25 ms·
Google fined €150M, Facebook €60M for for non-compliance with French legislation
- pxeger1 5y agoGovernments should do something about the phenomenon where a company get so many fines that they just become part of their business model.
- pull_my_finger 5y ago> Following investigations, the CNIL noted that the websites facebook.com, google.fr and youtube.com do not make refusing cookies as easy as to accept them Seems like a ton of websites are using the same cookie framework and they all do this. You get a pop up with with a button to allow all, or a button to customize your preference and you have to go through a bunch of accordions and grey patterns to make sure everything but "essential" cookies are disabled.
- SkySkimmer 5y ago>Since March 31, 2021, when the deadline set for websites and mobile applications to comply with the new rules on cookies expired, the CNIL has adopted nearly 100 corrective measures (orders and sanctions) related to non-compliance with the legislation on cookies. I didn't realize there was that delay, I thought the rule was supposed to be enforced years ago.
- 88 5y agoMy understanding is EU member states have some freedom to implement the “cookie law” (ePrivacy Directive) in different ways, and this deadline is linked to some updates to the legislation in France which took effect from Oct 2020.
- Nextgrid 5y agoBut this is (also?) in breach of the GDPR which was supposed to go into effect in 2018.
- dj_mc_merlin 5y agoThere's multiple delays, arguably for a good reason. First, the law has to be ratified by each member state, which will also mean another delay state-side until legally enforceable. Institutions usually have a warm-up period too until they start enforcing new laws, preferring warnings beforehand. It might seem inefficient but generally this is the only sane way to roll out changes across a society. Having people coordinate and "change habits" (as deplorable as the present habits may be) is best done gently. Providing ample time and warning for people to find a good course forwards.
- Aachen 5y agoOne might even argue it's still too fast, given how many cookie walls we see. People are not aware that any site with such a banner is shady and that it's usually not required, and by now everyone has it fixed in their mind that it's the politicians that are stupid and don't understand technology. If we had done a better warmup with better communication, we might have had better-informed people (at least the techies, I understand that not every grandma is going to know the details here).
- hadrien01 5y agoThat's the delay set by the French DPO (Cnil). At that date, most French websites finally introduced an option to directly refuse (often a simple link saying "Continue without accepting").
- calltrak 5y ago
- johnklos 5y agoIt's a shame there aren't more big fines for shitty sites, like stackoverflow.com, that punish people who don't accept all cookies by prompting on every visit. If that's not bad enough, having an "Accept all" button but requiring another click to have the option of refusing, then making us manually select each category to turn off, then confirming, is certainly not symmetric. These large sites know exactly what they're doing. They're hoping people will become fed up enough to just accept, or they're hoping there'll be enough accidents where people click "Accept all". It's rather shitty.
- jason-phillips 5y ago> ...shitty sites, like stackoverflow.com, that punish people who don't accept all cookies by prompting on every visit. Easy solution: UBlock Origin > eye dropper tool > highlight cookie div in lower left corner > click Create button I agree that they're very annoying.
- pmontra 5y agoI selected the cookie dialog with the element picker of uBlock Origin and made it go away forever.
- bunnythefifth 5y agohttps://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/
- mlatu 5y ago"In most cases, it just blocks or hides cookie related pop-ups. When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do). It doesn't delete cookies. "
- pmontra 5y agoThank you. I forgot to mention that I'm also using Cookie Autodelete https://addons.mozilla.org/en-US/firefox/addon/cookie-autodelete/ https://addons.mozilla.org/en-US/firefox/addon/cookie-autode... I whitelist the sites which I need cookies for.
- jhoelzel 5y agoGood. I for one am sick of tidiously applying my cookie guidlines and popups "correctly" only to see dark patterns everywhere. No, not a single person has a legitimate interest in being subscribed to your 160 marketing companies. Even the people that "like ads" know this is just blanket stalking.
- glitchcrab 5y ago'legitimate interest' is such a bad description because most (uneducated) people will think that it means they have to accept it because it is legitimately allowed. Those cookies are only legitimately interesting to the ad networks, and it's incredible how many companies are listed under that banner when you click through.
- quickthrower2 5y agoEquivalent to: ordinary person fined $0.62 for littering.
- makapuf 5y agoMore like a headline: "ordinary person <name> fined 0.62 for littering". Would I like to litter, the fine would be slightly annoying (maybe worth busting my ass to a proper trashcan to avoid this fine), but also being in the news about it.
- hnbad 5y agoI don't think Google and Facebook are very concerned about having minor headlines about cookie-related fines. The users who would react negatively to this already don't trust them and those who trust them either don't understand the issue or don't care.
- makapuf 5y agoYou're right, unfortunately. I hope this adds up but I'm not myself convinced.
- hetspookjee 5y agoSo what platforms are currently serving most of the news? I believe the number is well over 50% of the news is served through Facebook and Google, but I struggle with finding an actual number on it. In any case, I'm sure there are plenty of ways to push down any negative news surrounding their own platforms.
