4 ms·
According to GDPR the defaults has to be "no consent".
by funcDropShadow 6y ago
According to GDPR the defaults has to be "no consent".
- zepto 6y agoHow is ‘default’ defined? Does just highlighting the ‘no consent button’ after a massive set of options count?
- munchbunny 6y agoIt will likely be up to the courts to interpret around the edges, such as "can the modal have everything turned on by default?" That said, at a baseline it means that if you didn't click a "consent" button or some equivalent action, they can't assume they have your consent.
- pbhjpbhj 6y agoI was on a mainstream site yesterday (can't recall now which) it had a cookie dialog with no options checked, and a "accept and go to site" button, so I assumed it meant "accept the above settings". Nope, it fills in all the unchecked options, then "accepts" those settings and goes to the site. It was so incredibly devious I was almost impressed as I immediately closed the tab.
- lmkg 6y agoThe part of GDPR that covers this in depth is Recital 32. https://gdpr-info.eu/recitals/no-32/ https://gdpr-info.eu/recitals/no-32/ There's a lot of detail, but the most important part is this: "...inactivity should not therefore constitute consent." While I'm not sure there's an EU-wide ruling, the Greek DPA has specifically called out the "Consent" option being more visually prominent than the "Not Consent" option. They also mention the anti-pattern of bugging for consent daily but not bugging for un-consent afterwards, but that probably runs more afoul of "consent must be as easy to withdraw as to give" rather than "freely given."
- PeterisP 6y agoThe key part is that it's defined based on the intent and outcome. The company has to demonstrate that each user made an intentional, fully informed, freely given opt-in choice - that they knew what they agreed to and wanted to agree. If users did not intentionally want to opt in to you doing X with their data, then you don't have a valid legal basis for processing no matter what they clicked, since whatever system you built apparently did not truly capture what the user wanted. If a site wants to use data in ways that need consent (by the way, most reasonable uses don't need consent because 'legitimate need' applies - it's pretty much only things like "use all your private data for targeted advertising" and "share your private data with these 1000 trusted partners" that need consent) then it's the burden of the site to ensure that the options are presented in a clear, nonconfusing way, that users get fully informed, etc, and demonstrate to the data protection agency that whatever they implemented achieves these goals. "Just highlighting the ‘no consent button’ after a massive set of options" most likely is not effective to that goal, and a data protection agency can easily verify that (run a study with 10 new users signing up for the site and fill out a questionairre of what they wanted to consent) so it should invite administrative action from the DPAs, with mandates to change the system and/or fines depending on the circumstances. It's just that they're not really bothering with random websites (yet?) since the majority of their work is on how the all the EU non-web businesses (e.g. retailer loyalty programs, phone providers, banks, etc) handle private data.
- umvi 6y ago> The company has to demonstrate that each user made an intentional, fully informed, freely given opt-in choice How is this even possible without setting up a video meeting where a consent officer interviews you and quizzes you to make sure you understood your rights and what you were consenting to? This seems like an exceedingly onerous thing to demonstrate
- vertex-four 6y agoBy giving them a dialog that clearly describes what they are opting in to, with a clear "I do not agree" button, that does not degrade the user's use of the website. What you should do to comply is literally in the guidance; both the old guidance and the newly published guidance. The EU does not act like the US - if there's a piece of law, there is guidance on how to comply with that law. You follow it and you're safe, until someone publishes updated guidance. A number of companies are betting that doing something short of what the guidance recommends will still result in a compliant website. They are in a situation where, if they attract the attention of a regulating body, they may be fined.
- umvi 6y ago> By giving them a dialog that clearly describes what they are opting in to, with a clear "I do not agree" button, that does not degrade the user's use of the website. And what if your cat walks across the keyboard and accidentally consents, but you never even realized it? Should there be a consent banner across the top at all times? Or what if you are drunk when you are surfing the web and didn't understand your rights when you accidentally consented (drunk people can't consent - the website raped your privacy)?
- vertex-four 6y agoThen, assuming that you can evidence that you followed the guidance, and you implement the rest of the GDPR, which gives the person in question a mechanism to revoke their consent, you're pretty much definitely fine. You realise that we're not out on a witch hunt here, right?
- deleted 6y ago[deleted]