18 ms·
What Do You Agree to When You Accept All Cookies
- deleted 6y ago[deleted]
- iamacyborg 6y agoRegulatory bodies have failed to protect consumer rights when it comes to enforcing the GDPR as concerns cookies on the web. it's highly disappointing.
- jraph 6y agoI like to think the war is not over here. I'd say, they have not succeeded yet.
- jokethrowaway 6y agoThe only hope left is for Europe to collapse economically and hope websites will stop shoving popups down our throats. Or fund someone to write better anti-cookie-banner extensions. Ublock works incredibly well for ads, after all.
- iamacyborg 6y agoPopups are not the problem.
- earthboundkid 6y agoWhy not have a law that your policy must have a summary that is less than 140 characters long?
- rjmunro 6y agoNot a summary, the whole legally binding thing. But I'd allow 280 characters. It would be good to define some phrases in the law that then have unambiguous legal meaning so that privacy policies don't have to spend time defining things in full.
- earthboundkid 6y agoAll those terms exist, they’re just long and meaningless to native speakers. A summary is fine and can be legally enforceable.
- svachalek 6y agoI like the open source license pattern. Anyone can make any agreement they want, but most of the time you just need to see "Apache" or "GPL" and you know the deal. And when you see a new one you wonder what exactly is going on here. But really, most of the time the cookie deal is "do you agree to have all kinds of information gathered about you and sold at will to other companies, our future management, and mysterious government entities in perpetuity, in exchange for seeing a few cat pictures? oh, and also we can make this even more unfair at any time without your agreement." They really should just be illegal, period.
- danso 6y agoThat law/regulation would seem difficult for a court to uphold – e.g. a company being diligent and detailed in explaining its complicated policies, but getting dinged when someone is misled by their arbitrarily word-count-limited summary. But in any case, the example provided by the article does have a top summary [0] (it's the very prompt that the author investigates). And the individual line item settings are each summarized in a single sentence [1]. That said, the actual example summaries given seem to IMHO make a case for mandating specific and explicit language, akin the "Surgeon General's" warning text on cigarette packs, to accompany whatever euphemistic language companies continue to use. We're far enough into the Internet age to be pretty confident that the vast majority of people just do not and cannot comprehend that "We use cookies to improve the site, measure performance, understand our audience, enhance our experience and provide you with advertising based on your browsing activities" means actual tracking. [0] http://www.conradakunga.com/blog/images/2020/12/Banner1.png http://www.conradakunga.com/blog/images/2020/12/Banner1.png [1] http://www.conradakunga.com/blog/images/2020/12/Reuters5.png http://www.conradakunga.com/blog/images/2020/12/Reuters5.png
- earthboundkid 6y agoApple’s privacy labels seem like a step in that direction. Needs the force of law though.
- progval 6y ago> Why not have a law that your policy must have a summary that is less than 140 characters long? Not as explicit as 140 characters, but it's already covered the GDPR From the preamble, paragraph 32: > If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided. From article 7, paragraph 2: > 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding. (emphasis mine)
- CoolGuySteve 6y agoI really wish this law had forced websites to respect a toggle in the browser UI instead of being allowed to engage in all their dark pattern shenanigans.
- rjmunro 6y agoEarly on, browsers had UI to block cookies. Sometimes you had to press "yes" to accept a cookie. No participation from websites was needed. No one ever used it, and over time it got more and more hidden. It's still there if you look for it.
- dsego 6y agoYes, I remember this as a kid in the early IE days, like version 4 or something, not sure, but it was there.
- Nextgrid 6y agoThe concept of tracking as per the GDPR goes beyond cookies though. It includes any kind of personal data collection, and personal data refers to anything that can uniquely identify a person with reasonable certainty. So cookies aren't the only thing that requires consent - things like browser fingerprinting and even collecting IP addresses for non-essential purposes (aka you can probably claim legitimate interest if you collect them for technical or fraud prevention reasons, but using that data for analytics or marketing would require consent). This is also why I think clicking "accept all" on the cookie prompts with cookies disabled at the browser level isn't a good idea. You're still giving them permission to stalk you using other means than cookies, and they very well know that. At least use an ad-blocker which blocks the consent prompts completely - technically you never provided permission, so while they might still stalk you at least they don't have a legal basis for doing so. The GDPR is less about the technical aspect of data collection and more about the intent behind said collection and the planned use for the collected data, something the browser can't really tell.
