4 ms·
> These notifications are incredibly annoying but have become necessary to do business online to comply with data protection regulations like GDPR. Alternative
by DitheringIdiot 4y ago
> These notifications are incredibly annoying but have become necessary to do business online to comply with data protection regulations like GDPR.
Alternatively, you can just not track the behaviour of every person who lands on your website.
Use contextual ads instead of personalised ads.
- TEP_Kim_Il_Sung 4y agoPersonalized ads never seemed workable, nor sensible to me, especially when showing me products I had just bought. It makes more sense if they are about tracking and influencing behaviour, as is done in Chy-nah.
- rrwo 4y ago> Alternatively, you can just not track the behaviour of every person who lands on your website. Tracking behaviour is useful to ensure the site is working, that people are able to use the site and make purchases, or even to know what parts of the site people are using. There is nothing wrong with that, so long as the logs are not shared and not kept for longer than necessary. Tracking people's use of the site to build a profile of them and share with third parties, without consent, is where the privacy problem comes from.
- SahAssar 4y ago"Tracking" that is necessary to ensure the service is functioning does not require consent. That is for example why logging IPs for things like rate-limiting or DDoS protection does not require consent, but that data cannot be used for anything else. If you do not track users but just track usage that should not require consent. So if you track for example purchases per hour (but not which users made a purchase) you can see if it becomes irregular. You can also track usage of certain site functions without tying that data to a specific user or session. So the actually necessary tracking does not require consent, but since companies got used to tracking everything and tying it to users/sessions before these laws it seems like they try to continue on that path instead of adapting.
- denton-scratch 4y ago> So if you track for example purchases per hour (but not which users made a purchase) you can see if it becomes irregular. Yeah, nice for you! But you're requiring my collaboration in your investigations; sorry, but I can't tell which cookies (or web-storage blocks) are for checking whether my behaviour is "irregular", and which are intrusive data-collectors. I'm not going to scrutinise every cookie a site serves; life's too short. I configure my browser to accept first-party session-cookies only. My web-storage pool is zero bytes. If your site doesn't work with those settings, your site is broken (and I'll find a better one).
- SahAssar 4y agoI think you misunderstand my point. The "tracking" I mentioned is only "actions per {time unit}", for all users. Basically aggregating how many times the "/api/checkout" endpoint is hit. It requires no cookies, it requires no checking of any individuals behavior. The only point of it is if action $FOO decreases dramatically then $FOO might be broken. At no point does that require cookies or personal data or personal tracking. My point was that you don't need cookies or personally identifiable info to be able to make sure a website runs well.
- denton-scratch 4y agoI think I did misunderstand your point, by about 180deg. Sorry. Thank you for clarifying.
- denton-scratch 4y ago> Tracking behaviour is useful to ensure the site is working If that's the only way you can tell the site is working, then something's obviously wrong. > There is nothing wrong with that Indeed, there's nothing wrong with that, except that I'm not OK with cookies that are served by third-parties, or by some framework or analytics script that you've thrown onto the site.
- rrwo 4y agoYou need logs of some form to know what users did, or tried to do. I'm not talking about 3rd party analytics.
- denton-scratch 4y agoAnd I'm not talking about logs. Logs are fine and necessary; I'm a sysadmin.
- gnyman 4y agoYep, I paused at that also. Quite hypocritical of them to state they are "legally required" when the prompt they display isn't in compliance. The European Data Privacy Board (EDPB) has been very clear that the choice to opt out must be as easy as to opt in. Yes/No, not Yes/More Info. But due to lax enforcement companies just keep ignoring this. Luckily it's (very) slowly changing. Even Google was recently forced to amend their practices but it took a fine of 150 million, and probably a threat of a lot more for them to finally do it. https://www.cnil.fr/en/cookies-google-fined-150-million-euros https://www.cnil.fr/en/cookies-google-fined-150-million-euro... If anyone is interested, NOYB is doing good work to make sure companies are aware that they are breaching the GDPR, which is also very useful when it finally comes to enforcing it as they can't pretend they didn't know. If you like their work you can become a member to support them. https://noyb.eu/en/noyb-aims-end-cookie-banner-terror-and-issues-more-500-gdpr-complaints https://noyb.eu/en/noyb-aims-end-cookie-banner-terror-and-is...