- ErikCorry 5y agoIt's over half of Google's estimated annual revenue in France. Not sure how you did that calculation, but if someone confiscated half your income it would not be much like a 62 cent fine.
- deleted 5y ago[deleted]
- stuaxo 5y agoThis is good, hopefully we will these start to see buttons to disagree to all appear on more sites - I've certainly given in and clicked agree a few times.
- MaxikCZ 5y agoMy uBlock origin blocks a huge part of cookie banners. For some "Behind the overlay revival" works great, mainly for sites that just darken whole page with modal in the middle. Its one click away. For the 1% I manually block the element through uBlock origin, and the remaining 0.1% of websites that send you to another URL to confirm/deny, with no easy way to deny (looking at you, techcrunch) I just leave the site.
- Thiez 5y agoBut will that "reject/disagree all" button also object to the 100 "partners" that data will be shared with because of (il-)legitimate interest?
- MauranKilom 5y agoIf a company does that then it doesn't need to show a button in the first place - both are an equally invalid basis for data processing.
- Cthulhu_ 5y agoOr do away with them altogether; I wish that they tweaked the laws so that tracking or not is a browser setting, optionally enabled on a per-website basis but with no room for websites to bully you into it. As we can see from Apple's changes recently, the vast majority of people do not agree to being tracked. The cookie banners bully people into allowing it anyway, because the opt-out is so convoluted.
- baby 5y agoYou can already manage cookies on the browser side.
- Aethylia 5y agoSurprised that amazon isn't in there for the horrible UX of sending you to a separate page to change preferences, then back to the homepage.
- marcodave 5y agoI agree, I got bitten already more than one time, and it's ridiculous how can they get away with it. How's not that an infringement?
- josh_fyi 5y agoThere are so many dark patterns for tracking users, not to mention other dark patterns. The excessive focus on cookies is a distraction. (Not to mention that cookies can be a valuable, almost unavoidable way of providing useful services.) Dark patterns should be suppressed, but balancing attention on all such patterns.
- kuschku 5y agoEU law never specifically mentions cookies, it applies to all forms of tracking, even e.g. to CCTV in public spaces. GDPR and eProvacy Dir. are very broadly defined because they apply to anything containing or storing identifiable data, even IP addresses in server logs.
- izacus 5y agoWow, nice. Does that mean that they'll issue the fine for all those hugely shitty sites with GDPR dialogs that slowly load "Reject" buttons as well?
- raverbashing 5y agoIt would be a good idea to fine a site based on their fake delay and/or how many cookie options they present (if it's one of those that give a switch for every "cookie vendor" they have for example)
- flipbrad 5y agoThis isn't a GDPR fine, it's EU ePrivacy Directive. That's why the French regulator felt it could fine Google directly rather than refer the matter to the Irish regulator - it says the GDPR's one-stop shop rule doesn't apply to this infringement.
- YetAnotherNick 5y agoWhat's the difference between those two? What are the requirements for ePrivacy directive for sites?
- flipbrad 5y agoePrivacy predates GDPR and applies specific (and stricter) rules to a few things, including against intrusion to internet-connected devices (the ePrivacy Directive's so-called cookie rule also affects malware, telemetry, software updates, etc). It's long overdue an update but its intended replacement, the ePrivacy Regulation, is taking a while to be agreed by EU legislators. In the meantime we're stuck with out of date legislation that's applied and enforced without the benefit of the GDPR's "one stop shop" enforcement coordination rules - neither of these things is ideal!
- Karupan 5y agoI often read about regulatory bodies penalising big tech, but have often wondered if they actually pay the fines? Or do they end up paying a much lesser amount after appeals?
- andylynch 5y agoCivil fines like this are normally announced as a settlement with the company concerned including (like here) undertakings to correct their practices. This means no appeals, and also leaves the door open for court action if they continue in misconduct breaching the settlement.
- sjtindell 5y agoDumb question - I always come on HN, where lots of web devs hang out, and see people decrying dark patterns. So who builds this stuff? Where are the devs defending it? Or do they just take a check and keep quiet?
- omgitsabird 5y agoMaybe they attempt to comply with regulation that is often confusingly worded and written by people who are not human computer interaction experts.
- geewee 5y agoI've done a lot of compliance work, and the laws are _very clearly_ worded. This is definitely a case of "let's see what we can get away with"
- franciscop 5y agoExactly, I don't know what people are saying (well, I smell an agenda) but the GDPR is the easiest "specification" I've read.
- arkh 5y agoBut if you can't be bothered to read a RFC, 40ish pages of GDPR will be too much for you. You've got code to write, reading and learning is for schmucks.
- usr1106 5y agoThese fines have nothing to do with GDPR. GDPR introduced one stop shopping with EU for data controllers. Google does that in Ireland. GDPR is a regulation, legally binding all over EU. And for others offering services to EU residents, although that's probably unenforcable. When they get fined in France the basis is a French law. Probably a law to implement an EU directive. The cookies directive (don't remember the official name) is older than and different from GDPR.
