5 ms·
Browsing the web in Europe is like experiencing the rebirth of the pop-up ads era. It has lead to compulsory acceptance. This too shall pass. There is a reason
by jmarbach 7y ago
Browsing the web in Europe is like experiencing the rebirth of the pop-up ads era. It has lead to compulsory acceptance. This too shall pass.
There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services.
- FeepingCreature 7y agoI've been very satisfied to the extent to which these popups allow you to not opt in to everything and still use the site. I think the previous popups have trained us to assume that the popups are meaningless and we just have to click yes on everything. This is not so!
- pteraspidomorph 7y agoAs an european who rejects ad trackers on every website, I can confirm that a good 95% of them are correctly implemented and will let you keep browsing. Some of them (usually americans with a poor understanding of why they even implemented that) will kick you out or ask you again on every page load until you accept. We need a standard for managing these controls on the browser side, which major browsers can then implement. It wouldn't surprise me if people were already working on something like that. If I reject ads from google doubleclick specifically, they should be pre-rejected for every subsequent website that asks the same question. Likewise for the various cookie purposes. (I do understand the unfortunate potential for fingerprinting here...)
- vectorEQ 7y agoi don't think its a problem that people don't let you use the site if you don't opt-in. thats a design choice, not a fault or problem or bad implementation. just a show of that they would really really like to track you. if you don't want to be tracked, then it's a clear indicator to avoid such site in the future. I wholeheartedly agree on your point though, that if i reject 'A' on one site, it could be assumed by the browser i'd like to reject 'A' on the next site. Perhaps the same kind of block could occur like they do with faulty ssl settings, just stating that you blocked 'A' on some site ,and this site is using the same, with a button to proceed if you accept that fact.
- wsy 7y agoThat's not how GDPR is designed. In Europe, the business model to 'sell' Web content for the permission to track has now become illegal. Web site owners will need to change their business model, or they will be fined. Note that you can still 'sell' Web content for forcing your customers to see advertisments. You just aren't allowed anymore to track that on a person-by-person basis.
- mnw21cam 7y ago> i don't think its a problem that people don't let you use the site if you don't opt-in. thats a design choice It's illegal. End of.
- Macha 7y agoI find that some vendors will have a section for "information storage and access" and list both the cookie used to remember your gdpr setting and cookies from doubleclick in there. Or the opt out page just leads to instructions to disable cookies in your browser.
- pteraspidomorph 7y agoEvery single website seems to have a slightly different layout for the permission manager thing, even when the software for multiple websites is (in name) the same software developed by the same company. Why? Tricking the user into accepting something they wouldn't want to seems to be a major reason. It drives me nuts. If there was a single permission manager whose layout is controlled by the Firefox devs this wouldn't be a problem.
- icebraining 7y agoBoth of those are illegal, and may get the site fined.
- amelius 7y ago> We need a standard for managing these controls on the browser side, which major browsers can then implement. Like the "Do Not Track" header field? https://en.wikipedia.org/wiki/Do_Not_Track https://en.wikipedia.org/wiki/Do_Not_Track Perhaps it will work if introduced as a GDPR header field.
- mnw21cam 7y agoThat is a good point. If my browser is sending a do not track header, why is your server even asking me how much tracking I want?
- amelius 7y agoClearly they are asking because they hope that you click "Yes". Once you click "Yes" they give you a cookie and stop bugging you. It's a nasty trick of the tracking industry. GDPR does not forbid websites to ask or even deteriorate your experience (afaik). Perhaps that should change.
- mnw21cam 7y agoGDPR does forbid providing a lesser experience for people who do not consent to tracking. (Obviously aside from the direct consequences of not having tracking, like getting different adverts.)
- kretor 7y agoThere's a browser extension which clicks away the consent dialogues for you: https://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/ It lets you specify a global setting to what extent you want to be tracked, and communicates that to sites that support the extension's "standard".
- pteraspidomorph 7y agoBut there is no reason for most websites to be compliant when they know that by default they will get what they want (blanket permission)...
