惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
Google DeepMind News
Google DeepMind News
GbyAI
GbyAI
Y
Y Combinator Blog
T
Threatpost
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
MyScale Blog
MyScale Blog
Security Latest
Security Latest
T
Threat Research - Cisco Blogs
量子位
I
Intezer
Simon Willison's Weblog
Simon Willison's Weblog
C
Cybersecurity and Infrastructure Security Agency CISA
L
Lohrmann on Cybersecurity
L
LINUX DO - 最新话题
The Register - Security
The Register - Security
T
Tailwind CSS Blog
爱范儿
爱范儿
Google DeepMind News
Google DeepMind News
T
Troy Hunt's Blog
Stack Overflow Blog
Stack Overflow Blog
Cloudbric
Cloudbric
S
Secure Thoughts
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
L
LangChain Blog
Recorded Future
Recorded Future
小众软件
小众软件
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Tor Project blog
人人都是产品经理
人人都是产品经理
F
Full Disclosure
O
OpenAI News
Webroot Blog
Webroot Blog
A
Arctic Wolf
TaoSecurity Blog
TaoSecurity Blog
P
Privacy & Cybersecurity Law Blog
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
H
Heimdal Security Blog
B
Blog RSS Feed
Vercel News
Vercel News

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
APRA fumbles targeted advertising
Carlo Cilent · 2024-05-15 · via Blog of Simple Analytics

The US Congress unveiled a new, bicameral federal privacy bill last month: APRA (short for American Privacy Rights Act). The proposal has been the talk of the town lately in the privacy space, but there’s a sour note for the marketing and ad tech folks: the rules on targeted advertising are incomprehensible.

Here is what APRA is about, what it says about targeted advertising, and how we feel about the law overall.

  1. Why is APRA such a big deal?
  2. What is in APRA?
    1. What is the scope of APRA?
    2. What rights do you have?
    3. Data minimization
  3. What does APRA mean for advertising?
    1. Targeted advertising: opt-outs and limitations
    2. Targeted advertising and sensitive data
  4. How is APRA overall?
    1. The good
    2. The bad
    3. The so-and-so
  5. Conclusions

The UK Government chose Simple AnalyticsJoin them

Let’s dive in!

Why is APRA such a big deal?

To this day, the US lacks a federal privacy law. This creates a dangerous regulatory gap and turns the digital economy into a data free-for-all that is ripe for harmful abuse- as we have seen in the post-Dobbs privacy and human rights nightmare.

The FTC is doing its best to fill the void and control the damage but lacks the authority to truly fix the situation. In the meantime, many States got tired of waiting for Congress and passed their own privacy laws- including California, home to the Silicon Valley giants.

APRA could close the regulatory gap, bring some degree of uniformity across the US, and enact some much needed privacy protections for Americans. Last but not least, the law may significantly impact the global digital economy as a whole, given the weight of GAFAM and other tech giants.

What is in APRA?

We can only provide a very general overview of APRA because it is a very complex piece of legislation. Let’s try and break down some of the most important stuff.

What is the scope of APRA?

The scope of APRA is quite wide but it does not apply to everyone, or to all kinds of data. Small businesses, the government, and services providers working for the government are exempt.

The notion of covered data, it is quite broad, not unlike the notion of personal data in the GDPR. However, employee data is exempt from APRA (which is a questionable choice). Additionally, APRA does not replace more specific laws like HIPAA.

What rights do you have?

APRA includes several rights such as the right to access covered data, the right to correct and delete, data portability, and the right to opt out of targeted advertising and data disclosures.

APRA also includes a private right of action: you can sue a business if it violates your rights. This is important because the US legal tradition has somewhat complicated rules on who can and cannot sue.

Certain types of covered data are considered sensitive data and can only be disclosed with opt-in consent (with some carve-outs). The list includes, among other, health data, precise geolocation information, data related to sexual behavior, the content of personal communications, government-issued identifiers like social security or plate numbers, and any data from a minor of 17.

Two specific types of sensitive data deserve special attention: cross-website user behavior, and behavioral and activity data collected by “high impact” social media. These are the data that you would typically use for retargeting. So, an explicit opt-in requirement for disclosures is a big deal for ad tech.

Data minimization

APRA includes a data minimization principle: the processing of covered data needs to be necessary, proportionate, and limited. The principle comes with a laundry list of “permitted purposes”- that is, specific types of processing that respect the principle of data minimization.

In practice, we have a broad rule and a long list of complicated exceptions. This results in a very complex and sometimes contradictory system. In all likelihood, it will take some time and case law to make sense of it all.

What does APRA mean for advertising?

Targeted advertising: opt-outs and limitations

At a surface level, APRA is clear enough: targeted advertising is allowed on an opt-out basis. Contextual advertising does not come with the same requirement.

