#GlobalPrivacyControl

2025-01-17

@fasnix und Ablehnen nur ein klick, ohne #Nudging oder #DarkPattern.
Scheint nicht zu funktionieren, ich bin dafür, dass das ab sofort nur noch opt-in geht, das "in" darf von mir aus in der Fußzeile der Webseite zu finden sein. Alternativ könnte sich "die Industrie" auf einen Standard zum Opt-In auf Browserebene einigen, ich wette das wird schneller funktionieren als #DoNotTrack oder #GlobalPrivacyControl 😉
@peaceout @br_data

Zuri (he/him) 🕐 CETshaedrich@mastodon.online
2024-12-22

One of the best lies of the anti-privacy internet is "We do not know how to react if someone's browser signals us 'Do Not Track'"—I mean, could this be more literal?

It's like a bank robber saying "What do you mean: 'Don't take the money'? I don't understand. What do you expect me to do? Work? That's ridiculous! Best I can do is taking your money"

#DNT #DoNotTrack #privacy #GDPR #GPC #GlobalPrivacyControl #privacyMaters #MyPrivacyisNoneOfYourBusiness #surveillanceCapitalism #dataCapitalism

:mima_rule: Mima-samamima@makai.chaotic.ninja
2024-12-12

So apparently the #DoNotTrack (DNT) signal is legally recognized in #Germany, citing the #GDPR and arguing that DNT is a "valid objection" to the "processing of personal data". IANAL, but I find this ruling potentially problematic. ​:sakuya_think:​

We know that IP addresses are "personal data"; it is explicitly included as an example by the GDPR. This along with the ruling has some chilling ramifications. If my understanding is correct, it means a website cannot use a CDN to optimize serving its content based on the user's location, because that would be "processing of personal data" (the IP address). And it's not like a website could just "opt-out" of Germany; even the very act of opting-out would be a GDPR violation, because again you're processing a user's IP address in order to show the geolocation notice of content being blocked for Germany. Show the content if the German user has signalled DNT? Still a GDPR violation (the DNT signal can act as an identifier which makes it "personal data" along with the German IP)
​:TenshMelt:​

This ambiguity of how to interpret DNT makes me happy that
#Mozilla is finally going to ditch it in #Firefox in favor of #GlobalPrivacyControl (GPC) which has a clearer and limited definition while still covering what privacy-conscious users really want in the first place: not wanting their data sold and shared to advertisers. It's just legally difficult to "prohibit tracking" when a user says so; should ETag not be included and performance be sacrificed because they can be used for tracking like a cookie? But then if an ETag is not included that would create a data point that can be tracked then? ​:TenshMelt:​

Let tracking be defeated by technical solutions (private browsing/incognito mode, content blockers like uBlock Origin, and proxy software if you really need it). Political solutions are much more appropriate elsewhere like the selling and sharing of data.
​:seija_coffee:​

2024-12-11

@TechCrunch they did add #globalPrivacyControl though--technically similar but sites are required to act on it in more and more jurisdictions

2024-10-09

you know you've been doing #privacy nerd stuff for too long when someone posts an actual working Lego Turing Machine, and your eye jumps to the #globalPrivacyControl link in the cookie banner

ideas.lego.com/projects/10a323

iam-py-test :unverified:iampytest1@infosec.exchange
2024-07-29

Interesting GPC (Global Privacy Control) reaction.

#GlobalPrivacyControl

A popup message on the website dnb.com
The message reads: "We see that you have the Global Privacy Control enabled in your browser. We have turned off all but ‘Required’ cookies which are necessary to enable the basic features of this site to function.  If you wish to further exercise any applicable data subject rights (DSR) please complete the form available at Your Privacy Choices. For further information on how Dun & Bradstreet uses your personal information, please see our Cookie Policy."
2024-06-26

@carnage4life Blocking AI crawlers with robots.txt and "noai" HTTP headers and tags currently seem to depend on ToS being enforceable.

But companies already have to act on an "opt out preference signal" under several state #privacy laws—so I'm working on extending #globalPrivacyControl to make it work from server to client, not just client to server. The law and the robots header+tag are already there, so not much work needed for sites to add it blog.zgp.org/x-robots-tag-for-

2024-06-21

@jensimmons Support for #globalPrivacyControl would help us give Safari users a much less confusing #consent experience--people can turn it on once and sites just do the right thing (more and more of them anyway)

2024-04-11

@mhoye good idea. For example we have #globalPrivacyControl for browsers but it should be possible to apply the setting to all software that communicates on your behalf

blog.zgp.org/gpc-all-the-thing

2024-04-09

Technical protections alone won't be enough to protect web users from #surveillance. Legal protections are also necessary, and simple tools are needed to help people exercise their rights. For example, it's time to standardize the #GlobalPrivacyControl. cdt.org/insights/deprecating-t

2024-04-03

imho #GlobalPrivacyControl is too good to be kept just on the web

blog.zgp.org/gpc-all-the-thing

(also if the web has it but other communications media don't, companies will try to force or nudge you off the web and into native apps or buy buttons on appliances or whatever)

2024-03-29

I've been studying #AB3048 which is the #California #GlobalPrivacyControl mandate bill

The really good thing about this bill is that it covers "a device through which a consumer interacts with a business" and not just browsers

cppa.ca.gov/announcements/2024

2024-03-22

@SPF @volkris @null

If you make a direct connection to a server you can pass #GlobalPrivacyControl (GPC) in an HTTP header. That doesn't work out of the box in a federated system.

IMHO ActivityPub needs a way to pass header info (such as GPC and noai) in objects. http-equiv?

github.com/w3c/activitypub/iss

2024-02-27

good design work by whoever did the #globalPrivacyControl popup on mazdausa.com/ -- it really makes GPC look like a high-end luxury feature. I'm impressed

Dawn Tåke 🌙 :sparkletrans:Tourma@tech.lgbt
2024-02-08

I think this is the first time I've ever seen this. Might have the popup blocked at home though.

#Firefox #GlobalPrivacyControl #Kia

A screenshot of a Kia website that I visited for a patron.  At the bottom it states that my "Opt out preference signal honored." Due to my "Global Privacy Control" settings.

First time I've ever seen a site state this.  Go Kia.  Your commercials are annoying af, but I'll give you this.
2024-01-14

@jwildeboer even better, respect #DoNotTrack and #GlobalPrivacyControl headers for automatic opt-out!

2023-12-15

@mastodonmigration If you connected directly to a server owned by that company, you could set a #globalPrivacyControl header (which has legal effect in some places)

What if ActivityPub were extended so that GPC (and other opt out headers) could travel with the objects they apply to?

github.com/w3c/activitypub/iss

2023-12-13

How do you do #globalPrivacyControl for the Fediverse?

I'm thinking about one way that it might work that also addresses the likely comment that if ActivityPub is going to have GPC then it should also have #noai. And probably opt-out headers I haven't heard of.

Just filed an issue, will be interesting to see what people think

github.com/w3c/activitypub/iss

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst