3 ms·
Go to this website: https://europa.eu/ https://europa.eu/ This is the official EU website. EVERYONE is being trained to click I accept. And then they do a n
by privateSFacct 7y ago
Go to this website:
https://europa.eu/ https://europa.eu/
This is the official EU website.
EVERYONE is being trained to click I accept.
And then they do a nonauthenticated javascript scrip insert into a secure page ON THEIR HOMEPAGE. You gotta love it.
<script type="text/javascript" src="http://ec.europa.eu/wel/surveys/wr_survey01/wr_survey.js"></script>
What would provide users some actual security is if their browser would block this unauthenticated insert of javascript if its in a secure page. In other words, DON'T trust the website to do the right thing, just take control at the browser level.
- saagarjha 7y agoThat's because they're using cookies that are not essential to the functioning of their website.
- ratww 7y agoNo. Look again. There's a very clear "I refuse cookies" button, which I can click and continue to the website. [1] The point of those things is that I can refuse cookies or tracking without retaliation and without loss of functionality. Remember: functional cookies don't require consent. They are doing it right. It is all the non-compliant companies with only the "Accept" button that are training users to click on it. Those cookie bars are not compliant with GDPR at all. [1] https://imgur.com/a/tj7egN0 https://imgur.com/a/tj7egN0
- oneeyedpigeon 7y agoI agree that this is an excellent approach, but the wording should be a lot clearer. When I see “This site uses cookies to offer you a better browsing experience” and a yes/no choice, I assume I’ll be missing out if I choose 'no'. Really, there should be an explicit reference to 'tracking', and a reassurance that everything will work perfectly if I choose 'yes'.
- privateSFacct 7y agoLook again please. "Here's how the GDPR options of an European website looks like: https://imgur.com/a/ckOivi7 https://imgur.com/a/ckOivi7 " False, the EU website has an ugly cookie bar with a button called "I accept" that everyone has been trained to click yes on. "That "Analytics Advertising Feature" MUST be unchecked by default. Only users that actually want to be tracked are tracked." False, users can be presented with an accept / reject button on a standard cookie bar, clicking accept can opt them into tracking - please LOOK at the EU website example I provided. "Every "tracking feature" (cookies, fingerprinting, IP tracking, whatever) must be hard opt-in." This can be done though an accept button on a website that users have been trained to click yes on. My earlier suggestion that folks do a study on how many users navigate into these policies for every website they visit to make fine grained selections if such options are even available stands as well. "If a website only use functional cookies (colours, session, login, cart, language) they don't need consent, just disclosure (and it doesn't have to be an ugly cookie bar)." I gave you an example of an ugly cookie bar on an EU website subject to GPDR - I can find many more. This is the problem with these folks messing the net up. Everyone should do this / shouldn't do that, but no attention to what is actually happening. I want to be clear, billion of pages are showing I accept buttons, some without reject buttons if they are disclosure only, some with reject buttons that kick you off the site, and some with reject buttons that opt you out of tracking, and users are being / have been trained by the EU alert notices / disclosure only notices (which generally DO have an I accept button) etc to waste their time clicking I accept everywhere. This is bad for actual user choice, actual privacy.