8 ms·
> They can't run Google Analytics for the visitors that don't check this box I don’t understand. They can. Just anonymize the ip. You can track all their activ
by digitalengineer 7y ago
> They can't run Google Analytics for the visitors that don't check this box
I don’t understand. They can. Just anonymize the ip. You can track all their activities. Am I missing something?
- AdriaanvRossum 7y agoGoogle Analytics tracks your visitors with a cookie [1]. You need consent for placing that cookie under the GDPR and other privacy regulations. [1] https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage https://developers.google.com/analytics/devguides/collection...
- eli 7y agoI don’t think GDPR necessarily says that one must get consent for every cookie.
- tyingq 7y agoGoogle analytics does use first party cookies for the site stats, but it also s̶e̶t̶s̶ [edit] can set a third party DoubleClick cookie that tracks users across sites. So that anonymizing the IP doesn't anonymize the user. There's also optional functionality that can track users via the first party cookie. Passing login id, for example, to GA.
- founderling 7y agoit also sets a third party DoubleClick cookie I have never witnessed that. Can you link to a site that uses only Google Analytics where that happens? Maybe you confused Analytics and Adsense?
- tyingq 7y ago"For customers that are using Google Analytics' Display Advertiser features, such as remarketing, a third-party DoubleClick cookie is used in addition to the other cookies" So, I suppose I should have said "can set", though remarketing is very common. https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage https://developers.google.com/analytics/devguides/collection...
- founderling 7y agoI would think that enabling the "Display advertisers features" only makes sense for webmasters who also use Google Adsense. And then their visitors get bombarded with all kinds of cookies anyhow. So I don't think it applies to the use case at hand. Where a webmaster wants to implement statistics without violating GDPR.
- tyingq 7y agoIt's used for Adwords. That doesn't change anything on your site. You can remarket only on Google searches, for example...no AdSense involved.
- true_religion 7y agoIt’s not a double click cookie, but if you have multiple sites under the same analytics account google will be able to track cross site sessions via a cookie they set to their own domain.
- eli 7y agoNot in a default configuration
- donohoe 7y agoThere is much confusion as there is both the Directive 2009/136/EC (aka EU Cookie Law) AND GDPR. EU mandated that all websites (residing in EU) to obtain informed consent before they can store or retrieve information on a visitor's computer or web-enabled device. This is not limited to "cookies". The law doesn't even mention the word "cookie". It covers localStorage and any TBD technology in the future. There are exceptions for "strictly necessary" like a store would not have to get consent to operate a shopping cart on the website as thats can be considered critical to the purchasing and checking out. However storing what you browsed for recommendation purposes is not, and therefore that would require consent.
- ksec 7y agoOn the Subject of GDPR, Are there any website still blocking EU visitors or has that been solved? I remember when GDPR was introduce lots of website simply decide to shut off EU IP access and redirect them to a page saying not available to EU.
- LeftHandPath 7y agoI think a number of US news sites (e.g. LA Times) still block EU traffic. Furthermore, GDPR has caused a massive decrease in the number of newly registered domains that are successfully recognized as spam: > Prior to the implementation of GDPR, security researchers were able to identify and block 1.8 million newly registered malicious domains in October of 2017 alone. Fast forward to February of 2019 and that number drops to less than 160,000.[0] And it has caused a major annoyance for the general public, who mindlessly consent to almost every "consent" prompt they are given.[1] Companies are also at the mercy of their regional government when it comes to compliance. A company in Greece was fined 150,000 euros, not because the law made it illegal to process data in the way they did, but because the reason they provided for processing was the "wrong" one.[2] > PWC asked its employees for permission to process their personal data when it should have used a different legal basis (combination of contract, legal obligations and legitimate interest). [(2)] In effect, their effort to follow the law made them break the law, even though their actions were legal under Article 6, Section 1 of the GDPR.[3] This flies in the face of the EU's language in 2018, where they suggested that companies attempt to follow the "spirit of the law" rather than to worry about dotting i's and crossing t's. Oddly enough, regulators seem to be pleased with this outcome of seemingly arbitrary enforcement. [0]: http://www.circleid.com/posts/20191213_the_high_cost_of_privacy_in_a_post_gdpr_world/ http://www.circleid.com/posts/20191213_the_high_cost_of_priv... [1]: https://www.cnbc.com/2019/05/04/gdpr-has-frustrated-users-and-regulators.html https://www.cnbc.com/2019/05/04/gdpr-has-frustrated-users-an... [2]: https://iapp.org/news/a/just-say-yes-gdpr-consent-is-not-as-simple-as-it-seems/ https://iapp.org/news/a/just-say-yes-gdpr-consent-is-not-as-... [3]: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/
- robflaherty 7y agoGDPR is not a cookie law. You don’t need consent to run out-of-the-box GA with IP anonymization.
- EsssM7QVMehFPAs 7y agoYou most certainly do, even if it might not yet be prosecuted. See article 6 1/a-f for lawfulness of processing. Without consent there only remain select few conditions, none of which apply to the operation of GA for visitors without a legal contract with the site operator on a different level (ie. customer relationship). It is only a matter of time..
- detaro 7y agoI'd not label that as "certainly", quite a few lawyers disagree about 1f not being applicable for basic, ano-/pseudonymized analytics.
- donohoe 7y agoThere is much confusion as there is both the Directive 2009/136/EC (aka EU Cookie Law) AND GDPR EU mandated that all websites (residing in EU) to obtain informed consent before they can store or retrieve information on a visitor's computer or web-enabled device. This is not limited to "cookies". The law doesn't even mention the word "cookie". It covers localStorage and any TBD technology in the future. There are exceptions for "strictly necessary" like a store would not have to get consent to operate a shopping cart on the website as thats can be considered critical to the purchasing and checking out. However storing what you browsed for recommendation purposes is not, and therefore that would require consent.
- lentil 7y ago> You need consent for placing that cookie under the GDPR Do you have a reference for this? It not how I understand GDPR, and I am not clear which part of it would apply here when personally identifying information is not being tracked.
- EsssM7QVMehFPAs 7y ago"Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person." GA pseudoanonymizes visitor data, but the does not exempt site operators from adhering to the consent mechanisms of the GDPR.
- lentil 7y agoBut the cookie is not "Personal data which have undergone pseudonymisation", is it? Assuming we're talking about the case where no PII is being sent along with the tracking data (which I believe is the point of masking the IP address, among other protections) how could this be attributed to a natural person? What I'm trying to understand is why the addition of an opaque cookie value necessarily changes the situation, such that consent is required. It's very possible I'm missing something here; genuinely trying to learn what that is.