- hanoz 7y ago> As an european who rejects ad trackers on every website, I can confirm that a good 95% of them are correctly implemented and will let you keep browsing. Really? Any chance you could share some examples, because my strong impression is that a clear 95% of those I see are not compliant.
- clinta 7y agoHow does that work anyway? If you decline to allow the site to store a cookie on your machine, how does the site know that you already rejected the popup to avoid showing it to you on your next action?
- pteraspidomorph 7y agoThey store that information on a cookie! Some websites try to break their own permission manager on purpose (or at least I can only imagine it's on purpose) by burying the cookie that stores the permission manager's settings within the list of cookies you have to accept or reject, so if you "reject all" you will be asked again and again. Non malicious implementations either include the permission manager among the essential cookies or list it at the very top so you can choose to keep it. If the permissions were managed by the browser then cookies could be managed directly on the client side without server side interference, and preferences could be communicated to the website via headers (like DNT but GDPR requires a lot more granularity, and is also legally enforceable in the EU).
- ubercow13 7y agoI don’t really find that reasonable, the email is for identifying and securing my account, not marketing.
- hjanssen 7y agoWhich is not a problem with the regulation in and of itself but instead just highlights how ubiqitous tracking has become.
- dspillett 7y agoThat, and many implementations are deliberately inconvenient in the hope that you will eventually capitulate or accidentally opt-in, while trying to make it look like the legislation is the problem rather than their implementation.
- seszett 7y ago> There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services Certainly not. If I didn't check a box saying "I want to receive commercial emails related to your products and services" I expect not to receive those. I might unsubscribe from the whole thing if I don't have any other means of avoiding those useless commercial emails.
- Macha 7y agoI generally report such "you bought something and so we signed you up to the mailing list" activity as spam in Gmail, and if the unsubscribe button links me to a third party vendor, list "I never signed up for this list" as the reason.
- 9HZZRfNlpR 7y agoThis is how at least local businesses do here now, I don't have problem with marketing emails from them. You actually have to check the input, not accidentally forget.
- webbie917 7y agoThe issue here is "relating to their products and services". Per GDPR, the consent can not be "bundled". When you signup for an account you consent to communications about your account only and things like product updates or tips for using product should be under their own explicit consent. Most email marketing service providers don't even support multi-interest opt-out page, or charge a lot for configuring your unsubscribe page this way (like a multiple of list size for each option gasp), so this makes it impossible for email recipients to choose what emails types to opt-out of so marketers in turn don't bother to collect unbundled consent. Comparison of some market leading ESPs (see multi interest opt out row): https://www.bigmailer.io/bulk-email-marketing-services/ https://www.bigmailer.io/bulk-email-marketing-services/
- dexen 7y ago>Browsing the web in Europe is like experiencing the rebirth of the pop-up ads era. Very much so; the pop-ups interrupt and obstruct, breaking immersion. I sincerely hope a browser gets brave enough to start blocking those obstructions by default. It irks me how every "Cookies" banner is an unpaid advertising billboard saying, "Your privacy is valuable to us. Yours faithful, EU". >This too shall pass. For now, uBlock Origin[1] + the ruleset from I Don't Care About Cookies[2]. -- [1] https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... [2] https://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/
- brosinante 7y agoImmersion into what, the internet?
- arkh 7y ago> the pop-ups interrupt and obstruct, breaking immersion. Here is a trick for website owners: don't track your users. No need for any popup anymore.
- snowwrestler 7y agoThis is incorrect, an EU website must provide notification of cookies if they use cookies at all, even for basic session tracking of authenticated users.
- icebraining 7y agoIt should be noted that's related to the cookie law (ie, the ePrivacy Directive), not the GDPR, and there is a proposed replacement (the ePrivacy Regulation), since basically everyone agrees the current situation is not good. Unfortunately it's taking longer than initially expected.
- Nextgrid 7y agoIncorrect. I guess this must be a lie pushed by bad actors who are inconvenienced by the regulation and want the public to perceive the regulation negatively. You do not need consent for cookies that power basic website functionality or a feature the user is trying to use. So setting a cookie when someone logs in or adds an item to their shopping cart.
- Angostura 7y ago> It has lead to compulsory acceptance. No. It leads to non-acceptance by default. If you are seeing forms where you are opted in to data capture by default that isn't a core part of the service, that's a breach.
