User Tools

Site Tools


practices:legal_enforcement

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
practices:legal_enforcement [2026/09/10 17:45] – cross-link the new Privacy:Policies page (Authored by Claude) karel.kubicek.claudepractices:legal_enforcement [2026/09/11 18:00] (current) – Carve-out drift: the domain-to-company ownership material moved from Programming:Crawler:webXray to the new Design:Ownership resolution on 2026-09-11; repoint the link. Authored by Claude karel.kubicek.claude
Line 215: Line 215:
  
   - **A named complainant who is a data subject**, with the evidence that they are one. Not "we crawled 100k sites" but "the following was written into //my// terminal at //this// timestamp".   - **A named complainant who is a data subject**, with the evidence that they are one. Not "we crawled 100k sites" but "the following was written into //my// terminal at //this// timestamp".
-  - **The controller, identified.** Reg. 2025/2518 Art. 4(1)(d) asks for //"information which facilitates the identification of the controller or processor"//. For a third-party tracker this is real work: the domain is not the company. See [[Programming:Crawler:webXray]] for the ownership databases and how much they disagree.+  - **The controller, identified.** Reg. 2025/2518 Art. 4(1)(d) asks for //"information which facilitates the identification of the controller or processor"//. For a third-party tracker this is real work: the domain is not the company. See [[Design:Ownership resolution]] for the ownership databaseshow much they disagree, and how often each is right.
   - **The provision breached, named as an article of the //national// law.** "Art. 5(3) ePrivacy Directive, as transposed by § 25 TDDDG" is a case; "the site is not GDPR compliant" is not. This is also where the ePrivacy/GDPR split has to be made explicit — and note that the German provision is the same example this page would have written as "§ 25 TTDSG" two years ago: the statute was renamed to TDDDG in 2024, section number unchanged.((Verified 2026-08-18 at [[https://www.gesetze-im-internet.de/ttdsg/__25.html|gesetze-im-internet.de]], whose URL path still reads ''ttdsg'' while the heading reads "§ 25 TDDDG — //Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei digitalen Diensten//".))   - **The provision breached, named as an article of the //national// law.** "Art. 5(3) ePrivacy Directive, as transposed by § 25 TDDDG" is a case; "the site is not GDPR compliant" is not. This is also where the ePrivacy/GDPR split has to be made explicit — and note that the German provision is the same example this page would have written as "§ 25 TTDSG" two years ago: the statute was renamed to TDDDG in 2024, section number unchanged.((Verified 2026-08-18 at [[https://www.gesetze-im-internet.de/ttdsg/__25.html|gesetze-im-internet.de]], whose URL path still reads ''ttdsg'' while the heading reads "§ 25 TDDDG — //Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei digitalen Diensten//".))
   - **Reproducible evidence, not a table of percentages.** A HAR or a request log with timestamps, the screenshots of the banner state, the exact user journey, and the crawler configuration. See [[Programming:Traffic files]] and [[Design:Automated measurements]].   - **Reproducible evidence, not a table of percentages.** A HAR or a request log with timestamps, the screenshots of the banner state, the exact user journey, and the crawler configuration. See [[Programming:Traffic files]] and [[Design:Automated measurements]].
practices/legal_enforcement.1789062349.txt.gz · Last modified: by karel.kubicek.claude