The responsibility rests with companies to obtain clear consent from you, and you must opt in to receive information from them, the law states that “pre-ticked boxes are not considered to be valid consent under GDPR”. The law also recognises that consent is not always possible, for example an employee cannot consent to be supervised by CCTV for a productivity issue – since there is a power imbalance between the employer and the employee. The penalties for companies are steep, up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher. No wonder companies are working hard to set up good privacy systems.
As an individual, a consumer and an employee I like the principles of the law. I’m glad to see a comprehensive overall of how our data is used, and that the EU is using its power to counteract the power behind US tech giants who haven’t taken as much care of my data as I’d like. But oh boy it’s exhausting to read everyone’s terms and conditions and sort out what I’m going to agree to. And not all companies present it in the easiest way. Here’s the notification on data sharing from FastCompany
-
Fast Company
-
EMX Digital LLC
-
BIDSWITCH GmbH
-
Adform A/S
-
AdRoll Inc
-
Adobe Advertising Cloud
-
AppNexus Inc.
-
Flashtalking, Inc.
-
SalesForce DMP
-
Quantcast International Limited
-
Bombora Inc.
-
Oath (EMEA) Limited
-
Index Exchange, Inc.
-
DoubleVerify Inc.​
-
Confiant Inc.
-
Purch Group, Inc.
-
Dataxu, Inc.
-
MediaMath, Inc.
-
Research Now Group, Inc
-
Revcontent, LLC
-
LiveRamp, Inc.
-
Criteo SA
-
OpenX Software Ltd. and its affiliates
-
DigiTrust / IAB Tech Lab
-
Liveintent Inc.
-
Eyeota Ptd Ltd
-
Integral Ad Science, Inc.
-
BeeswaxIO Corporation
-
Celtra, Inc.
-
Revcontent, LLC
-
Conversant Europe Ltd.
-
Lotame Solutions, Inc.
-
Justpremium BV
-
RhythmOne, LLC
-
PubMatic, Inc.
-
PulsePoint, Inc.
-
GumGum, Inc.
-
SlimCut Media SAS
-
Sharethrough, Inc
-
Sizmek Technologies, Inc.
-
Sonobi, Inc
-
Smart Adserver
-
The Rubicon Project, Limited
-
Unruly Group Ltd
-
Teads
-
Tapad, Inc.
-
The Trade Desk, Inc and affiliated companies
-
SpotX
-
TripleLift, Inc.
-
Sovrn Holdings Inc
-
Sublime Skinz
-
Taboola Europe Limited
-
comScore, Inc.
-
district m inc.
Some companies weren’t able to make their sites GDRP compliant in the two years since the law was passed and I got this message
Fast Company made a list of companies that hadn’t made the deadline, of their list Klout and Super Monday Night Compat have shut down for good, and A&E Networds, Crowdpac and History.com have managed to put a solution in place in the week following the deadline).
On the upside perhaps I will end up with less spam. A friend of mine who returned to New Zealand a decade ago commented “maybe the recruiters who haven’t believed my unsubscribe requests will finally figure it out”. Let’s hope.
I have had a few emails that stated “confirm now or we’ll never email you again”.
Me: “You promise??!!”