- maccard 7y agoGreat, so how do we fix that and stop them doing it?
- satanspastaroll 7y agoWe generally fine them big for breaking it, and may forbid them from doing business at all if they keep breaking it
- maccard 7y agoWho is "we", how do "we" decide who is breaking the laws and how can _I_ tell themof a blatant disregard for the laws?
- satanspastaroll 7y agoEvery country implements their version of GDPR and it's sanctions. You can tell your authorities or dedicated organization about violations. Not all countries have yet implemented procedures for them however.
- alkonaut 7y agoWait for a small number of companies practicing the “by using this service you agree to” thing to be fined a large part of their turnover. After that companies will adapt. Now we are in a sort of transition phase where laws are written but companies interpret them themselves (badly) and there are few guiding cases. I look forward to the next phase when the notices will be gone or say “did you know you can enable tracking so we show more relevant ads that we get more money for showing?”. I’ll say no regardless of how much I enjoy that content.
- diffeomorphism 7y ago> It has lead to compulsory acceptance. This too shall pass. Indeed, mandatory acceptance is not a meaningful choice and hence explicitly ruled out by the GDPR. > There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services. Sure, and all necessary use of information is just fine and unproblematic. Just the additional spying on top of that requires an additional, unforced opt-in.
- disiplus 7y ago> There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services. not true, i mark all those as spam, if there is a "newsletter checkbox" i check it out, but if they have hidden it somewhere i dont care, mark as spam and next.
- wongarsu 7y ago> There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and service "Communications" as in "valuable information", like letting you know somebody logged into your account. That's fine and unaffected by the GDPR. If by "communication" you mean unsolicited advertisements about the company you are describing illegal behavior that was already illegal before the GDPR. "I agree to be contacted for marketing purposes" checkboxes are ubiquitous precisely because without my opt-in they can't.
- CrLf 7y ago> Browsing the web in Europe is like experiencing the rebirth of the pop-up ads era. And this by itself says a lot, but not what people usually think it says. In fact, you don't need any kind of cookie popups _unless_ they're tracking cookies. Any reasonable use of cookies for site-specific reasons (authentication, session, csrf, load-balancing, settings) is already allowed with no need to opt-in[1]. The reason why cookie popups are so widespread is two-fold: 1. Because indeed most sites track you to death, and are unwilling to back off even if it costs them visits (many people just close the tab upon being presented with all but the least obnoxious popups). In this perspective, the GDPR is working as intended; 2. General ignorance about the cookie exceptions. You can hardly blame the regulators for that. In fact, AFAIK the GDPR clarified a few things that were ambiguous WRT cookies. That backfired horribly, but just beacause ignorance is rampant. [1] https://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm https://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
- rypskar 7y agoSo much this. Every time I see a popup with "We respect your privacy", I think "no you don't" and try to see if it is something I can block in privacy badger to remove the popup. If the site respect users privacy it will not track the users and don't need the warning
- mnw21cam 7y agoMore accurate - "We value your privacy". In other words, your privacy has value to them, and they are eager to shaft you that privacy to extract the value.
- TeMPOraL 7y agoThey value your privacy the same way a mugger values your wallet. They'll often even offer you a degraded experience if you don't consent.
- masklinn 7y ago> There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services. No. Most of the services out there require an email to sign up to the service itself. Using that email for anything beyond the core provision of the service I signed up for is a breach. If I bought a fucking pencil sharpener from your website, any communication beyond keeping me abreast of (and optionally checking if I was happy with) my order is abusive.
- jobigoud 7y ago> It has lead to compulsory acceptance I have a simple heuristic: if there is a big overlay preventing me from looking at the content, I just disable javascript altogether for the site. Most of the time this result in a clean experience with just the text I was interested in in the first place. If it breaks the article I close the tab.
- iicc 7y ago> There is a reasonable expectation that when you submit your email to a company in exchange for their service By banning consent bundling GDPR is designed to make this exchange of value illegal. And no, it's not "reasonable" because it leads to situations where the only way to pay for a service is with your PII.