3 ms·
The Sheet #16 about cookies and third-party trackers is quite interesting: ## To benefit from the exemption from consent **Subject to a number of
by luch 6y ago
The Sheet #16 about cookies and third-party trackers is quite interesting:
## To benefit from the exemption from consent
**Subject to a number of conditions**, cookies used for audience measurement are exempt from consent.
**These conditions, as specified in the [guidelines on cookies and other trackers](https://www.cnil.fr/en/cookies-and-other-tracking-devices-cnil-publishes-new-guidelines), are**:
* To inform users of their use;
* To give them the ability to object to their use;
* To limit to the following purposes only:
* audience measurement;
* A/B testing;
* Not to cross-check the data processed with other processing (customer files, statistics on visits to other sites, etc.);
* To limit the scope of the tracer to a single site or application editor;
* To truncate the last byte of the IP address;
* To limit the lifetime of the trackers to 13 months.
Provided that the conditions are met, **we therefore switch from an opt-in to an opt-out regime**.
It is also possible for the same third party (subcontractor) to provide a comparative audience measurement service to multiple publishers, provided that **the data is collected, processed and stored independently for each publisher and that the trackers are independent of each other**.
## In practice
**Most large audience measurement offerings do not fall within the scope of the exemption, regardless of their configuration**.
That's what I though, when websites welcomes you with a giant popup "Manage your consent" with a gazillion third-party trackers all opt-in (and you need to disable them one by one) they are actually not GDPR-compliant.
- Semaphor 6y agoYeah, barely anything is compliant. Though I’ve recently encountered a bunch of sites that are, so maybe things are slowly changing.
- alkonaut 6y agoWhat is the largest GDPR fine yet for a violation specifically about website consents? I have seen some large fines but all seem to be of "backend" violations. It would be nice if there could be a handful of large high profile sites given a huge fine for having one of those annoying popups with everything opted in. There seems to be companies selling blatantly noncompliant GDPR popup tech too. That has got to be the most snake oil thing ever.
- sgift 6y ago> What is the largest GDPR fine yet for a violation specifically about website consents? 200 million for British Airways according to https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- Semaphor 6y agoDifferent type than what OP asked for. > The ICO’s investigation has found that a variety of information was compromised by poor security arrangements at the company, including log in, payment card, and travel booking details as well name and address information.
- sgift 6y agoMy bad, misread the reason. I looked for cookie and it seems to be 30k then to Vueling airlines: > (...) for not giving users the ability to refuse their cookies and force them to use them if they want to browse its website. In other words, it was not possible to browse the Vueling page without accepting their cookies.
- Semaphor 6y agoNice find. There are 3 others related to cookies, seems only Spain is going after them so far and only after the violators who don’t even pretend to be compliant. I think some of those were already violating the GDPR’s predecessor.
- Semaphor 6y ago> What is the largest GDPR fine yet for a violation specifically about website consents? I don’t think anything big. Which is a shame, because as long as that continues, the fake-compliance popups will continue. > There seems to be companies selling blatantly noncompliant GDPR popup tech too We are using one of those (Sourcepoint [0], we don’t pay for it though), they are very configurable, you can be as compliant or non-compliant as you want with their settings. They support all variations. [0]: https://www.sourcepoint.com/ https://www.sourcepoint.com/
- Nursie 6y agoIndeed they are not. What they are hoping is that - a) Nobody is going to hold them to real compliance b) User fatigue and dark patterns will make you just click "OK, fine" to everything and then they can claim to have permission. The problem is that 'b' there pretty much rules out the possibility of freely given, informed consent, and makes the whole exercise pointless.