5 ms·
I don’t get it. Why not just set a 24-hour cookie scoped to the path, and every request without the cookie is logged as a “unique visit”. That gives unique vis
by fogzen 3y ago
I don’t get it. Why not just set a 24-hour cookie scoped to the path, and every request without the cookie is logged as a “unique visit”.
That gives unique visits by device within a 24 hour period, per page, with no logging of any ID/IP whatsoever. You can pair this with signup counts or campaign codes to get conversion rate by channel, all without any nonsense “anonymized” user IDs.
- chrismorgan 3y agoePrivacy Directive says you can’t store that cookie without consent (since it’s not in any way essential). More generally: analytics mustn’t rely on storing anything on the user’s device for its functionality; that’s why people head in the direction of fingerprinting.
- fogzen 3y agoI didn’t realize that. That seems pretty stupid. The system I describe doesn’t log any personally identifiable information.
- frereubu 3y agoIn the article they point out that anything that can be used to identify one click and link it to a subsequent click - in your example the cookie - is considered person hall data. This is because you may be able to de-anonymise a person from the pattern of their interactions.
- fogzen 3y agoThe cookie is the same for all users. There is no value unique to each user. All that is logged is “a visit to this page occurred at X time” and if the request contained the cookie then it is marked “unique”. The cookie value is the same for everyone. What should matter is what’s logged. Every request contains an IP that’s how the web works.
- frereubu 3y agoAh yes - I misread your suggestion. Seems feasible in that case.
- ttepasse 3y agoBack in 2012 the EU’s Article 29 Data Protection Working Party* published an rather readable opinion about the different cookie consent exemptions. Yes, first party analytics are not essential. The WP29 even proposed to exempt them in a hypothetical future privacy directive. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio... The WP29 is superseded by the European Data Protection Board and there seem to be proposals for an updated ePrivacy Regulation making their way through the system. Signals are mixed. The proposal by the commission from 2017 mentions the usefulness of analytics cookies as a possible exemption. The EDPB on the other hand gives the opinion that a future ePrivacy Regulation should not lower the level of protection offered by the current ePrivacy Directive and looks not kindly on possible exemptions, but describes an exemption for an audience measurement as “very limited privacy risk for the users”. Interesting. Maybe there is a possibility in the future. https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-privacy-and-electronic-communications https://digital-strategy.ec.europa.eu/en/library/proposal-re... https://edpb.europa.eu/sites/default/files/files/file1/edpb_statement_on_eprivacy_en.pdf https://edpb.europa.eu/sites/default/files/files/file1/edpb_...
- shadowgovt 3y agoThat would require you to now have all users opt-in to cookies on your site where they didn't have to do that before. ... because users absolutely love clicking through those annoying opt-in compliance boxes. So the admin now has the choice of no longer having that data or damaging UX. The law seems pretty clearly bent on just not letting web admins collect that bedrock baby's-first-metric anymore for European users.
- Hitton 3y agoYou can do basically this without cookies with daily random salt (which is not stored longterm) added to the ip + useragent hash mentioned in the article.
- cuu508 3y agoIt's not quite the same though. In the cookie case, you can detect a returning visitor by the presence of the cookie, you do not need to assign an unique identifier. In the hashing case, the hash of the IP and UA counts as PII, at least for the 24 hours while you still have the salt.
- patrakov 3y agoYou can completely, at all, avoid storing PII for the purpose of estimating the number of unique visitors. The answer is to use HyperLogLog (see e.g. https://en.wikipedia.org/wiki/HyperLogLog https://en.wikipedia.org/wiki/HyperLogLog or http://antirez.com/news/75 http://antirez.com/news/75) on a strong fingerprint of the user's device. In this case, only some small amount of aggregate data across all seen fingerprints is stored. NB: this is completely irrelevant except as a mathematical curiosity, because GDPR prohibits any processing of PII (in this case - the fingerprint), not just storing it anywhere, without a legal basis.
- cuu508 3y ago> NB: this is completely irrelevant except as a mathematical curiosity, because GDPR prohibits any processing of PII (in this case - the fingerprint), not just storing it anywhere, without a legal basis. Hmm, but using PII in anonymized form is allowed, right? But how do you anonymize PII without processing it?
- andrewaylett 3y agoBecause that involves storing a cookie, which you're not allowed to do except as necessary to operate the site without first gaining consent. I use Plausible, which works by hashing IP addresses. Honestly, I disagree with the analysis as given: the claim is that we're assigning a unique ID to each user, but it's really not doing that -- the ID changes, and more than one user may have the same ID. GDPR is a balancing act, between the rights of the people involved and the desires of data controllers to have useful data. In practice, Plausible presents (at least to my mind) a solution to my legitimate interests with a privacy impact that's suitably minimal for the level of interest I have in the statistics I collect. A cookie is arguably less privacy-preserving, as it has better specificity.