Can you be more specific? The only related court cases I'm aware of are U.S. The Crew lawsuit which seems to have reached settlement recently and the French case regarding which I haven't seen any updates since it's filing.
This is actually slightly narrower exception than people (and regulators) think. The exception is:
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
What I hate about EU laws is they tend to word these things like this.
People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business.
People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario.
Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all.
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
If you did this people would only use the same half dozen sites and competitors would emerge.
We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.
Other processing (like after value is read) can happen under GDPR if the data is personal data.
My understanding is that ePD was obsoleted by GDPR.
Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.
No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 2025.
ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.
If someone is in EU and is affected by this they could potentially utilize GDPR to make both Microsoft and LG take responsibility for this.
It's hard to say directly from the article if there is any GDPR breach. If everything was part of the installer and it doesn't actually submit anything (including downloading the ad) to LG then it's harder to argue that there is GDPR violation, but knowing the SOP of these kinds of software that is unlikely.
If the software did indeed send personal data to LG then there are at least following question: How was Article 13 notice delivered to user? Article says that this was installed quietly. Did Microsoft deliver Article 13 compliant notice to user at some point? They probably did deliver their own notice (though it's open question if it's compliant), but not LG's. However since Microsoft is the one that installed the software and they exercise control over the standards which must be met, it's possible that they would end up being joint controller at least for some processing.
I should add that Article 13 requires that the notice is given "at the time when personal data are obtained". The only exception is when "data subject already has the information" and possible Article 23 restrictions, but those are unlikely to apply.
If someone wants to make a complaint they should first make Article 15 request to LG. Copy of personal data is useful, but 15(1) information is the primary goal. Additionally ask for information on how and when did LG provide you the Article 13 notice if they did indeed process your personal data.
After that if they cannot show that they provided Article 13 notice when they received your personal data submit a complaint to your local DPA. You can additionally flag other violations as well if they are applicable (e.g. not naming recipients as part of Article 15 response, not giving actual retention time or meaningful information how that is determined, invalid legal basis etc.). You should also flag in the complaint that Microsoft is likely joint controller for some of the processing given that they are the ones who approved the automatic install of the software which violated GDPR.
There are multiple ways to use feedback. Personally I would often be fine with actual human reading my feedback, taking in account the points I made and evaluating how it should affect their feature development and future roadmap.
Now what I would expect AI companies to do is to take things which were submitted as feedback and pretty much adding to training:
"Do more of this: <copy of the whole response which was flagged as good in feedback>"
"Do less of this: <copy of the whole response which was flagged as bad in feedback>"
It's paraphrased, but the point is that they will most likely use it more-or-less as-is and thus whatever is in there will be part of the model's training set rather than someone picking up the parts from response that are important and only including them (which happens with traditional feedback).
If you have a naive loop like this you will quickly poison your dataset with e.g. thumbs downs because someone is unhappy with the latest frontend update, or teach models to not correctly refuse. I’m sure the pipeline is more sophisticated and in the middle.
Sure, but the point is more that once you submit feedback then the usual "opt out of using my data for training" no longer apply and at least that reply (and possibly whole conversation) can be included in training set in one way or another.
They don't use your general chats it if you have opted out (note: opted out, not opted in). However if you submit feedback then whole conversation can be used.
> Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.
> If you explicitly report materials to us (e.g.via our thumbs up/down feedback mechanisms), or by otherwise explicitly opting in to training, then we may use those materials to train our models.
No for what? The opt-in for model training? About a year ago Anthropic changed "Allow use of your chats and coding sessions to train and improve Anthropic AI models" to default to on: https://www.anthropic.com/news/updates-to-our-consumer-terms
Or do you mean the feedback stuff? Their KB article at least seems to contradict that.
No it's opt-in now. Yes they nag you and might ask you if they can use your transcript to train on but you have to agree to it and it's something you can disable.
That's good if true. When did it change? I very much do remember that back when the change happened the modal I received didn't actually say anything (https://news.ycombinator.com/item?id=45064212) and thus I was by default opted-in until I saw the news and went to disable it, fortunately before the training actually started.
I'm not sure but I had this same conversation with CC just days ago and it told me to check my settings because it changed. My account is 4 months old and it was disabled so I assume it's been opt-in for at least 4 months.
Aren't the cameras on city's land or did city lease the land to Flock? If they are on city's land couldn't city require that Flock removes their stuff from city's property or city will do it on Flock's expense?