- 5y ago
- JCWasmx86 5y agoThis fine is ridiculously small, it simply won't hurt these companies.
- flipbrad 5y agoLook again at the nature of the offence - it's not about consentless tracking (any tracking here, using cookies, was opt in). Plus, users that were concerned enough could quite easily refuse; they just couldn't do it with a single click. How much do you think they actually suffered? How big of a fine do you think something like this actually deserves (given we're just talking about French users here, not EU or global)?
- JCWasmx86 5y agoGiven Google made 17 Billion dollar in Q1 2021 [0] in Europe/Africa/Middle East, I would say that around 2 Billion dollar would be more appropriate. Facebook made 6.5 Billion dollar in Q1 2021 [1] in Europe, so maybe around 1-1.5 Billion dollar. [0] https://businessquant.com/google-revenue-by-region https://businessquant.com/google-revenue-by-region (Didn't find a better source or one that lists the revenue for France only) [1] https://www.statista.com/statistics/223279/facebooks-quarterly-revenue-in-europe/ https://www.statista.com/statistics/223279/facebooks-quarter... Edit: I tested the banners: Facebook: "More Options" -> "Allow only essential cookies" (1 click more than necessary) Google: "Anpassen" -> Switch off "Suchanpassung" -> Switch off "Youtube-Verlauf" -> Switch off "Personalisierte Werbung" -> "Bestätigen" and then there are 3 seconds of delay with progress bar. (4 clicks more than necessary + delay). This delay does not occur, if I simply press "Accept all"
- flipbrad 5y ago2 billion dollars just in respect of French users having to wait a few seconds and do a few clicks?
- thrwyoilarticle 5y agoCould we not be disingenuous? If the delay was meaningless, it wouldn't exist. There is a clear intention by these companies to bore or confuse people into signing their rights away. Consider how many lawyers are on payroll or retention at these companies who are aware of the requirements of the law, then consider that G/FB made a cynical, calculated decision to ignore it.
- twblalock 5y agoThese stupid cookie dialogs are a result of EU law in the first place. They shouldn't exist, and even if they exist in Europe, as a non-European I shouldn't have to deal with them. Cookie dialogs are the contemporary equivalent of popup ads, in terms of the annoyance to users. I'd love to find a browser that makes them go away, just like browsers blocked popups years ago.
- top_sigrid 5y agoYes they do exist becuase of the GDPR, but what's your point? So the privacy law that is regulating tracking and data transfer - especially when ambiguous to the user - is to blame and not the companies performing these shady practices? The companies that then make a cookie banner cat-and-mouse game with dark patterns to trick users into "consenting" anyways, although it was clear from the beginning that many of these practices are illegal, a fact that jurisdictional takes some time to establish. But sure, the law which puts users' privacy at the center is to blame and not these companies.
- twblalock 5y agoYes, the law is to blame. The companies never would have done any of this except for the law. The GDPR is the reason the web is festooned with ridiculous cookie consent forms of all kinds, both the good ones and the bad ones. Keep in mind too that I am not a citizen of an EU country. I have to put up with these dialogs and I get nothing in return. The upside for EU citizens is that they have a law to protect them. All I get is the downside.
- kuschku 5y agoSo you suggest that without the law they wouldn't track you? Or that without the law they wouldn't even give you a notification that they do illegally track you?
- YetAnotherNick 5y ago> So the privacy law that is regulating tracking and data transfer - especially when ambiguous to the user - is to blame and not the companies performing these shady practices? Yes, the purpose of the law is to end the shady practice which doesn't seem to be happening and no one is caring about the outcome. Popup seems to be just like a second ToS which existed in web for years. If the law doesn't track its real world effect or doesn't do an analysis on the benefit to annoyance ratio, yes it's the law which is to be blamed.
- MrDresden 5y agoGood they get fined, but those amounts really are peanuts for companies of that size.
- geewee 5y agoYou'd imagine(hope?) they might get more fines if they don't stop.
- nmehner 5y ago"In addition to the fines, the restricted committee ordered the companies to provide Internet users located in France with a means of refusing cookies as simple as the existing means of accepting them, in order to guarantee their freedom of consent, within three months. If they fail to do so, the companies will have to pay a penalty of 100,000 euros per day of delay."
- PeterisP 5y agoSo, 36.5 million per year of delay - perhaps that's affordable on their scale.
- Youden 5y agoIf they continue to refuse, the fines are unlikely to stop there.
- MauranKilom 5y agoWell, it's ~356 developers they could have paid for that year instead. If only France fines them that might be workable, but there are a lot of other countries in the EU...
- avianlyric 5y agoGDPR allows fines up 4% of global annual turnover. So $3B for Facebook if the regulator wanted to.
- makapuf 5y agoWhat would prevent (apart from being painful on purpose) a browser "do not track" preference to be set once (off by default / changeable per site, not to repeat what IE did to kill DnT), and sent as a DnT header (do not track / ask me everytime / legitimate interest only) ?