- jokethrowaway 6y agoTL;DR: Thanks Europe for fixing something almost nobody cared about, by making the internet worse for everyone and by forcing society as a whole to spend money building terrible UIs. And in the end, people still just Accept All because it's the fastest way to content.
- bb101 6y agoThe most egregious violation I've seen is weather.com's cookie process. Go to https://weather.com/en-GB/ https://weather.com/en-GB/ and click "Proceed with required cookies only". It's almost theatrical: first a spinning loading wheel, then the message "We are processing your request, this could take up to a few minutes to process." Then wait for their "Processing 0%" countdown take a few minutes to reach 100%. Anyone would think they are trying to discourage people from choosing that option?
- mattvot 6y agoLooking at the network requests when you hit that button it seems to be hitting a lot of tracking providers opt out API endpoints. Which is good I suppose, though better not to even include their scripts until you agree to it
- noja 6y agoSo if I opt-out, it (basically) sends my ip address to lots of trackers? Why? That sounds illegal. Why doesn't it simply not load the trackers?
- hutzlibu 6y agoOoops, erm, technical reasons I guess. Well, it could have been really easier to implement the opt out it later by this design, but it is more likely, that the dataflow is intended.
- riggsdk 6y agoJust the fact that it sends out-out HTTP calls to all those providers means that they now know that you are using that website. It's terrible design.
- 411111111111111 6y agoPretty sure it's designed with that in mind... The saying not to attribute to malice what could be explained by incompetance only works if the actor isn't generally malicious. AdTech definitely is.
- ThePhysicist 6y agoWhat the author discovered here is the full list of publishers as given by the IAB consent framework [1], which is an attempt at self-regulation by the ad industry and website publishers. Presenting the user with the full list of advertisers is indeed silly and not compliant IMHO. We also offer an open-source privacy & security tool for websites (Klaro! - https://github.com/kiprotect/klaro https://github.com/kiprotect/klaro) and we have decided against implementing the IAB framework as it's clear that it does not conform to the intent of the GDPR. We also opted against using dark-patterns and making declining more difficult than accepting. Overall this results in slightly less opt-ins (around 50-70 % for most websites) but in any case those dark patterns will have to go sooner or later. [1] https://iabeurope.eu/transparency-consent-framework/ https://iabeurope.eu/transparency-consent-framework/
- hadrien01 6y agoI've seen some French Government websites using orejime, a fork of Klaro. Thank you for making that tool, it's great to use as an end-user!
- ThePhysicist 6y agoThanks, always great to hear that people find it useful :)
- hombre_fatal 6y agoIt amazes me how bad the internet experience gets when using a VPN server in the EU. I thought cookie popups were annoying, but I didn't realize how much more ubiquitous they are when you have an EU origin ip address. If you haven't tried it before, it's worth doing it just to see what those poor people put up with.
- estaseuropano 6y agoI think you got it the wrong way around. The neighbouring town publishes data on water quality, and you pity the poor souls because the data shoes their water quality is horrible. Thing is, you are using the same water source. If anything, your water is likely worse because there is no transparency and some of the pipes might be leaded and you wouldn't even know it. Same with cookies. The internet is polluted with aggressive tracking everywhere. In the EU you see how horrible it is - in the rest of the world people aren't even half as aware. That said, people either start using browser plugins or just click yes and sacrifice their soul to the gods of dark patterns. In either case you don't see those banners as frequently unless you use private browsing.
- hombre_fatal 6y agoYou seem to think that the cookie popups are doing something useful, but that's up for debate. Cookie popups could be making it worse by normalizing tracking and programming everyone for an "Accept all or get nothing" compliance culture. Btw, some of my message was lost in your attempted analogy: If we both are drinking toxic water, then I feel bad that you have to additionally click through a legislator's theater of concern and sign through various permission-granted-to-poison-me slips while you drink from the same tap.
- MereInterest 6y agoPart of it is lack of enforcement. The GDPR requires that rejecting tracking be as easy as accepting it. If there is an "Accept all" button, then there must also be a "Reject all" button. Furthermore, there can be no penalties for rejecting the tracking. So clicking the "Reject all" button may not bar the user from the site.
