EU to Facebook: 'Drop Dead'
A leak from the European Data Protection Board reveals that the EUâs top privacy regulator is about to overrule the Irish Data Protection Commission and declare Facebookâs business model illegal, banning surveillance-based ads without explicit consent:
https://noyb.eu/en/noyb-win-personalized-ads-facebook-instagram-and-whatsapp-declared-illegal
In some ways, this is unsurprising. Since the GDPRâs beginning, itâs been crystal clear that the intention of the landmark privacy regulation was to extinguish commercial surveillance and ring down the curtain on âconsent theaterââââthe fiction that you âagreeâ to be spied on by clicking âI agreeâ or just by landing on a web-page that has a link to some fine-print.
Under the GDPR, the default for data-collection is meaningful consent, meaning that a company that wants to spy on you and then sell or use the data it gathers has to ask you about each piece of data they plan to capture and each use they plan to make of it.
These uses have to be individually enumerated, and the user has to actively opt into giving up each piece of data and into each use of that data. That means that if youâre planning to steal 700 pieces of information from me and then use it in 700 ways, you need to ask me 1,400 questions and get a âYesâ to each of them.
Whatâs more, I have to be given a single tickbox at the start of this process that says, âNo to all,â and then I have to be given access to all the features of the site or service.
The point of this exercise is to reveal consent theater for the sham it is. For all that apologists for commercial surveillance insist that âpeople like ads, so long as theyâre well-targetedâ and âthe fact that people use high-surveillance services like Facebook shows a ârevealed preferenceâ for being spied on,â we all know that no one likes surveillance.
Thereâs empirical proof of this! When Apple added one-click tracker opt-out on its Ios platform, 96% of users opted out, costing Facebook more than $10b in the first year (talk about a ârevealed preference!â) (of course, Apple only opted those users out of tracking by its rivals, and secretly continued highly invasive, nonconsenual tracking of its customers):
https://pluralistic.net/2022/11/14/luxury-surveillance/#liar-liar
Properly enforced, the GDPR would have upended the order of the digital world: any argument about surveillance between product managers at a digital firm would have been settled in favor of privacy, because the pro-privacy side could argue that no one would give consent, and the very act of asking would scare off lots of users.
But the GDPR wasnât properly enforced, thanks to structural problems with European federalism itself. The first line of GDPR enforcement came from privacy regulators in whatever country a privacy-violator called home. That meant that when Big Tech companies violated the GDPR, theyâd have to account for themselves to the privacy regulator in Ireland.
For multinational corporations, Ireland is what old-time con-artists used to call a âmade town,â where the cop on the beat is in on the side of the criminals. Irelandâs decision to transform itself into a tax haven means that it canât afford to upset the corporations that fly Irish flags of convenience and maintain the pretense that all their profits are floating in a state of untaxable grace in the Irish Sea.
Thatâs because there are plenty of other EU countries that compete with Ireland in the international race to the bottom on corporate governance: Malta, Luxembourg, the Netherlands, Cyprus, etc (and of course, thereâs post-Brexit UK, where the plan is to create an unregulated haven for the worst, wealthiest companies in the world).
All this means that seeking Irish justice from a corporation that wronged you is like asking a court in Moscow to punish an oligarchâs commercial empire on your behalf. Irish regulators are either âdingo babysittersâ (guards in league with the guarded) or resource-starved into ineffectual torpor.
Thatâs how Facebook got away with violating the GDPR for so many years. The company hid behind the laughable fairy-tale that it didnât need our consent to spy on us because it had a âlegitimate purposeâ for its surveillance, namely, that it was contractually obliged to spy on us thanks to the âagreementâ we clicked on when we signed up for the service.
That is, you and Facebook had entered into a contract whereby Facebook promised you that it would spy on you, and if it didnât spy on you, it would be violating that promise.
But while the GDPR has a structural weaknessâââallowing corporations to choose to be regulated in countries that canât afford to piss them offâââit also has a key strength: the private right of action, that is, the right of individuals to sue companies that violate the law, rather than having to convince a public prosecutor to take up their case.
https://www.eff.org/deeplinks/2019/01/you-should-have-right-sue-companies-violate-your-privacy
The private right of action is vital to any privacy regulation, which is why companies fight it so hard. Whenever a privacy bill with a private right of action comes up, they tell scare-stories about âambulance chasersâ whoâll âclog up the system,â trotting out urban legends like the McDonaldâs Hot Coffee story:
https://pluralistic.net/2022/06/12/hot-coffee/#mcgeico
But here we are, in the last days of 2022, and the private right of action is about to do what the Irish regulators wouldnât do: force Facebook to obey the law. For that, we can thank Max Schrems and the nonprofit he founded, noyb.
