8 ms·
The real problem with the law is that you need a cookie to set the preference for the tracking to begin with, which I don't want. The law of course states that
by bsdubernerd 5y ago
The real problem with the law is that you need a cookie to set the preference for the tracking to begin with, which I don't want. The law of course states that there shouldn't be any tracking without explicit consent.
I'm sure the people using cookie blockers here are pretty familiar at how bad the browsing experience becomes if you expire and/or block cookies.
The law should have been amended to REQUIRE websites to honor the already-existing-and-failed do-not-track header and ENFORCE that such header results in no popup whatsoever, since the choice has ALREADY been made.
That is also required since the law is pretty generic and doesn't explicitly mention "cookies", but any method which can be used for tracking purposes.
The question for a website on a technical level is then:
- If I land on a website with such a consent, how do I guarantee that the first request before and UNTIL the consent is acted on respects my will to not be tracked?
- Doing so as a dev is an absolute nightmare. Using the header would be a huge time saver.
- As a user, how do I ensure I'm not being tracked? Let's be honest: I do not trust even google to honor the setting. Shady organizations are commonplace on the web. Everybody knows (browser vendors included) you need to act in a defensive manner.
Blocking everything unless explicitly allowed is the only strategy that should be followed currently by those who care (and are willing to endure the resulting experience)
- sarnowski 5y agoNot all cookies require consent. There are many legitimate reasons to collect personal data - consent is only required if you cannot find another legitimate reason. For cookies that mean: technical cookies that you need to technical provide your offering (think of authentication session cookie, loadbalancer sticky session cookies, but also cookies to understand if someone opted into tracking) can be set with legitimate interest and do not require a consent. A consent under GDPR is strictly opt-in. This means, by default you must not track a user (EU citizen) that just landed on your site. After consent, you can load your GA plugin.
- sime2009 5y ago> The real problem with the law is that you need a cookie to set the preference for the tracking to begin with, which I don't want. The law of course states that there shouldn't be any tracking without explicit consent. The law doesn't concern itself with tracking directly. It talks about the use and handling of personal information. Putting a cookie on your machine to record that you rejected all tracking (i.e. "tracking=no"), is perfectly fine and does not require consent. It is not personal information.