4 ms·
A bit of a tangent, but I think some people often criticize GDPR because it doesn’t have perfect enforcement, or some people are annoyed by the cookie banners.
by dsomers 5y ago
A bit of a tangent, but I think some people often criticize GDPR because it doesn’t have perfect enforcement, or some people are annoyed by the cookie banners.
However, a positive aspect I don’t hear talked about enough is how it has had a chilling effect (in the most positive pro consumer way possible) I’ve noticed in my industry people are just much more careful about user data now, compared to it hardly being talked about before GDPR. Just the threat of those fines has scared C levels enough to put at least some engineering resources on privacy and security where there was much less before from my experience.
- chromanoid 5y agoI totally agree. I think the Cookie thing is also deliberately overblown. Useful cookies don't need consent (which are not used for tracking).
- dkersten 5y agoIts also a different directive from GDPR, but people like to lump them together for maximum outrage.
- zeorin 5y agoThat's not accurate, at least as far as GDPR is concerned. Only necessary ones don't need consent, but the bar for "necessary" is high: the software wouldn't be able to function without it and there's no way to implement the software without it. Think: "address" is necessary for "delivery". Even then you still need consent to store the cookie under most versions of the "Cookie law", which is a complementary but different thing to GDPR.
- chromanoid 5y agoSure? https://www.iubenda.com/en/help/23672-gdpr-cookie-consent-cheatsheet https://www.iubenda.com/en/help/23672-gdpr-cookie-consent-ch... I would claim the only way to make a webapp with login securely function in a usable manner is to use a session cookie with secure transport policy. Do you really need more than that?
- simpss 5y agonot sure if you want to say that such a session cookie would require consent or not, but just to make it clear, it definitely doesn't. See 3.2 in data protection working party recommendations: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio...
- pimterry 5y ago> Even then you still need consent to store the cookie under most versions of the "Cookie law" I don't think the cookie law is different from GDPR in that respect. IANAL, but from the EU directive itself [1]: > Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information [...] and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user. I read that as having the equivalent "no consent required for strictly necessary data" get-out clause to the GDPR. Yes, strictly necessary is a high bar, but for cookies that clear that bar I think both GDPR & the cookie law let you off the hook. [1]: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- TeMPOraL 5y ago> Only necessary ones don't need consent, but the bar for "necessary" is high: the software wouldn't be able to function without it and there's no way to implement the software without it. Think: "address" is necessary for "delivery". Yup. That's literally the point. Phrased in an equivalent form: cookies that require consent are ones you don't actually need. It's thus not GDPR's fault that a site opts to spam their users with a consent popup - it's their choice to include cookies that aren't required to provide the service.
- jefftk 5y agoYou're assuming everyone agrees on "need". People disagree with governments all the time, so it's not surprising here that a website operator might consider a cookie to be necessary for the operation if their service, but the government views their needs differently?
- chromanoid 5y agoI think they literally mean "technically need". This is objectively deductible.
- simpss 5y agoIf i can delete the cookie and nothing goes visibly wrong, it's obviously not needed. Same with blocking a script that sets such a cookie. Most cookies are not needed for providing a service. edit: see the article 29 data protection working party guidelines here: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio...
- privacylawthrow 5y agoI am a privacy lawyer that has spent far too many hours on cookie issues. It is disappointing that your correct answer was downvoted. It goes to show just how much misinformation is out there about GDPR. The top comment in this thread demonstrates that as well as the Data Protection Directive of 1995 had a functionally identical requirement allowing users to opt out of completely automated decisions for credit purposes.
- pydry 5y agoI feel like the cookie banners could be fixed with an iteration of the law that requires adherence to an HTTP request header like do not track.
- TeMPOraL 5y agoI think DNT could be rescued if it could be turned into a browser-wide consent UI. Currently, with its history of being set to 1 by default in some browsers, it doesn't really distinguish between "I don't consent" and "I haven't expressed an opinion", giving sites an excuse to ask you anyway. Myself, I wish another GDPR iteration would instead mandate the shape and form of the initial consent popup, requiring it to fit to the following template (or something similar/equivalent): +------------------------------------------------+ | Allow additional data collection? [X] | | | | This site would like to use technical means | | such as cookies and local storage to collect | | data about you and your computer. This data is | | not necessary for the correct functioning of | | this site, and does not impact the service | | it provides. | | | | Do you consent to this opt-in data collection? | | | | GDPR requires this message to be shown because | | the data collection requested is not necessary | | and may carry data privacy risks. Necessary | | data collection does not require consent form. | | | | [Learn purposes and] [>I do not consent<] | | [configure consent ] | +------------------------------------------------+ With an explicit [>I do not consent<] button, pre-selected, in the "call to action" color, doing the same thing as [X] does, which is declining data collection described. Displayed in the same language website content is, and with specific regulations guarding against the common "dark pattern" bullshit. I'm sure Brussels has some webdevs that would be happy to provide standard templates and React components and whatnot, so that site authors could just plug in a stylesheet and a JSON blob to configure the [Learn purposes...] section. The ultimate solution would be for member states' DPAs to get off their collective butts and start issuing fines for the current crop of blatantly illegal consent popups, but in the interim, it would be helpful to regulate the popups, so that they clearly communicate that a) they're requesting strictly unnecessary tracking that can be safely ignored, b) showing an annoying popup is a choice by the website owners, who decided to request consent for additional tracking.
- MomoXenosaga 5y agoVery true. Enforcement is never 100%. Crimes will continue to happen, some people will always get away with it. But that doesn't mean we should give up on making laws.
- YetAnotherNick 5y ago> I’ve noticed in my industry people are just much more careful about user data now My company and all the sites that I use didn't decrease data collection by a bit. They just added consent form in place of T and C. I would like to hear any counterexamples though, that some company actually stopped collecting data that they were collecting before GDPR.
- hansilo 5y agoHere's a high profile example of a company that stopped placing non-essential cookies: https://github.blog/2020-12-17-no-cookie-for-you/ https://github.blog/2020-12-17-no-cookie-for-you/