7 ms·
We care about your privacy notices have become the bane of my life.
by barking 6y ago
We care about your privacy notices have become the bane of my life.
- ianlevesque 6y agoJust pair them with cookie notices for extra effectiveness!
- briandear 6y agoRight up there with emails from software companies with “our response to Covid-19.” You are a software company. Unless the server has the virus, I really don’t care.
- Causality1 6y agoIndeed. Frankly I miss the days when my popups had breasts in them.
- Nextgrid 6y agoThe majority of these aren't actually compliant. Tracking should be opt-in and consent should be freely given. If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily by running a web scraper and looking for one of these non-compliant "consent management" solutions (looking at you TrustArc) and fining every single company that uses it.
- SpicyLemonZest 6y agoI've seen a lot of people say this, but I'm just not convinced it's actually the law. It's not obvious to me that analytics cookies categorically can't be essential or that "freely given" implies strict UI neutrality between accepting and declining.
- Tomte 6y agoYesterday the highest German court (BGH) ruled that "default accept" in cookie dialog boxes is illegal. It was a pre-GDPR case, but the court said it interpreted the them-in-force law in a GDPR-friendly way.
- Nextgrid 6y agoThe majority of websites use third-party analytics that collect way more information than necessary and may use it for their own purposes (surprisingly a lot of these companies' main business is ad-tech). The problem here is that not only do you get analytics but the third-party (with whom the user has no relationship and their interests might be against the user's) is now able to track that user across other websites.
- chris_engel 6y agoWell, essential means that a web service cannot technically work without it. For example, a session cookie.
- Nextgrid 6y agoThe law explicitly has exemptions around purely functional cookies so you are free to set session cookies without requiring consent/disclosure.
- shadowgovt 6y ago> A lot of websites also consider analytics cookies as essential For a lot of websites, they are.
- lmkg 6y agoUnder PECR, a cookie being essential means necessary to provide the requested service, not necessary to stay in business. If the user wants to view a news article, and you can serve the article without using analytics cookies, then PECR doesn't allow the cookie. (The situation for paywalls is complicated.)
- cameronbrown 6y agoProviding the service assumes staying in business, no?
- p_l 6y agoNo, there's no protection for failed business models, as there should not be.
- shadowgovt 6y agoThe business model of Google isn't a failed business model. What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the former.
- Nextgrid 6y ago> afford the engineers with the technical expertise to comply with the law while accomplishing their goals Google is in breach of the GDPR as it stands, so no. > afford the lawyers to address the issue when they fail at the former Potentially, though again a clear-cut breach like theirs should result in a fine regardless of how much money they throw at the problem. As far as building a moat, I'm not sure. Whether it's Google or a one-man shop, neither can accurately track users without being in breach. There is no moat that I can see, you either break the law or you don't.
- JMTQp8lwXL 6y agoOn mobile, some of the opt-out toggle switches don't even function. You literally cannot disable the toggle in iOS Safari.
- SilasX 6y agoYeah but that says more about the clumsiness of iOS. Since upgrading to 13, a ton of stuff is broken, like tap to zoom, and significant ability to edit text fields. Web pages randomly freeze, forcing a kill and reopen, which I rarely saw before.
- andrewla 6y ago> The majority of these aren't actually compliant. The title of the article is "Two years in, GDPR defined by mixed signals, unbalanced enforcement". So sure, maybe they're not complaint, but nobody is enforcing anyway. EDIT: removed unnecessary pejorative statement from last paragraph
- JumpCrisscross 6y ago> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.
- Nextgrid 6y agoAbsolutely, given the current lack of enforcement. However, if you're going to be in breach, you might as well improve UX and not bother with the whole "consent management" thing, not to mention that the TrustArc garbage solution doesn't seem cheap.
- Mirioron 6y agoBut then it's much more apparent that you are in breach. If you pretend to care then the chance of being caught is much lower.
