #GPC #Internet #Kalifornia #MicrosoftEdge #news #ochronaDanych #prywatność #usa

  7. One of the best lies of the anti-privacy internet is "We do not know how to react if someone's browser signals us 'Do Not Track'"—I mean, could this be more literal?

    It's like a bank robber saying "What do you mean: 'Don't take the money'? I don't understand. What do you expect me to do? Work? That's ridiculous! Best I can do is taking your money"

    #DNT #DoNotTrack #privacy #GDPR #GPC #GlobalPrivacyControl #privacyMaters #MyPrivacyisNoneOfYourBusiness #surveillanceCapitalism #dataCapitalism

  8. So apparently the #DoNotTrack (DNT) signal is legally recognized in #Germany, citing the #GDPR and arguing that DNT is a "valid objection" to the "processing of personal data". IANAL, but I find this ruling potentially problematic. ​:sakuya_think:​

    We know that IP addresses are "personal data"; it is explicitly included as an example by the GDPR. This along with the ruling has some chilling ramifications. If my understanding is correct, it means a website cannot use a CDN to optimize serving its content based on the user's location, because that would be "processing of personal data" (the IP address). And it's not like a website could just "opt-out" of Germany; even the very act of opting-out would be a GDPR violation, because again you're processing a user's IP address in order to show the geolocation notice of content being blocked for Germany. Show the content if the German user has signalled DNT? Still a GDPR violation (the DNT signal can act as an identifier which makes it "personal data" along with the German IP)
    ​:TenshMelt:​

    This ambiguity of how to interpret DNT makes me happy that
    #Mozilla is finally going to ditch it in #Firefox in favor of #GlobalPrivacyControl (GPC) which has a clearer and limited definition while still covering what privacy-conscious users really want in the first place: not wanting their data sold and shared to advertisers. It's just legally difficult to "prohibit tracking" when a user says so; should ETag not be included and performance be sacrificed because they can be used for tracking like a cookie? But then if an ETag is not included that would create a data point that can be tracked then? ​:TenshMelt:​

    Let tracking be defeated by technical solutions (private browsing/incognito mode, content blockers like uBlock Origin, and proxy software if you really need it). Political solutions are much more appropriate elsewhere like the selling and sharing of data.
    ​:seija_coffee:​

  9. @TechCrunch they did add #globalPrivacyControl though--technically similar but sites are required to act on it in more and more jurisdictions

  10. you know you've been doing #privacy nerd stuff for too long when someone posts an actual working Lego Turing Machine, and your eye jumps to the #globalPrivacyControl link in the cookie banner

    ideas.lego.com/projects/10a323

  11. @carnage4life Blocking AI crawlers with robots.txt and "noai" HTTP headers and tags currently seem to depend on ToS being enforceable.

    But companies already have to act on an "opt out preference signal" under several state #privacy laws—so I'm working on extending #globalPrivacyControl to make it work from server to client, not just client to server. The law and the robots header+tag are already there, so not much work needed for sites to add it blog.zgp.org/x-robots-tag-for-

  12. @jensimmons Support for #globalPrivacyControl would help us give Safari users a much less confusing #consent experience--people can turn it on once and sites just do the right thing (more and more of them anyway)

  13. @mhoye good idea. For example we have #globalPrivacyControl for browsers but it should be possible to apply the setting to all software that communicates on your behalf

    blog.zgp.org/gpc-all-the-thing

  14. Technical protections alone won't be enough to protect web users from #surveillance. Legal protections are also necessary, and simple tools are needed to help people exercise their rights. For example, it's time to standardize the #GlobalPrivacyControl. cdt.org/insights/deprecating-t

  15. imho #GlobalPrivacyControl is too good to be kept just on the web

    blog.zgp.org/gpc-all-the-thing

    (also if the web has it but other communications media don't, companies will try to force or nudge you off the web and into native apps or buy buttons on appliances or whatever)

  16. I've been studying #AB3048 which is the #California #GlobalPrivacyControl mandate bill

    The really good thing about this bill is that it covers "a device through which a consumer interacts with a business" and not just browsers

    cppa.ca.gov/announcements/2024

  17. @SPF @volkris @null

    If you make a direct connection to a server you can pass #GlobalPrivacyControl (GPC) in an HTTP header. That doesn't work out of the box in a federated system.

    IMHO ActivityPub needs a way to pass header info (such as GPC and noai) in objects. http-equiv?

    github.com/w3c/activitypub/iss

  18. good design work by whoever did the #globalPrivacyControl popup on mazdausa.com/ -- it really makes GPC look like a high-end luxury feature. I'm impressed

  19. @jwildeboer even better, respect and headers for automatic opt-out!

  20. @mastodonmigration If you connected directly to a server owned by that company, you could set a #globalPrivacyControl header (which has legal effect in some places)

    What if ActivityPub were extended so that GPC (and other opt out headers) could travel with the objects they apply to?

    github.com/w3c/activitypub/iss

  21. How do you do #globalPrivacyControl for the Fediverse?

    I'm thinking about one way that it might work that also addresses the likely comment that if ActivityPub is going to have GPC then it should also have #noai. And probably opt-out headers I haven't heard of.

    Just filed an issue, will be interesting to see what people think

    github.com/w3c/activitypub/iss

  22. @kopper #DoNotTrack mainly failed due to legal unclarity combined with the commercial desire to harvest as much data as possible. This is nicely summed up here: law.stackexchange.com/question
    The new mechanism #GPC #GlobalPrivacyControl is designed to fix these shortcomings, hence it is in the same place. Basically it is DNTv2.

    However a recent courtcase in Berlin about the original DNT might fix it after all based on the #GDPR wideangle.co/blog/do-not-track
    This means website operators can no longer safely ignore DNT signals.

    Having privacy laws is great, pitty that it takes decades of legal proceedings before any meaningful enforcement happens.

  23. #ConsumerReports "Permission Slip" mobile app for #CCPA Authorized Agent opt outs launches today

    (part of a privacy "complete breakfast" with #globalPrivacyControl, each one addresses different situations)

    consumerreports.org/electronic

  24. Enable Global Privacy Controls in your browsers.

    Do it NOW!

    globalprivacycontrol.org

    Personally I use Firefox however installing the EFF Privacy Badger Extension enable the same functionality as in Firefox 😀

    This is the main topic of discussion in this weeks episode of Security Now (Episode 934)

    youtu.be/hGyVuszu0F8

    #Privacy #GlobalPrivacyControl #Tracking #ContentBlocking