- sime2009 5y agoNothing prevents a browser from doing this. But it does nothing unless websites respect it. So far many websites haven't been cooperative, as evidenced by the amount of shitty cookie consent pop ups we all have to deal with.
- makapuf 5y agoSure, but we're speaking of a kind of standard (RFC or more specific one). In this case, compliance is in the law: albeit not perfect and people trying to game it, you have to comply or be fined (if you do business in the EU). EDIT: reference to DnT header https://wikipedia.org/wiki/Do_Not_Track https://wikipedia.org/wiki/Do_Not_Track
- MauranKilom 5y agoCompliance is already in the law: Accepting and rejecting cookies needs to be equally easy, otherwise you don't have consent for processing personal data. That's how they got these fines.
- geewee 5y agoWonderful. It's nice to see that the regulation is (slowly working) where we went from. - I don't have to tell you about tracking - I'll tell you but assume you accept - I'll ask you but make it extremely frustrating to opt-out - (Hopefully soon-ish) I'll ask you and make it equally easy to opt-in and opt-out
- medstrom 5y agoI don't know about Facebook, but Google/Youtube sticks out as the only place where I effectively have to Accept All every time. Most cookie dialogs take only two clicks to reject nonessentials! You click something like "Customize" and then "Save", skipping the step with the dialog boxes, because the nonessentials will be all already turned off when you enter the config screen, at least if you visit sites from Sweden. Even better if you visit sites from a Danish IP, I noticed there often exists an actual "reject" buttom which doesn't appear when you use a Swedish IP.
- aspenmayer 5y agoThanks for this relevant quality of life info.
- verytrivial 5y agoI noticed at the start of the WhatsApp T.O.S. change frog-marching that https://www.whatsapp.com https://www.whatsapp.com had (edit: AND STILL HAS!) a single click 'Accept' and some weaselling links about 'Checking your Browser settings'. Super--and I might even go so far as to say--hella assymetrical. Is there some exception for 'meta services' like this? It's not the service/app itself, but is required if you want to read T.O.S. details, get help, etc for WhatsApp itself. Or should Facebook open their checkbook again?
- charcircuit 5y agoHopefully companies will protest the EU and just get rid of these annoying popups altogether. If the EU wants to make it impossible for people to visit sites like YouTube I'm sure EU citizens will complain.
- MauranKilom 5y agoI think you gravely misunderstand. Companies do not have to show cookie banners, if they have other legal grounds for processing user data. The intended effect of the law is actually just that: Companies processing only data they absolutely need to. Your strategy for protesting the (totally sensible) EU law seems strange: "Let us openly break the law, let the EU announce that we broke the law, refuse to do anything about it, let the EU announce that they will fine us until we stop doing business in EU and then hope that the users take our side". Seriously, I'm interested in what PR message you intend to come up with that convinces users the EU is at fault for you mishandling people's data.
- unobatbayar 5y agoFrench administrative regulatory fining American tech conglomerates is laughable. Do they even have to pay this?
- po1nter 5y agoYes, if they want to keep doing business in France.
- d8c6c050cb0a4d7 5y agoThe fines were issued to Facebook Ireland and Google Ireland, which are within the jurisdiction of the EU. Typically if a company wishes to do business with EU residents they have to comply with the EU regulations. Many larger companies choose to incorporate somewhere in the EU to make this easier or in some cases they will even incorporate in each country that they do business in.
- WHA8m 5y agoCan you elaborate why this is laughable to you? This might be a shocker, but even American companies have to obey the local law of the country they operate in. Big tech runs offices, has infrastructure and profits of a huge market in those countries. All of this is leverage a country can use to enforce their law.
- unobatbayar 5y agoPerhaps laughable wasn't the proper word. It's just that there is nothing anyone can do against Google or Facebook at this point.
- ricardo81 5y agoI agree on the logic, though G and FB are hardly the only culprits. Ballpark guess is >50% of sites I visit with a cookie popup behave in a similar way. Would be much easier if there were a normalised DOM structure/wrapper for these cookie popups so an extension can be made to choose the preferred choice, with possible exceptions. Between the cookie popups and a "sign up to our newsletter" as soon as your pointer leaves the viewport- they're a huge time suck. I've seen some extensions advertised but unsure whether they're able to cater for all the variations of layout.
- ErikCorry 5y agoSo 50% of sites do this, but the only ones getting fines are foreign entities that politicians like to hate on for votes? That indicates to me that this is about revenue and politics, and not about the law. Call me cynical.
- Macha 5y agoAlternatively, it's about the cost/benefit of starting with the long tail vs starting with the largest offenders?
- thrwyoilarticle 5y agoThey're also the two who run the biggest ad networks. It's their cookies that other illegal dialogs are installing & it's them that benefits the most from a culture of ignoring the law. I'd be more than happy for fines to be extended to other companies but I hope these fines will be a wakeup call for them. If they don't want the fines, they could do what you and I do every day and follow the law.