I've seen videos of flock cameras installed improperly (missing a breakaway device) right next to roads. The city must be able to remove unsafe devices!
It's unfortunately somewhat common these days and personally I actively avoid any place which does this. At least it's only somewhat common rather than the standard so it's still possible. Couple of examples:
https://www.pacificcatch.com/menu/ "NorCal - A 3% surcharge (5% in San Francisco) will be added to all Guest checks to help offset the rising cost of wages and benefits. This is not gratuity."
Restaurant owners interviewed in the media here in SF are directly quoted saying they can’t do that because “customers would notice”, or think “oh that’s expensive, I can’t eat out twice a week”.
These are arguments for including the fees that make the customer __still pay the same higher price__, implying that the whole point is that they won’t notice. And reporters don’t seem to even register the absurdity of those remarks or question them in any way.
It’s the same thing with any “menu” vs actual price.
Airline baggage fees are probably the prototypical case for this. Airlines that did not display the lowest price during flight searches got outcompeted by those that did. This led the entire industry to change since it took an entire decade long marketing campaign centered around it (Southwest) to try to stay even.
Consumers make irrational choices all the time, and this is one of them. They absolutely notice the final bill and complain while continuing to patronize businesses that engage in such behavior.
Consumers would need to reward honest pricing if they wanted this to change. Or vote for regulation.
The restaurant fee isn’t a fee for something “extra”, it’s just a blanket extra charge on everything.
It’d be like the airline sold you a ticket for $500, but as you step off the plane at the destination they say “actually it was $550”, because it said so in the fine print.
More akin comparison would be charging for carryon vs condiments.
I just did trip with family where our allowance was 8 suitcases of 184 kg total weight. Buying same on a budget carrier we used on our leg would cost more than flights itself.
Yea, it's basically restaurant owners trying to get their customers involved in their political whining.
Notice how you never see things like "Business License Fee" or "Restaurant Electricity Bill Surcharge" listed out as separate line items on customers' bills. Those are things restaurant owners have to pay, too, so why don't they get their own charges to customers? Why does only "Living Wage" get a line item on the customer's bill?
"Fuel surcharge" on flights. Which should be illegal: the cost of hedging fuel cost risk should be included in any ticket price.
A friend said that Uber was charging a fuel surcharge here in New Zealand, but that it wasn't passed on to the driver (who pays for the fuel). If true I would find that interesting.
> A friend said that Uber was charging a fuel surcharge here in New Zealand, but that it wasn't passed on to the driver
I did a bit of a dive on this and I think it’s not correct.
I have a low threshold for hating them, after the reports of how females staffers were treated a few years back, but this new thing seems to be untrue.
Great link. Sounded suss to me. Could easily have been a bullshit taxi driver, or a social outrage story. I should have tried to validate before repeating, sorry.
Unfortunately you’ve spoken too soon on this one. I recently had an energy surcharge added due to the “Iran war” (as explained by the server) added to every check.
Hey now, let's not get carried away, these jackass restaurant owners want to make it clear, the "Living Wage" guilt trip is the tip part, and the fees THEY put on are to pay for "benefits like healthcare" and you're not allowed to consider it part of the tip.
Nevermind that California doesn't even have a lower "tipped" min wage like some states do, so by supporting tipping, we're just saying that servers simply "deserve" more money for some reason than people who stock shelves or pick orders at Amazon or Walmart.
> Nevermind that California doesn't even have a lower "tipped" min wage like some states do, so by supporting tipping, we're just saying that servers simply "deserve" more money for some reason than people who stock shelves or pick orders at Amazon or Walmart.
Isn't this the thing the government is saying in California? They passed a law requiring restaurants to pay the same minimum wage as jobs where workers don't get tips, on top of the tips, essentially making it the law that people in tipped occupations have to be paid more than what can be paid to people doing any other kind of work.
Unless the point is to get customers to stop tipping because a) the workers are now guaranteed the same minimum wage as anyone else even if they don't and b) they can't afford the tip on top of the prices that now have the higher minimum wage priced into them anyway.
That's why you don't say _in town_. That's verifiable and specific. You just say _lowest prices_ (nobody cares if you aren't specific), or add fine print that specifies a time/location (Amazon renewed: comparison price is the brand new version of same item on Amazon itself) or _only at $store_ (your competitors aren't participating in your branded sale).
> This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.
reply