8 ms·
GDPR does not allow you to store dark/light mode inside local storage
- nequo 4y ago> GDPR does not allow you to store dark/light mode inside local storage Important addendum to the title: without your consent. That makes sense. Information in your local storage that the website can access can be used to identify and track you.
- CodesInChaos 4y agoI am skeptical that the rules are quite that strict, as long as you don't use them for any other purpose (in particular fingerprinting). Limiting the lifetime of the stored preference (e.g. by using `sessionStorage` instead of persistent `localStorage`) and never sending it to the server should help as well when arguing that storing this was necessary for what the user requested. Unfortunately there is no session-cookie equivalent for the `Storage` API. `sessionStorage` doesn't carry over to other tabs, and `localStorage` is persistent without the option to set an expiry date.
- thinking4real 4y agoHave any published studies come out showing what positive effects GDPR provides?
- jusssi 4y agoI don't have a published study. But, when some fool calls me on phone and tries to sell me something, I can ask them to remove my phone number from their list. And it actually happens, they won't call again. Pre GDPR they were like "yeah sure dude" and just kept calling every month or so.
- entropyie 4y agoI don't buy this. The whole point of the GDPR is to protect consumers from companies processing their data. If the dark-mode toggle data is only ever used locally, then the data is never "processed" by the company. At most this is a bad transcription of GDPR into German law.
- jdlshore 4y agoSomething doesn't smell right here. IANAL, but my understanding as someone who's read the entire text of the GDPR is that it regulates personally identifiable data, not cookies/local storage. The OP seems to be conflating the GDPR with §25(1) of the German Telemedia act, and it does indeed have a prohibition against using local storage. But it also says that local storage is allowed if it "is absolutely necessary so that the provider of a telemedia service can provide a telemedia service expressly requested by the user." (machine translated) So it's not the GDPR that's at issue, it's a particular German law, and that law appears to have a carve-out that specifically applies to the feature under discussion. Dark mode is a service that's (presumably) expressly requested by the user. Contact your own lawyer if you're concerned, but this seems like unnecessary hysteria to me.
- mytailorisrich 4y agoThis is not personal information (so not a GDPR matter) but a 'functional cookie' required to provide the functionality requested by the user So IMHO, and IANAL, this does not require consent and should simply be explained in your privacy/cookie policy. Lastly, depending on the implementation this piece of data may very well never leave the user's machine and thus may not even be known by the server.
- d1sxeyes 4y agoAlso not a lawyer, but I think it would technically count as personal information because it's a preference. Even if it's to provide functionality requested by the user, it would still be necessary to inform the user that this preference is being stored, etc. However, I agree to your second point, that asking the user's browser to store the information, and then have the browser make decisions based on that without anything being shared back probably does not violate GDPR as it wouldn't count as 'processing'. It would seem (although, without a deep dive into the codebase, I can't be 100% sure) that the tool just adds a class to the body: https://github.com/themesberg/flowbite-react/blob/765fedb3c966ea93e384339f6e121beda320c22f/src/lib/components/Flowbite/Flowbite.tsx#L34 https://github.com/themesberg/flowbite-react/blob/765fedb3c9... If this is the case, I think it unlikely that this would be found to be a GDPR violation as Flowbite (or the company which has deployed Flowbite) would not normally be able to detect this preference. It would be different if for example the preference caused a different stylesheet to be downloaded, which could then be combined with server logs, but overall, it seems as though all of the processing of the data (whether you consider it personal or not) is done entirely on the user's computer, and there would be no processing of any data by the company which has deployed Flowbite, therefore it would not open up any GDPR liability. Once again though, IANAL.
- mytailorisrich 4y agoA preference is not personal data in itself. It must be linked to an identified or identifiable person in order to be so. So in itself the functionality and storage of necessary flag falls outside of the GDPR. Now, if for instance the flag is stored in the identified user's account then it becomes personal data but I think consent still isn't strictly required on the basis of legitimate interest (and frankly this is only a freaking flag for dark mode so about zero impact on privacy or anything else).