- ErikCorry 5y agoThis is about the dialogs on facebook.com, google.fr and youtube.com. Not about dialogs on other sites that may or may not use ad networks.
- 5y ago
- jeofken 5y agoI can’t imagine anyone on HN not understanding this distinction; I can’t imagine any parliamentarian does understand it. A website can not “set a cookie” in the browser. The website can include a cookie that the user (agent) optionally can include in future requests. The user does not “accept” or “reject” cookies, but rather chose to include them in future messages, or not.
- kaba0 5y agoWhen disallowing setting such cookies will render the website unusable, this technical difference is not really meaningful. In practice a website can freely deny you usage without the correct semantic usage of cookies made up by them — that’s why laws are very important.
- zarzavat 5y agoThe user agent doesn't know what the purpose of each cookie is. It could be a purely functional cookie (like a session cookie for an e-commerce website) or an advertising cookie. The website has to allow the user to accept the former and block the latter.
- samuelfekete 5y agoThe money raised from these fines should go towards building a browser that handles cookie permissions on the browser side. Every site should get to ask for cookie permissions only once - through the browser - (like with notifications or location), and the browser should remember the user’s preferences and never ask again.
- userbinator 5y agoshould go towards building a browser that handles cookie permissions on the browser side. Don't they all do that? Per-site cookie management in the browser has been around since IE6 if not earlier: https://www.nlm.nih.gov/share/image/cookies_ie6_002.jpg https://www.nlm.nih.gov/share/image/cookies_ie6_002.jpg
- rightbyte 5y agoI have a vague memory that IE or maybe Netscape asked you for permission for each site with cookies way back?
- samuelfekete 5y agoTrue, but the UX was deemed to complex for the average user. Instead of it being something the user has to manually find in settings and configure, the browser can show an unobtrusive prompt for the user to agree whenever a site tries to store a cookie for the first time. There could also be changes to the cookie standard that allow specifying if a cookie is “essential”, so browsers can permit them by default, or “non-essential”, so the browser should prompt the user.
- baby 5y agoBrowsers already do this. These cookie laws are just plain stupid.
- MauranKilom 5y agoNo, the websites choosing to disregard both spirit and letter of the law are plain stupid.
- matsemann 5y agoEvery company using TrustArc or similar stuff should be fined.
- Fiahil 5y agoI always wonders where is the money going in this case ? I'm sure some part will go toward keeping the CNIL properly staffed (which is great), but where is the rest going ?
- bjornstar 5y ago@dang can you fix the typo in the title? Assymetric => Asymmetric
- asymmetric 5y agoThank you :)
- jpswade 5y agohttps://nocookielaw.com/ https://nocookielaw.com/
- tgv 5y agoModern day Robin Hood: steal from the poor and give to the rich, but frame it as freedom or some other weasely concept. Such a rebel.
- kuschku 5y agoEven 2 out of 3 configuration options for their consent manager immediately turn it into an illegal setup. GDPR isn't complicated, it only sounds complicated if you want to find a loophole without breaking the law. If you just comply, it's super easy and simple to follow.
- ErikCorry 5y agoI always accept all cookies, and it has caused exactly zero problems for me. I have no idea why everyone is getting so excited about them. The only annoying thing is having to click accept all the time. Seriously, the people downvoting this should try it. It frees up your mind to think about things that actually matter.
- mafuy 5y agoIt's not that you get punched in the face if you 'accept all'. It is that you create a small but real possibility to suffer from it in the future. Like getting a lottery ticket to win something like paying more for your flight, being denied insurance or bank loan, being subjected to political manipulation, having your name published alongside your sexual preferences, or, to nicely round it up, being selected for participation in a governmental work camp. All of this did happen in the past, albeit not to everyone of course, of course.
- ErikCorry 5y agoThose are paranoid things to worry about. Can you name a single example of someone in Europe who was denied some sort of insurance because they clicked on the wrong cookie consent button? If my government wants to put me in a work camp will Europe's cookie consent laws protect me? None of this makes sense.
- jokoon 5y agoI never accept those, because I highly suspect they're legally binding. The amount of those popups elements I have hidden using ublock with right click, it's staggering. Some websites introduce a vertical-scroll: hidden; rule on <body> that I often need to remove manually, or to introduce a CSS rule in ublock. Reader view often help a lot, but some websites, like yahoo, make it so that reader view won't work (it will display the consent thing in reader view). Some websites in france went another route: they ask users to accept cookies or to pay instead. It's crazy. It really shows data really, really matters to them. Other gimmick, I had big troubles using the mozilla matrix server because of cookies, since I've set up firefox to delete all cookies at shutdown, except those in a whitelist.
- the_other 5y ago> I never accept those, because I highly suspect they're legally binding. Thanks for articulating a feeling I hadn't managed to put a label on yet.
- avianlyric 5y agoThankfully GDPR makes it pretty clear they’re not legally binding if they don’t follow the rules. And most consent forms don’t follow the rules.
