5 ms·
Ok so there’s a privacy policy on this website and a standard “we use cookies” header but where is the consent management platform that’s supposed to let me rev
by potench 8y ago
Ok so there’s a privacy policy on this website and a standard “we use cookies” header but where is the consent management platform that’s supposed to let me review all the purposes and vendors used on the site so I can choose which ones I want to give consent to and which ones I don’t.
The https://github.com/appnexus/cmp https://github.com/appnexus/cmp appnexus cmp is the only cmp I’ve found that’s open source and provides a clear reference to what GDPR means as far as integrating the actual GDPR spec for an euconsent signal, a UI for managing consent, and deferring cookies/data-collection until after consent. Gdpr goes into effect in 4 days and I still haven’t seen any CMPs integrated in the wild. Has anybody?
- KozmoNau7 8y agoI haven't seen a single one of those in the wild yet, only "we've updated our ToS with a section about your private data, agree or stop using our service", which simply does not fly.
- tallanvor 8y agoI'm pretty sure that GDPR doesn't mean you get to decide which vendors Microsoft gets to use. The commitment is that Microsoft and all vendors they use will be following GDPR.
- Angostura 8y agoDon't forget that 'consent' is only one of the bases to collect data. Where the data is vital to the ability to run the service, it will be being collected on the basis of contractual agreement, not consent.
- KozmoNau7 8y agoI've seen a lot of privacy policies include lines like "we collect your activity data on the website, so we can improve your experience" or "we use cookies to gauge how to improve our services" or "we collect usage data to improve our marketing across other sites and platforms", which are both horribly vague and certainly not vital to run the service. I took those lines basically verbatim (translated from Danish) from Just-Eat's Danish website. I am pretty sure they're violating GDPR, based on what they say in their privacy policy. Collecting usage data and sending data to third-party marketing companies is not vital to running a food ordering website. A ToS is not a legally binding contract, and I have not been asked for direct consent to their use of my data.
- Angostura 8y agoThose that you describe, should certainly be asking consent, or at a real push, listing the cookies and their names so that you can block them in-browser.
- jacquesm 8y agoYes I have, for a medical company I recently did DD on. It was done pretty good actually and they are considering fielding it as a separate (whitelabel) product for others.
- r3bl 8y agoHere's a marvelous example I've stumbled upon yesterday: https://juro.com/policy.html https://juro.com/policy.html The entire privacy policy is very well done (and beautifully designed, I may add). Clear options, transparency over who gets your data, ability to use the product without providing PII and all sorts of other goodies. Specific quotes related to consent: > If you have previously given consent to our processing your data you can freely withdraw such consent at any time. You can do this by emailing us at support@juro.com. If you do withdraw your consent, and if we do not have another legal basis for processing your information, then we will stop processing your personal data. Disclaimer: I'm not affiliated with Juno nor am I their user. I just randomly stumbled upon their privacy policy.
- grabeh 8y agoIt may be a good policy, but this is unrelated to the point on cookie consent made in the parent post. In fact the Juro site uses a variety of analytics cookies without even having a cookie banner in place, let alone any granular system for managing cookie consent.
- r3bl 8y agoFine, here's a Dutch public broadcaster: https://www.npo.nl/ https://www.npo.nl/ Upon opening it, you'll see a button labeled "Cookie-instellingen aanpassen". Clicking on it allows you to fine tune their cookie policy. "Functional" and "Analytics" categories can't be disabled, while the other (third-party) cookies can.
- grabeh 8y agoThanks! Although I gotta say that they offer no options in relation to analytics cookies which is technically in breach of the e-Privacy directive as those cookies are not strictly necessary here. There are a few cookie solutions that can be used here - BT.com has a decent user flow. The new e-Privacy Regulation coming into force next year will however, as presently drafted, provide an exception from consent for analytics programmes that only use gathered data on a per-site basis (so excluding Google Analytics for example).