- aquir 6y agodoesn't matter how long I need to scroll I always try to reject everything for every website that I know I will visit multiple times. And I also use NoScript and uBlock Origin But this is a prime example for a "dark pattern" And also, if I can't reject most of the stuff I just close the site
- rinze 6y agoI agree that Cookie AutoDelete will wipe them as soon as the tab is gone.
- rhn_mk1 6y agoIt's not cookies though, despite the title. GDPR banners regulate sharing of personally identifiying data, which are a wider category, with things like browser fingerprints or IP addresses in it too.
- eptcyka 6y agoI love that the post doesn't answer the question in the title, just shows that its inconceivable that any layperson would be able to answer the question on their own.
- Ragnarork 6y agoWhich is in itself a meta-answer to the question.
- sdfhbdf 6y agoIt’s cliche but why for the love of god cant they honor Do Not Track that is a toggle in every browser [0]. [0]: https://en.m.wikipedia.org/wiki/Do_Not_Track https://en.m.wikipedia.org/wiki/Do_Not_Track
- scatters 6y agoBecause browser vendors decided to toggle it to on by default, which made it meaningless.
- mnw21cam 6y agoIn what way did it make that meaningless?
- MisterTea 6y agoIn the sense that browser vendors decided to put on a privacy protection facade by enabling a "privacy protection" flag that webshites can easily ignore. The earn kudos from users while websites can keep abusing said users. Win-win for greed.
- MereInterest 6y agoIt didn't. Advertisers like to think that they have a moral right to track people unless explicitly told not to stalk people. In that framework, changing the default means that a DoNotTrack header doesn't necessarily show intent on the part of the user. Instead, the appropriate framework is that advertisers do not have a moral right to track users unless the user has consented to it. By having the DoNotTrack header be on by default, it means that a user removing it shows consent to be tracked, where previously its absence could also have indicated that the user was unaware of the header.
- mnw21cam 6y ago100% agreed. That was the point I was making.
- FriedrichN 6y agoIf a website had me jumping through too many hoops, I just don't bother. Many websites refuse to work without an egregious amount of third party JavaScript which makes it a pain in the ass to visit if you use uBlock Origin/uMatrix. Let's be honest most of the websites that won't work without JavaScript aren't even really worth it. The content is usually garbage anyway.
- greggyb 6y agoI find very few sites in my regular browsing where uBlock Origin makes it unusable. The out of the box defaults are very well tuned in my experience.
- encom 6y agoI have all the filters enabled in uBlock (except language specific ones), and that takes care of most cookie popups. If I still see a popup, I just leave. I refuse to interact with popups. That was true in the 90's, and it's true today.
- herodotus 6y agoSafari used to make it easy to reject all cookies with an exception list. I wish this feature would return. They have also made it very difficult to access and manage cookies outside of Safari. Seems inconsistent with Apple's public stance on tracking.
- jefftk 6y agoSafari rejects third party cookies by default, so I don't see why that feature would be needed anymore?
- Faint 6y agoAll this "do you agree to this and that" nonsense could be avoided by "inversion of control": instead of sites asking users whether they agree to this 100 page document, websites should be legally bound to listen and honor directives that users give about the data the sites gather. For example, for cookies, legally force, with the cookie (with a standard protocol), transmit of "intent", like cross-site tracking, whether it is used for advertisement or something else, whether it may be shared with third parties, etc. Then the browser would simply not accept cookies with intent the surfer disagrees with. Another possibility is, that the browser could, in a standard header, with a bunch of standardized flags, tell what the site may or may not do with the data they gather about the surfer.
- tagawa 6y agoTake a look at Global Privacy Control (GPC) which aims to do similar to what you’re describing, and is legally binding under CCPA and could be under GDPR too: https://globalprivacycontrol.org/ https://globalprivacycontrol.org/
- eyelidlessness 6y agoA much more naive version of this, the Do Not Track header, was removed from major browsers (partly) because it was actually being used for fingerprinting. I strongly suspect a less naive version would be subject to more abuse: as it gets more granular it becomes a fingerprint all on its own. I understand that you’re suggesting pairing it with legal force, but I also highly doubt that would or could be effective in any kind of consistent way.
