5 ms·
If someone doesn't accept cookies, how exactly would a site remember that the person did not accept cookies?
by Raqbit 5y ago
If someone doesn't accept cookies, how exactly would a site remember that the person did not accept cookies?
- EtienneK 5y agoIANAL: Essential cookies (cookies that are needed for the correct working of the website) do not require consent.
- sgt 5y agoA lot of people don't know that, and default to annoying cookie popups regardless. How do we create awareness around that?
- OJFord 5y agoPunish bad pop-ups, so people are wary of them ('wait is this bad') and discover (and find attractive) the possibility of not having one (can't be fined for a bad thing that doesn't exist) & network effects ('wait how do they have no pop-up')?
- Nextgrid 5y agoA lot of people's salaries depend on pretending to not know that. Slight difference! ;)
- undecisive 5y agoA lot of this depends on personal definition. If the site allows you to visit it, is it working incorrectly? If a site works correctly, but would work even better with a cookie, is that cookie essential? Obviously this isn't the way the lawmakers intended the law to be interpreted, but it is probably considered a valid interpretation of the law.
- Cthulhu_ 5y agoIt's not about cookies. The legislation and the consent popups are not about cookies. They're not even about whether they're essential. The banners are there for you to opt-in to your activity on the website and beyond to be tracked by a 3rd party, possibly across multiple other websites. We do not need to discuss whether a cookie is essential, because it's a red herring. It's not about cookies, it's about behavioural tracking, it's about your browser activity being sent to 3rd parties, being collated and used to e.g. serve you advertisements to sell you shit.
- undecisive 5y agoThat's what I'm saying. I recognise that's not what the law was intended to do. The problem is that individuals and small businesses would rather interpret the law in a way that isn't going to get them in trouble, even if it is over-reaching. There has been a level of paranoia stirred up, caused by other companies interpreting the law badly. It's like staying away from all bodies of water because someone sometime drowned while swimming in the sea. It's a vast overreaction, but it works. In short, we have lots of armchair lawyers giving idiot-in-a-hurry interpretations, and everyone is doing it wrong because everyone is scared of doing it wrong. It doesn't matter what the banners were intended for.
- EtienneK 5y agoIt's not that simple though. Even though I agree with you that it is not JUST about cookies, the legislation and guidelines do go into some cookie specific details such as when you can use session cookies vs. long lived cookies as an example.
- gkbrk 5y agoYou don't need to store an identifying cookie to remember someone clicked "no" on a popup. Storing a cookie or localstore that says "cookiePrompt = rejected" should be sufficient.
- flipbrad 5y agoThe rules in question apply to any storage of information to, or reading of information from, an Internet-connected device. It doesn't have to be "identifying" information. Edit: I'm amazed this comment is being downvoted. Go read the CJEU's ruling in the Planet49 case if you disagree with me!
- rndgermandude 5y agoThe Planet49 case has not much at all to do with that. They were using tracking cookies that they also shared with third-parties, i.e. "non-essential cookies, i.e. not was OP suggested, and they were using a pre-checked checkbox for consent. The CJEU (and German BGH) decided that having such an "opt-out" does not constitute active consent. PS: You might be misinterpreting that what the court said about "personal data" (aka Question 2). The crucial bit here is this >That interpretation is borne out by recital 24 of Directive 2002/58, according to which any information stored in the terminal equipment of users of electronic communications networks are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. That protection applies to any information stored in such terminal equipment, regardless of whether or not it is personal data, and is intended, in particular, as is clear from that recital, to protect users from the risk that hidden identifiers and other similar devices enter those users’ terminal equipment without their knowledge. This just means that cookies containing personal data and cookies containing no personal data have to be handled the same. This still means essential cookies are still fine. It just means there is no difference between putting some static text, random string (which could be an identifier), or the users home address (personal data) in a cookie. Planet49 tried to claim that their tracking ids were not personal data and therefore they do not need any consent, and they failed, that's all.
- 5y ago
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- flipbrad 5y agoAt least under UK/EU law, you could likely justify such a cookie under exemptions allowing nonconsensual cookies - that's explicitly stated in the French regulator's guidance, for example.
- scrollaway 5y ago“Cookie dialogs” are supposed to be about trackers of all sorts (not just cookies); there to ask for permission to store non-essential trackers in general. We need to stop calling them cookie pop ups as that’s a misnomer. You can use cookies. You can store site state, login sessions, shopping carts and much more without asking at all. They are tracking consent popups.
- Mulpze15 5y agoIs this true? 1- If I count page views on my site, no consent necessary. 2- If I count sessions on my site, no consent necessary. 3- If I count page views per sessions on my site, is consent necessary? 4- If I count return visits on my site, consent necessary? 5- if I remember what people bought on my site, consent necessary? Related to 3 and 4, how long is a reasonable cookie expiration? 6- Am I looking at this issue the right way? Thx.
- Cthulhu_ 5y agoThe answer is no, unless you use a 3rd party like Google Analytics, then you need to look closely at legislation and their settings about whether you need to ask your end user for consent. But generally speaking, you do not need a tracking consent banner unless you use tracking, directly or via 3rd parties.
- scrollaway 5y agoI’m not a lawyer, so take this with a grain of salt. But I have implemented gdpr for several companies. First, you do not need consent for anything deemed essential to your site. Furthermore, you kind of get to say what is essential and what isn’t, as long as you can reasonably defend it. For example a shopping cart is certainly essential. Previous purchases, page views, etc all essential. “Page views per session”, most likely not essential (though you can make the argument they are), but if you’re not installing an identifier on the user to track them (for example, they’re signed in and you’re aggregating as such), then you don’t need to ask for consent. If this sounds like there are loopholes that’s because there are loopholes. Concretely, tracking consent dialog are one of the looser parts of gdpr. So what I usually tell clients is: You do not need a consent dialog, unless you use a first or third party analytics library. If you add a third party analytics library (google analytics, Facebook pixel, piwik, plausible, …), [edit: or third party ads, they come with their own tracking], do not load it until you’ve asked for consent. Ask for consent once per account or per logged out device. Give the option to accounts to revoke consent.
- franciscop 5y agoIt's not accepting cookies vs not accepting cookies; it's accepting non-essential (tracking + others) cookies vs rejecting those. While this is an interesting question/argument, I'd argue that adding a cookie to represent that you have rejected all cookies might be considered an acceptable essential cookie, since it's expected you need to reject them all only once. See here for example: https://bombich.com/cookies#essential https://bombich.com/cookies#essential
- teh_klev 5y agoIt's not about remembering a user's cookie options. The point the parent is making is that "Reject All" should be upfront and centre along with "Accept All" so you don't need to then navigate extra layers to refuse cookies. i.e. it's just one click instead of many. However that said the cookie preferences "cookie" can be considered a strictly necessary cookie so that it can be used to remember your cookie choices. This is the UK's Information Commissioner's guidance on such cookies: https://ico.org.uk/for-organisations/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies/how-do-we-comply-with-the-cookie-rules/#comply19 https://ico.org.uk/for-organisations/guide-to-pecr/guidance-...