3 ms·
I'd have one very important addition, as you tend to use the word yourself even if you basically term at pointing out this distinction: The law itself does not
by krsdcbl 3y ago
I'd have one very important addition, as you tend to use the word yourself even if you basically term at pointing out this distinction:
The law itself does not even mention "cookies", afaik.
It aims at regulating ANY kind of detection or storage of PII, regardless of it's technical nature.
"Cookies" are preferred nomenclature partly because non technical users kinda understand what it means, but it's VERY MUCH also part of the very tactics you are writing about: because "do you accept cookies?" is a really really cute obfuscation of "do you consent to us taking your fingerprints and tracking everything you do online?".
That also goes for calling the GDPR the "EU cookie law".
The EU already had a "cookie law" long before GDPR that already mandated informing users about the site's usage of cookies, but it was widely ignored or even unknown to publishers outside of the eu since it: didn't regulate consent & storage, referred to cookies specifically and had thus become easy to kite with modern tracking techniques even if anybody gave a damn, and also didn't impose any kind of substantial sanctions when breached.
The GDPR aimed to fix that and therefore explicitly avoids specifying any technology it should be applied to. It's applicable to cookies, server side tracking, fotos of you or paper forms just the same.