17 ms·
> it's legal wise the same as a cookie I am not sure that is the case. GDPR makes provisions for personal data that can uniquely identify users. Blanket statem
by __ka 7y ago
> it's legal wise the same as a cookie
I am not sure that is the case. GDPR makes provisions for personal data that can uniquely identify users. Blanket statements like: Local storage is not allowed I think are misleading. The state is persisted in the client's machine. Unlike cookies, which get attached to all requests in the specified path, local storage items are not transmitted with the request. Furthermore, in the approach I recommended earlier, no unique identifiers are being sent with the request at all. I am pretty sure that is GDPR compliant, but would love to be pointed to legal provisions that would suggest otherwise.
> it's a trade-off we are willing to accept.
Referrers, in my opinion, are not reliable enough to derive uniques, and I would assume (although I would not have any numbers to back it up), that the margin of error is very significant when you consider every condition under which referrers would not be sent (some very good cases when that happens are mentioned by other people in this very thread)
- jedimastert 7y agoFunctionally, local storage is the same as cookies with the only real difference being it requires an active request. Any information stored can immediately moved to and from the browser to the server with fetch or whatever. "Uniquely identifying users" would work with local storage the same as a cookie.
- true_religion 7y agoIt could be moved, but until you actually do it it’s not tracking but merely logging.
- yorwba 7y agoThe same is true for cookies.
- true_religion 7y agoBut cookies are automatically sent with every request to your server. So you would need to take special care to ensure they aren’t sent until you have permission.
- deleted 7y ago[deleted]