- Dylan16807 6y agoDo you mean the direct cost of implementing the compliance, or the indirect cost of no longer getting extra ad revenue in an illegal way? In most cases I bet the former isn't all that much. The latter is a harder nut to crack, with everyone trying to toe the line and referencing what other companies are able to get away with. Lack of good faith is a big obstacle.
- JumpCrisscross 6y ago> I bet the former isn't all that much One of the fundamental problems with GDPR is it contains a federated complain-investigate enforcement model. So your bet would have to apply to each of the EU’s twenty-eight members, now and in the future. In that context, throwing up notices and calling a day makes sense. One can argue one tried. But not go so far as to potentially create new liabilities by interpreting these enforcers’ current and future preferences too strongly.
- disabled 6y ago> There is insufficient evidence attempting to comply with GDPR is worth the cost. The number of people working at the respective national privacy regulators is appalling. All of them have an extremely scarce amount of privacy auditors that are qualified to extensively investigate privacy breaches. Even Ireland, which has a huge tech hub with the social media companies especially, has a scarce amount of them. The Financial Times wrote an article about this awhile back, which tends to have good reporting on tech and privacy issues.
- SyneRyder 6y agoHere's an example of a broken site: https://www.europarl.europa.eu/privacy-policy/en https://www.europarl.europa.eu/privacy-policy/en The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and "atidvisitor" analytics identifiers it has set to identify you). If that's the result on the EU Parliament's own website, on their privacy policy page, it's safe to say the EU doesn't actually care about privacy.
- Mirioron 6y agoMaybe all these websites are simply taking the EU Parliament's site as an example on how you should do it? They made the regulation, surely you should follow their example.
- XCSme 6y agoThat's incredible and just shows how stupid this directive was. In my opinion it destroyed the user privacy and user experience: the average user now clicks "accept" as soon as he visits a site. This made it easy to fool non-technical users to subscribe to push notifications, give access to location and other privacy-invading features. I used the phone of my sister for a few minutes and her notification center was bombarded with random push notifications froms sites he visited and to which she unknowingly subscribed to.
- Nextgrid 6y agoI agree that the current lack of enforcement is bad for the intent of the law and its long-term impact. Currently the lack of enforcement allows non-compliant solutions (where accepting is easier than declining) to thrive so people get used to accepting everything. Down the line, even when enforcement catches up and compliant solutions start appearing, users will still be clicking accept because they've been trained to do so. This is unfortunately good for adtech/martech not just now but in the future, so all of those currently making your money on stalking users, don't cry, it's all gonna be okay.
- tjoff 6y agoDisrespectful web developers have become the bane of my life. Be thankful that GDPR exposes them, and look for alternatives.
- microcolonel 6y agoSetting aside GDPR for a moment, the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog.
- tjoff 6y agoAgain, only because of incompetent and/or immoral developers.
- microcolonel 6y agoHow else can you even store a consent for cookies/localStorage? You can go around calling people immoral and incompetent, but what is the actual way to ask for permission to store data? If your contention is that it is immoral or incompetent to store any data except through some specific user interaction related to those data, sure that's an opinion. But if your job is literally "tell me which other pages users go to after this one", it's not really that crazy of an ask. The law seems to call upon you to make it conspicuous, but when you make it conspicuous it is annoying, the law then calls upon you to make it not annoying. The better solution, in my mind, is just making cookie control features more visible in browsers. They work great, and it's the right place for this form of consent. Malicious actors abuse the current circumstance, because it relies on there being a responsible party with collateral to complain against. This is one of those times where the engineered solution is better than the social one.
- ratww 6y ago> How else can you even store a consent for cookies/localStorage? You said "the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog". But if cookies are disabled, then there's no point in asking for consent. There should be no cookie banner in this case.
- XCSme 6y agoFound this Chrome Extension: I don't care about cookies - Remove cookie warnings from almost all websites! https://chrome.google.com/webstore/detail/i-dont-care-about-cookies/fihnjjcciajhdojfnbdddfaoknhalnja https://chrome.google.com/webstore/detail/i-dont-care-about-...