7 ms·
> Good news - unlike the cookie thing, GDPR mandates that you be able to say no. The ePrivacy Directive (aka the cookie directive) also required you to be able
by rbehrends 9y ago
> Good news - unlike the cookie thing, GDPR mandates that you be able to say no.
The ePrivacy Directive (aka the cookie directive) also required you to be able to opt out. It was pretty explicit, too:
"Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller."
The problem was that some member states cooked up an "implied consent" interpretation, according to which visitors can be assumed to have consented.
The difference between the GDPR (and the new ePrivacy Regulation, which most likely is going to address the issue directly) is that they're regulations; they're directly applicable EU law, not law that has to be transposed into local law by the member states. The EU Commission is also given enforcement powers; and, if I read the upcoming ePrivacy Regulation correctly, can also go after the adtech companies directly rather than the site owners (because ignoring lack of consent is done at the adtech level rather than by site owners, as opposed to a failure of providing a consent mechanism).
I also wouldn't put too much emphasis on the GDPR; while it's likely to cause compliance trouble for adtech companies, the ePrivacy Regulation is more directly applicable.