Notably, advertising is only allowed based on data already collected under APRA. The rule is not 100% clear yet, but at face value it seems as though you cannot collect data solely for advertising. You can only advertise based on data you already control for a different purpose.

If that is the intent, then we really like the idea. Restricting advertising to the data you already control for other purposes, could limit the data hoarding we see everywhere and help reduce digital footprints without outlawing targeted advertising entirely.

Targeted advertising and sensitive data

Things get more complicated when it comes to sensitive data because it is not clear how the rules on sensitive data interact with the limitations on targeted advertising:

  • Disclosures of sensitive data in general are opt-in, unless one of several specific purposes applies (Sec. 3(b)(1)).
  • One of these purposes is targeted advertising. Targeted advertising is allowed on an opt-out basis but with the exception of sensitive data (Sec. 3(d)(15)).

These rules lead to potentially contradictory conclusions, as noted by the guys at Bloomberg Law. Their take on privacy is atrocious but they still make two valid points: first, taken at face value, APRA may very well ban targeted advertising based on sensitive data (which they would hate and we would absolutely love). Second, the law needs clarity.

Lack of clarity is a big deal because restrictions to the use of sensitive data apply to cross-site activity and behavioral data from social media- the stuff that powers most targeted ads around. The rules would massively impact ad tech but it would be nice to know just how.

TL:DR: targeted advertising based on sensitive data is either opt-in or outright illegal. Your guess is as good as ours.

How is APRA overall?

The law has quite a few good things going for it, mixed with some terrible ideas and unclear rules.

The good

The principle of data minimization shows a clear intention to move past the fiction of consent and give companies a list of do’s and don'ts instead. This is a great idea as consent is often extorted through unfair terms of contract or by hiding shady clauses in the fine print. With APRA, that stuff is out the window.

Incidentally, APRA forbits collecting consent through dark patters even in the specific scenarios where consent does matter. This is also a good call! We are tired of wrestling with impossibly obscure UIs that want more data for no good reason.

We also like that the list of sensitive data is fairly long and includes things like precise geolocation data, the content of personal communication, and cross-site online activity. We wish these data were sensitive under the GDPR as well.

Last but not least, APRA protects vast amounts of health data that fall outside the scope of HIPAA. These data have been a major issue since Dobbs v. Jackson ruling.

The bad

Many Sections of APRA are exempt from private action, including some crucial rules about data minimization. In other words, some of the most important APRA rules can only be enforced by Advocate Generals, the Federal Trade Commission, and other institutions- citizens can’t sue directly

The intent is to prevent a tidal wave of litigation against companies, which is understandable. Still, we feel that the exemption is too broad and could defang the law in practice.

Furthermore, as we mentioned, the rules on targeted advertising and sensitive data are obscure and contradictory. It doesn’t stop here: the rules on sensitive data are so poorly formulated, that they can be construed as being more permissive than the general rules in certain scenarios. This makes absolutely no sense and further adds to the uncertainty.

Last but not least, APRA does not apply to employee data. This is a god awful idea because bossware use is an urgent issue. If Congress feels that employee privacy is better addressed by a different law, so be it- but workers need that law yesterday.

The so-and-so

Finally, there is the thorny issue of State preemption. In a nutshell, preemption means that APRA “overwrites” State privacy laws (save for niche ones).

State preemption is a double edged sword. On the one hand, US privacy law is a messy patchwork right now, which makes compliance complicated for companies that do business nation-wide. Preemption would make the rules largely the same and ease the compliance burden.

On the other hand, some States have enacted laws that are quite strong and sometimes stronger than APRA. They don’t want to see them preempted by federal law and are pushing for APRA to set a floor rather than a ceiling in terms of privacy rights.

This is by no means a new problem. Not long ago the APRA's predecessor (ADPPA) was met with fierce opposition over preemption and the bill eventually went nowhere. Hopefully Congress will find a way this time around, even if that entails compromises.

Conclusions

In a relatively short time we have seen the TikTok ban, restrictions of data sales to “foreign adversaries”, the proposal of APRA, and House approval of the 4th Amendment Is Not For Sale Act (a less discussed but quite important development).

While some of these laws are controversial, there is no denying that privacy is gaining momentum at a policy level. This might just be the right time for Congress to seal the deal on a much needed federal privacy law. That being said, APRA's kinks still need to be ironed out and the issue of State preemption may throw a wrench in the negotiations.

All eyes are on Congress now. Given the US’ weight in the digital economy, a strong federal privacy law would be a major step forward not only for the US, but for global privacy as well.

We built Simple Analytics because we believe in a privacy-friendly web. We help our customers understand their traffic and expand their audience without collecting a single bit of personal data. Our web analytics tool is easy to learn, customizable, and comes with a hand AI assistant. If this sounds good to you, feel free to give us a try!