- GordonS 6y agoI think another reason Do Not Track failed is that advertisers (e.g. Google) didn't like it. Microsoft setting Do Not Track on by default in Internet Explorer was likely the death knell.
- chrisrhoden 6y agoThe on-by-default setting was technically a violation of the standard, which meant that participants felt they could ignore the setting for IE, which didn't help the initiative for sure. The industry-led-initiatives are all basically bad, for the obvious reasons. So many of them amount to telling ad networks whether or not the massive amount of data they have collected about you should be part of the consideration for what ads to show (for now) — many offer no possible way to opt out of recording and storing such data in the first place. This is a situation where legislation is probably the only answer.
- jokoon 6y agoI never click yes. Always use u block, right click and choose "block element".
- 2112 6y agoSame here, as previously learned on HN :)
- mfontani 6y agoNot clicking "yes" would work if most sites weren't, in fact, sending all tracking/setting all cookies by default, which most are :/
- Nextgrid 6y agoAt least it doesn't give them a legal basis for doing so, while clicking "yes" does. In practice, the real defense is a good ad blocker which would block both the consent prompt and the associated trackers.
- weinzierl 6y agoSomewhat related: Just yesterday the EU ePrivacy regulation took the first hurdle in Brussels. This will most likely bring some changes to the whole consent drama. I'm not good at reading legalese and there seems to be no commentary for the current version[1] yet. What I understand is that they "encourage" browsers to implement "whitelists" (their choice of word, not mine) as a solution to "end-users [..] overloaded with requests to provide consent". I'm not sure there is an update regarding first-party analytics cookies which some hoped will be there. [1] https://data.consilium.europa.eu/doc/document/ST-6087-2021-INIT/en/pdf https://data.consilium.europa.eu/doc/document/ST-6087-2021-I...
- tannhaeuser 6y agoI've changed my web browsing habits quite drastically: I usually just click "Save preferences", as opposed to the "Accept all" default on the most common form of Cookie dialog which hopefully opts me out of most shenigans. On some sites, I used to accept their defaults even. For example, heise.de (respected German computer news) used to be among the latter group, but when I saw they're carrying Facebook videos/pixels I've stopped going there. I'm leaving many sites when their draconian tracking/Cookies seems not worth it so overall, I visit a lot less sites than I used to, and in particular I find myself ignoring the one-time content marketing sites/blogs often linked from HN submissions greeting me with heavy Cookie dialogs. So for me personally, Cookie dialogs work as expected I guess. But I've yet to see actual figures on surfing behavior post-GDPR published anywhere. And I'm entirely unsure if people across the pond or publishing from other non-EU locations are even aware.
- jokethrowaway 6y agoI want to browse every dark corner of the web to discover useful facts and build my own ideas on subjects, not limit myself to the few most popular websites, driven by the wealthiest companies, that 90% of the people see. Between cookie banners and GDPR forcing newspapers to ban European visitors, I have to go through more hoops in order to see what I want. Just because you care about a website tracking you, that doesn't mean someone else cares. Legislation shaping the internet in this way and forcing everyone to think in a certain way is an authoritarian behaviour that I don't tolerate.
- a_imho 6y agoIsn't mass consent, forced consent and opt-outs illegal under GDPR? The legislation is there, why can't we create incentives to enforce it?
- Nextgrid 6y agoYes those are in breach of the regulation, and technically there are incentives - the maximum fines under GDPR can be quite large. The problem is that it doesn't seem like the regulation gives the right to a wronged party to sue for those sums of money. You can sue (I guess technically you can sue for anything anyway) but this would involve proving some damages. The only parties that can enforce the regulation (and levy the promised fines) are privacy regulators (such as the ICO in the UK, or the CNIL in France). Sadly, they've all demonstrated their incompetence and unwillingness to improve multiple times. There's a non-profit in the UK that wants to take the ICO to court over its incompetence/unwillingness to enforce the regulation - feel free to vote with your wallet: https://action.openrightsgroup.org/help-us-protect-your-data-illegal-ads https://action.openrightsgroup.org/help-us-protect-your-data...
- richardwhiuk 6y agoI'm not convinced any of this is legal FYI.
- mg5150 6y agoIMO, cookie consent should not be a website's reponsibility. It should be built into the user agent, which should block all cookies/analytics by default and prompt for consent when first visiting a site. Of course, this would most likely break adtech so it won't happen.
