4 ms·
There's a very clear distinction: GDPR requires that consent is not a precondition for offering a service. Most cookie policies in practice are all or nothing:
by molf 9y ago
There's a very clear distinction: GDPR requires that consent is not a precondition for offering a service.
Most cookie policies in practice are all or nothing: you either accept and continue, or you decline and cannot use the service/website. That is not allowed under GDPR.
- reid 9y agoInteresting. Which part of GDPR disallows the “decline and you cannot use the service” case?
- molf 9y agoQuoting GDPR: "Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement [...]" [1] "Consent is presumed not to be freely given [...] if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance." [2] [1] https://gdpr-info.eu/recitals/no-32/ https://gdpr-info.eu/recitals/no-32/ [2] https://gdpr-info.eu/recitals/no-43/ https://gdpr-info.eu/recitals/no-43/
- reid 9y agoThanks for replying! GDPR is complex. Indeed, declining these specific consents will still permit one to access a service. My understanding is that there can be other consents, such as consent to changes of Terms of Use, which are required to access a service.
- chii 9y ago> the provision of a service, is dependent on the consent despite such consent not being necessary for such performance. but to play the devil's advocate, if it costs money to provide a service, but that money is currently supplied by selling personal data to third-parties, then isn't it true that the service cannot be provided without the data?
- zaarn 9y agoWell then you'll have to hinge the performance of your service on actually asking the user for money.