3 ms·
Not sure why we should want to make companies less responsible in the first place. Anyway, as I said earlier, GDPR does not imposes burdens specifically on web
by cccbbbaaa 4y ago
Not sure why we should want to make companies less responsible in the first place. Anyway, as I said earlier, GDPR does not imposes burdens specifically on websites, but on any kind of PII processing. It is not the place to add provisions specifically for web browsers. I understand that the next ePrivacy regulation wants to make it more user friendly, but negotiations for this bill have stalled for years.
- xp84 4y agoI don't want companies to be less responsible. I just think it's a fool's errand to ever expect every single webstore that runs a Shopify shop to understand how to add their 38 different adtech "tags" in a way that truly ensures that cookie consent is captured, stored, and conveyed to each entity that could come into contact with that data. But by regulating browser vendors, they could have made it so that it doesn't matter what cookies they sent you. If the user hadn't consented in a browser UI, the browser would forget the cookies. Easy to verify compliance. It's just like the ol' pathetic "Do Not Track" header. Same flaw. Asking "please don't give me a cookie that I'll have to keep and send back to you anytime you see me" instead of saying nothing, and just dropping the cookies you don't need on the ground.
- tjoff 4y agoThere seems to be some serious misunderstanding here. For one, why do you think this is about cookies at all? This is not something that can be solved client-side other than obfuscation etc. They can track you with other means than cookies. Even worse, you might have an account on their site. Having an account and using the site (and logged in) makes it trivial to follow you, but that does not give them the right to abuse that information for other purposes. You might have an unique IP and can't reasonably expect to do anything about it. GDPR covers all of that. "Just delete your cookies/session" is not relevant.
- python999 3y agoGDPR requires you to request consent for any cookies the “could” be used to identify you, which makes them personal information. So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner. You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
- cccbbbaaa 3y ago> GDPR requires you to request consent for any cookies the “could” be used to identify you, which makes them personal information. > So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner. Wrong. The ePrivacy directive has an exception for strictly necessary cookies (Article 5.3), which is applicable for user sessions. The ePrivacy directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Search for “strictly necessary”. More details in this opinion from WP29, see section 3.2: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio... > You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie. Are you able to identify someone from the fingerprint of their browser? Then the fingerprint is PII. Consent (or any other legal basis from GDPR Article 6) is therefore required if the exemption from the ePrivacy directive is not applicable. GDPR Article 6: https://www.privacy-regulation.eu/en/6.htm https://www.privacy-regulation.eu/en/6.htm