Schrems, you may recall, is the Austrian activist, who, as a Stanford law student, realized that EU law barred American tech companies from sending their surveillance data on Europeans to US data-centers, which the NSA and other spy agencies treated as an arm of their own surveillance projects:
https://pluralistic.net/2020/07/16/text-adventures-resurgent/#nein
Schrems brought a case against the Irish regulator to the EUâs top privacy authority, arguing that it had failed its duty by ruling that Facebookâs âcontractual obligationâ excuse held water. According to the leaked report, Schrems has succeeded, which means, once again, Facebookâs business model is illegal.
Facebook will doubtless appeal, but the writing is on the wall here: itâs the end of the line for surveillance advertising in Europe, an affluent territory with 500m+ residents. This decision will doubtless give a tailwind to other important privacy cases in the EU, like Johnny Ryanâs case against the ad-tech consortium IAB over its âaudience taxonomyâ codes:
https://pluralistic.net/2021/06/16/inside-the-clock-tower/#inference
Itâs also likely good news for Schremsâ other ongoing cases, like the one heâs brought against Google:
https://pluralistic.net/2020/05/15/out-here-everything-hurts/#noyb
Facebook has repeatedly threatened to leave the EU if it is required to stop breaking the law:
https://pluralistic.net/2020/09/22/uncivvl/#fb-v-eu
This is a pretty implausible threat, growing less plausible by the day. The company keeps delivering bad news to investors, who are not mollified by Mark Zuckerbergâs promise to rescue the company by convincing all of humanity to spend the rest of their lives as highly surveilled, legless, sexless, low-polygon cartoon characters:
https://www.fool.com/investing/2022/12/06/why-meta-platforms-stock-dove-today/
Zuckerberg and his entire senior team have seen their net worth plummet with Metaâs share price, and that means the company needs to pay engineers with actual dollars, rather than promises of shares, which kills the massive wage-bill discount the company has enjoyed. This is not a company that can afford to walk away from Europe!
Between Appleâs mobile (third-party) tracker-blocking and the EU calling time on surveillance ads, things are looking grim for Facebook. You love to see it! But things could get even worse, and soon, thanks to the double-edged sword of ânetwork effects.â
Facebook is a network effects business: people join the service to socialize with the people who are already thereâââthen more people join to socialize with them. But what network effects give, they can also take away: a service that gets more valuable when a new user signs up loses value when that user leaves.
This is beautifully explained in danah boydâs âWhat if failure is the plan?â which recounts boydâs experiences watching MySpace unravel as key nodes in its social graph disappeared when users quit: âFailure of social media sites tends to be slow then fastâ:
http://www.zephoria.org/thoughts/archives/2022/12/05/what-if-failure-is-the-plan.html
Facebook long understood this, which is why it spent years creating artificial âswitching costsââââpenalties it could impose on users who quit, such as the loss of their family photos:
https://www.eff.org/deeplinks/2021/08/facebooks-secret-war-switching-costs
This is why Facebook and other tech giants are so scared of interoperability, and why they are so furious about the new EU Digital Markets Act (DMA), which will force them to allow new services to connect to their platforms, so that users who quit Big Tech wonât have to lose their friends or data:
https://www.eff.org/deeplinks/2022/04/eu-digital-markets-acts-interoperability-rule-addresses-important-need-raises
An interoperable Facebook would make it easy to leave social media by removing the penalties Facebook imposes on its disloyal users, and the EUâs privacy framework means that when they flee to a smaller safe haven, they wonât have to worry about commercial surveillance:
https://www.eff.org/interoperablefacebook
But what about advertising-supported media? Sure, being spied on sucks, but a subscription-first media landscape is a world where âthe truth is paywalled, but the lies are freeâ:
https://www.currentaffairs.org/2020/08/the-truth-is-paywalled-but-the-lies-are-free/
Ironically, killing surveillance ads is good news for ad-driven media. Surveillance-based ad-targeting is nowhere near as effective as Google, Facebook and the other ad-tech companies claim (these companies are compulsive liars, it would be amazing if the only time they told the truth is when they were boasting about their products!):
https://onezero.medium.com/how-to-destroy-surveillance-capitalism-8135e6744d59
And consent-theater or no, targeted ads reach fewer users every day, thanks to ad- blockers, AKA, âthe biggest boycott in world historyâ:
https://blogs.harvard.edu/doc/2015/09/28/beyond-ad-blocking-the-biggest-boycott-in-human-history/
And when a publisher does manage to display a targeted ad, they get screwed. The Googbook dupololy is a crooked affair, with the two tech companies illegally colluding (via the Jedi Blue conspiracy) to divert money from publishers to their own pockets:
https://techcrunch.com/2022/03/11/google-meta-jedi-blue-eu-uk-antitrust-probes/
Targeted ads are a cesspit of ad-fraud. 15% of all ad revenues are just unaccounted for:
https://twitter.com/swodinsky/status/1511172472762163202
The remaining funds arenât any more trustworthy. Ad-tech is a bezzle (âthe magic interval when a confidence trickster knows he has the money he has appropriated but the victim does not yet understand that he has lost itâ):
https://pluralistic.net/2021/01/04/how-to-truth/
As Tim Hwang foretold in his essential Subprime Attention Crisis, the pretense that targeted ads are wildly effective has been slowly but surely losing ground to the wider awareness of the fraud behind the system, and a reckoning is at hand:
https://pluralistic.net/2020/10/05/florida-man/#wannamakers-ghost
Experiments with contextual ads (ads based on the content of the page youâre looking at, not on your behavior and demographics) have found them to about as effective in generated clicks and sales as surveillance ads.
https://pluralistic.net/2022/04/29/taken-in-context/#creep-me-not
But this is misleading. Contextual ads donât require consent opt-in (because theyâre not based on your data) and they donât drive users to install blockers the way creepy surveillance ads do, so lots more people will see a contextual ad than a surveillance one. Thus, even if contextual ads generate slightly less money per reader or viewer, they generate far more money overall, because they are arenât blocked.
Even better for publishers: contextual ads donât erode their own rate cards. Today, when you visit a high-quality publisher like the Washington Post, many ad brokers bid to show you an ad, but only one wins the auction. However, all the others have tagged you as a âWashington Post reader,â and they can sell that to bottom-feeder junk sites. That is, they can collude with Tabooleh or its rivals to offer advertisers a chance to advertise to Post readers at a fraction of what the Post charges. Lather, rinse, repeat, and the Postâs own ad revenues are drained.
This doesnât apply with contextual ads. Indeed, none of the tech giantsâ much-vaunted âdata advantageââââthe largely overstated value of knowing what you did online 10 or 20 years ago, the belief in which keeps new companies out of the marketâââapplies to context ads:
https://pluralistic.net/2021/04/11/halflife/#minatory-legend
The transformative power of banning surveillance advertising goes beyond merely protecting our privacy. It also largely answers the case for âlink taxesâ (pseudo-copyright systems that let giant media companies decide who can link to them and charge for the privilege).
The underlying case for link taxes, snippet taxes, etc, is that Big Tech is stealing the news mediaâs content (by letting their users talk about and quote the news), when the reality is that Big Tech is stealing their money (through ad-fraud):
https://doctorow.medium.com/big-tech-isnt-stealing-news-publishers-content-a97306884a6b
Unrigging the ad-tech market is a much better policy than establishing a link-tax, like the Democrats are poised to do with their Journalism Competition and Preservation Act (JCPA):
https://www.politico.com/newsletters/politico-influence/2022/12/06/jcpa-opponents-spring-into-action-to-block-ndaa-inclusion-00072602
Itâs easy to understand why the monopoly/private-equity-dominated news industry wants JCPA, rather than a clean ad market. The JCPA just imposes a tax on the crooked ad-tech giants that is paid to the largest media companies, while a fair ad market would reward the media outlets that invested most in news (and thus in expensive, unionized news-gathering reporters).
Indeed, the JCPA only works if the ad-tech market remains corrupt: the excess Big Tech rents that Big News wants to claim here are the product of a rigged system. Unrig the system and there wonât be any money to pay the link tax with.
Image:
Anthony Quintano (modified)
https://commons.wikimedia.org/wiki/File:Mark_Zuckerberg_F8_2018_Keynote_%2841118883004%29.jpg
CC BY 2.0
https://creativecommons.org/licenses/by/2.0/deed.en
[Image ID: A theater proscenium. Over the proscenium, in script, are the words 'Consent Theatre.' On the screen is an image of Mark Zuckerberg standing in front of the words 'Data Privacy.' He is gesturing expansively. A targeting reticle is centered on his face. The reticle is made of the stars from the EU flag.]