- forgotmypw17 6y agoI'm agreeing to the site sending me some Cookie: headers, for my browser (user agent) to ignore.
- yawaworht1978 6y agoI was using the skyscanner app to check some tickets the other day and there was blatant price manipulation(used another device from browser and vpn from halfway around the world to compare). Then I tried to use the web page from yet another device from an anonymous chrome tab, the "minimal cookies for essential functionality would not go away. Europe. No declaration what that means anywhere, not sure how this is in harmony with gdpr laws. Infuriating.
- benlivengood 6y agoWhat strikes me as strange is the different levels of scrutiny the web gets vs. real life. If we walk outside of our house then we're likely on camera, potentially with facial recognition. Cameras will track our cars' license plates. Cellular networks know where our phone is at all times. Our payment card networks and the stores we shop at gather data on what we buy. This is effectively public information because normal everyday citizens can just look around and see us and recognize us and what we're doing. I assume every action I take is probably observed and logged by someone. Those folks share the information with their business partners. This has been going on since at least the 1980s to various extents; there isn't a way to opt out of participating in public spaces unless one is particularly wealthy, and then the risk is becoming a celebrity and losing even more privacy. If anything, the web is slightly less intrusive despite occurring in public (I argue that the Internet is just as public as any real public space; we rely on third-parties to forward all our traffic. We use TLS if we want to hide the details of what we're doing). It's not technically us being tracked but our devices and we can wipe them, block javascript or cookies or network requests, etc. Maybe tracking is more effective for being fully automated and granular, but I'm not sure if that's worse from a privacy point of view. I think collectively we need to decide whether we want more privacy or anonymity. Full anonymity is nearly impossible to achieve but would mean that no matter where we went or bought or did no one else would be the wiser. Presumably we'd only see shadowy hooded figures in public so that even we had no idea who they were. It sounds draconian in the other direction. Privacy, to me, is a polite fiction that we won't individually bother each other by using all the information we know about each other. For the most part this is already done in real life and the web. Companies don't wholesale dump/sell every piece of data they collect about us; they aggregate and categorize it. This is the middle ground of privacy where people mostly mind their own business but don't blind themselves to trends and patterns of behavior occurring in public.
- switch007 6y ago(Warning: hyperbole) I feel like the consent notices are a form of torture. You might browse 10s or 100s of sites a day, and instead of being shown what you want, you're presented a consent notification with all kinds of cognitive processing needed to ensure you don't do something you didn't mean and to get at the information you wanted. Maybe lockdown is making me cranky, but I'm getting really, really tired of the popups.
- roelschroeven 6y agoYou're not alone.
- Zanneth 6y ago“Strictly Necessary Cookies” being defined as cookies that are necessary for a site to function always frustrates me. In what way does a news website need cookies in order to function? What exactly would break in showing news articles when I disallow all cookies to be stored in my browser?
- ncallaway 6y agoI think a common example is any site that requires authentication will need to store some kind of session cookie in the browser. I suspect many news sites have subscriber accounts that you can log in with. Many subscription news sites might consider the "how many free articles has this visitor viewed this month" to be a strictly necessary cookie, but that's just speculation on my part.
- rav 6y agoOnce the article got to opening the Dev Tools, I was surprised at the next approach: Copying the HTML into an editor, reformatting, copying into a C# project, setting up build rules for the copied HTML code, etc. In this case I would always reach for typing a JavaScript oneliner into the dev console, using a couple of tricks: 1. Right click the element in the Inspector and choose "Copy" -> "CSS Selector". 2. Start typing the oneliner in the web dev console: Use [].slice.call(document.querySelectorAll("PASTED CSS SELECTOR")) to turn the elements into a JS array. 3. Use (...).map((o, i) => {...}).join("") to turn the JS array into a long formatted text string. The result is the following, which took me a minute to type up and debug - from my perspective, a thousand times faster than firing up an IDE and setting up a new "project" to simply run a regex against some HTML. {const rows = [].slice.call(document.querySelectorAll("li.vendor-item")).map((o, i) => {const idx = 1 + i; const name = o.querySelector(".vendor-title").textContent.trim(); const url = o.querySelector(".vendor-privacy-notice").href; return `|${idx}|${name}|[${url}](${url})|\n`}).join(""); `Listing As At 30 December 2020 08:10 GMT\n\n|-|Vendor| URL |\n|---|---|---|\n${rows}`}
- trulyme 6y agoClever! It depends probably on the tech you are most comfortable with. I would probably copy to vscode and then use search & replace with regex there, or use multiline edit.