- overlordalex 5y ago> The amount of those popups elements I have hidden using ublock with right click, it's staggering. I have a bookmarklet saved that simply deletes fixed elements, making it faster and easier to get rid of those[0]. However I have noticed sites are starting to make their banners more akin to shrinkwrap agreements where they state that dismissing the popup or continuing to read without making a choice is equivalent to acceptance. [0] What I find most interesting is how many websites become much more readable by this - I hate sites that use a good third of the screen real-estate for headers and footers, nevermind those awful menus that only appear on scroll-up and cover the top few lines of content. https://alisdair.mcdiarmid.org/kill-sticky-headers/ https://alisdair.mcdiarmid.org/kill-sticky-headers/
- 5y ago
- asimpletune 5y agoShould there be a plugin where you can just report offending websites for bad cookie consent practices?
- Nextgrid 5y agoIdeally data protection authorities would just run a web scraper to identify these preemptively. Most non-compliant flows are implemented using a handful of known libraries (TrustArc for example) that are trivial to detect.
- neurocat123 5y agoI seem to be the only one with this opinion in this thread, so perhaps I'm misguided, but the reason I'm tired of these cookie permission pop-ups is that they strike me as security theatre. It's pretending to the end user that they have some control over being tracked or not, when we all know that they'll be tracked all the same, with non-cookie based fingerprinting methods. Can the "don't do evil things with user data" intent of this legislation not simply be subsumed under GDPR?
- dvdkon 5y agoThey're not actually cookie permission pop-ups (that was a previous law IIRC), they're much broader consent pop-ups about handling user data. You don't really have any assurance they're not tracking you after declining, but it would at least be grossly illegal.
- MauranKilom 5y ago> Can the "don't do evil things with user data" intent of this legislation not simply be subsumed under GDPR? It already is. Processing personal data requires a legitimate basis. Freely given consent is one of those, and the reason these companies are being fined is because "freely given" requires symmetry in accepting/rejecting. Without the symmetry, the companies had no legal basis for processing the data, so they got these fines. It is harder to prove "evil things" in general, but the first step is preventing users from being coaxed into agreeing to "evil things" (or rather, making clear that this is illegal and will be punished).
- zaptheimpaler 5y agoThe next step in these laws should be mandating program consumable APIs for essential functions. What if every website showing a cookie banner also had to expose a few endpoints: /cookie-tracking/all/accept /cookie-tracking/all/info /cookie-tracking/essential/accept /cookie-tracking/essential/info Browsers could hook into these or making a browser extension would be easy enough. As a bonus we might witness the first ever televised government bikeshed over API/naming/is it really REST though?
- baby 5y agoThis seems like a nightmare for web devs
- noah_buddy 5y agoI think that a good society should probably prioritize data/cookie rights over webdev nightmares.
- baby 5y agoIt honestly is such a small overblown issue
- jpkeisala 5y agoWell, it is already nightmare. I would gladly welcome some standardization on cookie banners and tracking.
- yummybear 5y agoIt seems reasonable - until you actually look at the specifics. Some site may be just static files with no server-side api handling. Some may use GraphQL exclusively. Security. Government dictated API design will be an absolute shitshow. Etc.
- zaptheimpaler 5y agoFair enough. I'm not particularly good at web dev so maybe there are better ways. In the spirit of the law, yes maybe it should be less about mechanism and more about policy. The law they got fined over was that "accepting tracking cookies should be as easy as refusing them". I do think its possible to amend that to say _something_ like "both accepting and refusing should offer a simple program accessible mechanism to do so". Combined with the existing law, it would mean the mechanism/API can't be made arbitrarily difficult to reject but easy to accept. There will be room for debate here too, but it fundamentally is possible because the banners have to use such a mechanism.
- curiousgal 5y agoThis is the epitome of French hypocrisy when it comes to Big Tech. "Assymetric cookie dialogs" are a big no no but some of the biggest French websites give you two options: 1- Accept cookies and access the website. 2- Refuse cookies and pay 2€ per month to access the website. How is that less hostile than having to click a few extra buttons?
- alkonaut 5y agoI believe that’s also against the letter of the regulation.
- thrwyoilarticle 5y agoSomeone stole my bike but, sadly, was not caught. There are many more criminals than there is time to find and prosecute them.
- accidental_spec 5y agofuck the laws!
- alkonaut 5y agoYes. Fantastic. The figures are a bit low but this is exactly what I have been asking for. Big visible fines to corporations for simply making asymmetric non compliant cookie dialogs. I wish they’d also go after one of the smaller fish that use a “cookie dialog provider” in default configuration. Effectively saying “if you think you can get away with buying this scam service you were wrong and the fine that could show up any day could end your business”.
- pjerem 5y ago> Yes. Fantastic. The figures are a bit low While it's true they are a bit low compared to those companies revenues, they are pretty much higher than what we are used to until now.
