Techcrunch. There be #DataVampires.
I note the @DPCIreland has been investigating Verizon for a little over a year now https://www.independent.ie/business/technology/irish-data-protection-commissioner-opens-investigation-into-verizon-media-38407520.html
But let's take a quick peek because there's that IAB TCF 2.0 that enables #DataVampirism
I note the @DPCIreland has been investigating Verizon for a little over a year now https://www.independent.ie/business/technology/irish-data-protection-commissioner-opens-investigation-into-verizon-media-38407520.html
But let's take a quick peek because there's that IAB TCF 2.0 that enables #DataVampirism
There's the language of entitlement from the outset.
"We & our partners WILL store &/or access information on your device through the use of cookies & similar technologies, to display personalised ads & content, for ad & content measurement .." <my EMPHASIS. Not we'd like to
"We & our partners WILL store &/or access information on your device through the use of cookies & similar technologies, to display personalised ads & content, for ad & content measurement .." <my EMPHASIS. Not we'd like to
Selecting 'I Agree' = the feast of the #DataVampires
So, 'Manage Settings' (innocuous sound choice that doesn't reveal the depth pf tracking that lies beneath)
Good to see 'consent' defaults set to OFF.
BUT
So, 'Manage Settings' (innocuous sound choice that doesn't reveal the depth pf tracking that lies beneath)
Good to see 'consent' defaults set to OFF.
BUT

there are those "three types of partners that provide different options to set your privacy preferences" that involve a mix of consent, legitimate interests or opt-out.
'Framework Partners'.
'Non-Framework Partners'
'Google Partners'
Google Partners
'Framework Partners'.
'Non-Framework Partners'
'Google Partners'

Google Partners: By providing consent to Google, Google will also share your data with its additional partners (see 'Show Google Partners') to set cookies & similar technologies & collect information about your device & activity on our products & services to provide & measure ads

There are SEVEN HUNDRED AND EIGHTEEN 'google partners' listed under that 'Google Partners' link.
"By providing consent to Google ..." It isn't clear how someone provides consent to Google because it isn't set out as a 'framework partner' that

for which 'Legitimate Interests' is defaulted to ON but 'Consent' is defaulted to OFF.
But then it says "You can manage Google and Google Partners' use of your data through Google's View by partner consent control below." THAT partner consent is the 'framework partners'.
But then it says "You can manage Google and Google Partners' use of your data through Google's View by partner consent control below." THAT partner consent is the 'framework partners'.


So, 'Legitimate Interest' defaults set to ON for 9 of the 10 purposes. (Recap for a mo the initial dialogue window - defaulted to I agree. #DarkPatterns)
'Select basic ads'. LI? Unclear to me how the ePD consent rules don't apply.
The default ON applies to 474 'IAB Partners'
'Select basic ads'. LI? Unclear to me how the ePD consent rules don't apply.
The default ON applies to 474 'IAB Partners'
Then there are those 'special purposes'. Self-regulatory assurances & ambiguous language.
Ensure security, prevent fraud, and debug "Vendors cannot Conduct any other data processing operation allowed under a different purpose under this purpose." <cannot or are not supposed to
Ensure security, prevent fraud, and debug "Vendors cannot Conduct any other data processing operation allowed under a different purpose under this purpose." <cannot or are not supposed to
'cannot' but then, "Note: Data collected & used to ensure security, prevent fraud, & debug may include automatically-sent device characteristics for identification, precise geolocation data, & data obtained by actively scanning device characteristics for identification without
separate disclosure and/or opt-in." This is far too ambiguous to be compliant. But also, given reliance on the GDPR (*cough*) one assumes that each of the 368 IAB Partners listed, inc Techcrunch, has done a legitimate interest assessment and a DPIA - no @DPCIreland ?
Then there's the special purpose, 'Link different devices'.
I must test these privacy statements on friends & family ..
"Vendors can:
* Deterministically determine that two or more devices belong to the same user or household
* Probabilistically determine that two or more
I must test these privacy statements on friends & family ..
"Vendors can:
* Deterministically determine that two or more devices belong to the same user or household
* Probabilistically determine that two or more
devices belong to the same user or household.
Actively scan device characteristics for identification for probabilistic identification if users have allowed vendors to actively scan device characteristics for identification (Special Feature 2)"
Actively scan device characteristics for identification for probabilistic identification if users have allowed vendors to actively scan device characteristics for identification (Special Feature 2)"


But the explanations alone, do not aid informed decision making.
Almost done. You have Framework Partners and Google Partners. There's also, Non-Framework Partners (Twitter & FB) that "require you to opt-out directly through their privacy policies (click on each partner below) to limit their use of your data." Maybe the @DPCIreland

should also look at the privacy options of Twitter and Facebook that people are directed to when seeking to opt-out of ad tracking, profiling and targeting on techcrunch? @DPCIreland
EOT
EOT