‹ BackHN Continuity

Thread

ChatGPT now knows what you do on other websites via ad collector

764 points · 395 comments · lmbbuchodi

  1. thih9 · · focus · HN ↗
    I am once again happy that the EU is fighting practices like these via legislation.

    Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least.

    1. dmix · · focus · HN ↗
      The adtech/data broker business is still very lively in EU. The last time I read into it a year or two ago the consensus seemed to be the privacy gains over the last decade have been modest at best. There was a few big name trackers that were forced to narrow data collection but the general ad/location tracking and data broker business is still mostly the same.

      <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.06862" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.06862

      <a href="https:&#x2F;&#x2F;netzpolitik.org&#x2F;2025&#x2F;databroker-files-targeting-the-eu&#x2F;" rel="nofollow">https:&#x2F;&#x2F;netzpolitik.org&#x2F;2025&#x2F;databroker-files-targeting-the-...

      1. buzer · · focus · HN ↗
        There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.

        Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.

        Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller&#x27;s response to the DPA inquiry.

        Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.