- durnygbur 5y agoAmerican media companies when your account displays irregular activity: "nuclear ban on email, phone number, app store account, WiFi SSIDs, device fingerprint" The same companies with cookies: "here's consent dialog, on every visit, multiple times"
- baby 5y agoHonestly these cookie laws are a shit show. The experience of browsing the web in Europe is shit due to all the popups asking you about cookies. Browsers have extensions to manage cookies, why force website to come up with their own unique UI for cookies? Furthermore cookies are not even user-friendly concepts, they are made to be digested by machines, it’s such a misunderstanding of regulators type of situation.
- the_other 5y agoThe intent of the laws is to force businesses to make better decisions about how they monetise and how they manage user data. Most businesses have reacted by refusing to make these decisions in favour of users, instead choosing to make the experience of using their sites unpleasant to generate a backlash against the law. Like you're doing. You could say that the law is failing because it opened the loopholes allowing businesses to choose to behave badly, externalising the decision making to users. If that's your opinion, can you be a bit more specific, so we can dig into that issue and explore solutions and objections?
- baby 5y agoThe law is failing because it created a worst situation. This has been going on for what seems like a decade. Nobody won from this. This is a bad law QED.
- dvdkon 5y agoI don't see how the situation is altogether worse. Now everyone is aware about the extent of tracking and can opt out, even if most sites don't make it as easy as it should be. Is clicking "yes"/"no" such a big hassle that you'd rather have blanket tracking everywhere?
- baby 5y agoDo you live in Europe?
- efficientsticks 5y agoI’m relieved this (eventually) happened. Every day those consent forms remain up is like a giant F. U. from Google at GDPR. It’s not like they didn’t realise they were completely non-compliant.
- tyronehed 5y ago
- phrankeom 5y agoHello , I'm hacker 858 and from < Thailand > Power < 32 GB > it's a shame three arent's more big fines for shitty
- tentacleuno 5y agoDoes this mean the sites will only be fixed in France? They only seem to cite French legislation as the reason for the fine: > This constitutes an infringement of Article 82 of the French Data Protection Act.
- nottorp 5y agoMost likely. And in 3-10 years when they run out of appeals.
- tentacleuno 5y agoYeah I wouldn't be surprised if they implement this as a France-only thing, considering a lot of other regions haven't put their foot down yet. It's scummy, but I've come to expect it from these corporations.
- yua_mikami 5y agoI think punishments for breaking privacy regulations and laws should be applied to those who break the spirit/intent of the law and not just the letter. Otherwise it's just an arms race, when one loophole closes another opens.
- kuschku 5y agoLuckily, that's exactly how french law already works.
- avianlyric 5y agoThat’s how GDPR works. Most EU regulation focuses on outcomes, as opposed to specific methodologies. Results in many Americans complaining about how difficult to interpret the regulation is, due to lack of specificity (US regulation tends to be highly specific). But makes it much harder to people skirt the intent of the law, because the intent is written into the law and used as the benchmark to determine compliance. This approach does require a transition process so businesses and regulators can figure out how to meet the intent of law in their specific situation, and create implement guidelines. But over the long term produces more flexible law that adapts to technical and social change better.
- Vinnl 5y agoDoes anyone know what the ramifications are for other EU countries, legally? They get the fine because they've broken French law, but that French law (I think?) exists as an implementation of EU law. If they now update their dialogs in France but not in, say, the Netherlands, can a Dutch court/data protection agency refer to this decision?
- codeptualize 5y ago(Disclaimer I'm not an expert) Afaik the different data protection agencies cooperate, meaning they can join in, and compliance means compliance in the whole union. See: https://gdpr-info.eu/art-60-gdpr/ https://gdpr-info.eu/art-60-gdpr/ Point 10: "...the controller or processor shall take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union". But I'm not a lawyer so I might be understanding that wrongly.
- richardwhiuk 5y agoEU regulations (such as GDPR) are implemented by nations passing/updating their own laws.
- detaro 5y agoNo. Regulations are directly applying law (they regulate things). Directives are implemented by member state law (they direct member state law towards a common goal)
- Vinnl 5y agoI did not know that this distinction was between regulations and directives, thanks for sharing. Assuming this is the result of GDPR, the R being "regulation", then it seems that this automatically holds in the entire EU.
- codeptualize 5y agoThis is great, hopefully we can finally get past the puzzle solving to refuse the cookies.
- pulse7 5y agoI am so happy about this, because those companies are not respecting the local laws! Now others will also switch to "symetric options" because of fear...
- codeptualize 5y agoIt's great! It has surprised me for while that companies just didn't do it, it's quite well known. One thing I'm slightly worried about is that they are not going to do the symmetric "accept"/"decline" all but actually make you click 3-4 times and accept/decline each cookie category (similar to how you have to refuse the google one currently atm), that would be properly annoying. But let's hope not! This will certainly improve the situation.
- MichaelRazum 5y agoMost people are celebrating it here. BUT are google, facebook and co the only companies that get punished for this? Seems really weird to be honest if true. How about French companies?
- finikytou 5y agosurely u not one of the guys who blamed trumpists for telling how clinton was corrupt?
- MichaelRazum 5y agoHow is it related? I think this is a very bad comment that is not related to the topic.