- deleted 6y ago[deleted]
- anotheraccount9 6y agoBuried at the end of my website's TOS, I informed users that by visiting my website, they agreed to offer their soul to me. I don't recall receiving any comments or complaints about this.
- trulyme 6y agoCool! And how many souls do you have? ;)
- keeganpoppen 6y agolemme check MySoulQL real quick... `SELECT * FROM ...`
- sfy 6y agoI find the gdpr-popups themselves to be far worse than any ads I’ve ever encountered. I really don’t care that they profile my data, build models, try to trick me into spending as much money as possible etc. I’m like the meme dog in the house fire - This is fine!
- occz 6y agoI've taught myself to almost automatically find the reject all-option (which they must provide to be compliant).
- wombatmobile 6y agoNot trolling - I genuinely wanted to know what the article says. I tried to read it, and got through, I don't know, 5 or 10 screenfuls before giving up, my mind numb. The article would be much improved with an opening paragraph that summarises the findings. It would also be improved with formatting that clearly differentiates the article text from the extensive site text it quotes. That site text is designed to numb users and put them off reading. It worked for me.
- BugWatch 6y agoOpen Tumblr. Choose not to accept / options. You'll be faced with 330+ individual agree/disagree toggles. THERE IS NO REJECT ALL BUTTON. If you're not technically inclined, you have to manually click them all. You also have to choose block/remove consent (or whatever it is called) for similar crap hidden under the "Legitimate uses" category moniker. Same shit. For this, and similar idiotic dark patters, there's a Firefox addon called "Unchecker". https://addons.mozilla.org/en-US/firefox/addon/unchecker/ https://addons.mozilla.org/en-US/firefox/addon/unchecker/ That, is, of course, until they start using buttons (some already do), double negatives in the wording or some such crap.
- guillem_lefait 6y agoThe IAB vendor list is a json: https://vendorlist.consensu.org/v2/vendor-list.json https://vendorlist.consensu.org/v2/vendor-list.json Easy to parse and analyse.
- deleted 6y ago[deleted]
- hnick 6y agoI came here for the comments but then went back and read the article. It's a deep dive into the cookie popup and all associated links, including 647 "partners" each with their own privacy policy. There are a lot of screenshots. One thing I would like to see (and it shouldn't be too hard to code, using the example) would be a mirror of the entirety of text of all the privacy policies and everything else pasted back to back. The screenshots and implication of having 647 privacy policies is bad enough, but I really want to see my scroll bar shrivel up and die.
- floatingatoll 6y agoIs it legal under GDPR to direct someone to read that much material to agree to use a site? I’m guessing a simple GDPR complaint supported by this request would be very exciting.
- godelmachine 6y agoI do this for every website I visit 1. First go to cookies and reject all cookies except the strictly necessary ones 2. Then go to “Legitimate interest” and then simply click “Object all”. At my primary browser level - 3. In Firefox settings, choose “Block all cookies” (Hasn’t messed with my browsing experience, yet) 4. Periodically keep on deleting your browser cache and cookies. Don’t delete browsing history and saved logins. I am currently looking for ways to minimize JavaScript usage. If anyone has any ideas, kindly proffer. Caveat :- I am fully conscious that despite the painstaking activity of rejecting all cookies and objecting to all legitimate interest, I cannot rest easy that all websites I visit are scrupulous, cognizant and conscientious of my choice. Also, I don’t get to option to reject and object on all websites, in which case I first check if there’s an archived snapshot on the Wayback Machine[1], or I simply forego reading the article altogether. For ex - www.BBC.co.uk, and even Reuters as mentioned in the OP’s post. Ref. [1] www.archive.is
- VMG 6y agoFWIW I can't log into twitter without allowing any cookies (chromium) trying "reject all third party cookies" instead
- wdb 6y agoI have seen the active for 'legitimate reason' or 'legitimate interest' options but I am still unclear what they consider legitimate reason. Does anyone know what that entails? I couldn't find it in the policy itself.