- costent 5y agoThey are punishing French companies. Carrefour got a spicy +3M€ fine in November 2020. You can find a non-exhaustive list here (FR) > https://www.nextinpact.com/recherche;q=cnil%20amende https://www.nextinpact.com/recherche;q=cnil%20amende Also, GDPR applies as long as the company runs a business in EU. It doesn't matter where the company is originally from. They will be more than happy to fine the french entity if it made sens. Instead, they fine the Irish entity that performs social dumping. Not bad.
- ErikCorry 5y agoSo Carrefour got a fine that was only 2% of Google's fine. Carrefour has revenue of 80bn/year (Google has 68bn/year in Europe). Very spicy indeed. "The complainants argued that Carrefour (1) did not comply with their data access or erasure requests; (2) sent them direct marketing communications despite the fact that the complainants had objected to receiving those communications; or (3) in one case, did not allow the complainant to unsubscribe to marketing emails." This all seems a lot worse to me than making one button harder to press than the other.
- kovac 5y agoNot sure if it's me, but I feel like Stack Overflow has also started going mad with cookie acceptance requests lately with the default option is set to accept all cookies. It's fucking annoying.
- collinglass 5y agoNot enough to make them change anything. Business as usual.
- isbvhodnvemrwvn 5y agoI'd assume that if they don't change these popups they will get punished much more severely in the future - there is a figure of €100k/day mentioned.
- resonious 5y agoI love to see tech giants get fined as much as the next guy but I find these cookie laws a bit ridiculous. A better browser could just make cookies more visible. I should be able to configure what kind of cookies I save or don't. Oh wait, I can. It just takes an extension. Anyway the cookie banners are a nuisance. Every site has their own banner but they all do the same thing. And I can do that thing by myself in the browser.
- dijit 5y agoI remember in the 90s where cookies were not enabled on a site by default. It would be nice to go back to that, but I strongly suspect that Google has no incentive to do that.
- calltrak 5y agoI think Google has got too big for its own good. I like to use a Google alternative https://fabform.io/a/alternative-search-engines https://fabform.io/a/alternative-search-engines
- gundmc 5y agoYou didn't disclose this is your own website and you have been pasting this link in every single comment you make.
- jurassic 5y agoThe commenters here seem to take for granted that this cookie law is a good thing and Google/Facebook are evil villains, but there is a difference between a law and a good/just/reasonable law. I would argue interrupting the experience and wasting billions of peoples time clicking on cookie banners is also a form of harm. That’s certainly been my perception as an end user under this policy. I don’t work in ad tech and have no financial stake in this, I’m just sick to death of these fucking cookie popups.
- sofixa 5y agoBut the law isn't about cookies, it's about tracking and making sure you, the user, know you are being tracked. The poor UX is malicious compliance and seems to be working since so many people complaining about cookie banners and the law but not companies tracking you, the actual bad guys.
- baby 5y agoIt doesn’t matter what the law is about, what matters are the actual consequences and the impact that the law has had. So far it has had quite a negative impact for users. I really don’t see how this was a win for anyone.
- pull_my_finger 5y agoI wonder if you're playing Devil's advocate or you really are defending this.. They could skip the "burden" users face by just not using so many dang tracking cookies. If you want information about how your customers use the site, or what their interests are, you can just _ask_ and try to solicit feedback explicitly. Most of the people will likely decline, but that _should be_ their choice to do so. And providing feedback _should be_ opt-in, not opt-OUT.
- dmitriid 5y agoThe law: exists, and is quite unequivocal. Sites: implement things that are actually illegal under the law HN, en masse: the law is bad, how can you say it's good? EU has been very slow in going after websites, but I do hope they pick up the pace.
- cityzen 5y agounfortunately fines are just cost of doing business for scumbags like this.
- hiptobecubic 5y agoAll the complaining in this thread about the lack of accountability on the party of devs building this stuff are really missing the point. If it's not "meaningfully illegal" to do this, people will continue doing it. We already know it's extremely effective. These fines are pitifully small compared to the usual investment required to see the improvements to metrics that dark patterns bring. You don't see engineering firms ignoring safety regulations because they know the repercussions will destroy their business. Before that was the case (and in places where it still isn't the case) you see it all the time. Expecting some random line-worker to stand up against changes that bring in this kind of money for the firm is just delusional.
- domador 5y agoAside from the main topic in this article, I'm interested in knowing why the CNIL would have jurisdiction over Google and Facebook. I'm assuming that Google and Facebook have local offices incorporated in France, but is that the reason why?
- anticristi 5y agoGDPR explicitly gives extraterritorial jurisdiction: https://en.m.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.m.wikipedia.org/wiki/General_Data_Protection_Regu...
- mikotodomo 5y agoWTF can anyone just make their own country and sue every company for millions?
- tr33house 5y agoAt times I wonder if the EU decided that fines were the way to get a portion of the pie of all the American tech giants. They seem to be very effective at transferring the wealth periodically