5 ms·
Maybe the cookie tracking whether or not you responded isn’t saved if you reject cookies?
by OkGoDoIt 3y ago
Maybe the cookie tracking whether or not you responded isn’t saved if you reject cookies?
- doublerabbit 3y agoNah. They normally have the default "allow system cookies" which is untickable. What annoys me are the "Legitimate Consent" option on all 9000 cookie vendors. There never seems to be a "No to all" button on those.
- bad_user 3y agoThe IAB consent dialog is the worst, as it makes you consent to the entire advertising industry. Those legitimate interests, however, are bullshit. Just because they claim it, doesn't mean it's true. For instance, a DPA just claimed that Facebook can't claim a legitimate interest for behavioral advertising, so they'll have to ask for consent. Which will be interesting, because they won't be able to refuse service to those that decline.
- swores 3y agoThe "legitimate interest" part of GDPR is just horrifically abused by so many companies, who act like it's a magic two words which allow them to collect personal information without consent because they said "ooooh we really do have a legitimate reason for this data" which is against both the spirit and the wording of the GDPR. I really hope to see a few big cases where the EU fines companies for that, so that everyone else gets the picture and stops hiding behind legitimate fucking interest. But I don't know why that hasn't happened yet, hopefully it's just slow moving rather than a case of the laws implementing GDPR being fuzzy enough that countries are worried they wouldn't win the case in courts. (But if that were the case, hurry up and update the law!) /side note: apologies on behalf of my profession, since it's largely marketing people who've led to these shitty practises. We're not all assholes, some of us do respect people's data, rights, and (lack of-)consent.
- bad_user 3y agoMeta/Facebook was told that they don't have a legitimate interest in behavioral advertising. They'll need to ask for consent: https://thisisunpacked.substack.com/p/the-eu-war-on-behavioral-advertising https://thisisunpacked.substack.com/p/the-eu-war-on-behavior... Meta also broke the record for the biggest fine this year (1.2 billion). The fines are coming, and if they go after the biggest players first (e.g., Meta, Google), it will send shockwaves through the entire industry. When GDPR came into effect, being close to the advertising business then, I know some companies that closed shop in EU. But enforcement has been very moderate, at least in the beginning. There's also the issue that some DPAs are more active than others. On the other hand, it doesn't take a lot to set precedents, and EU countries may find that these fines are a nice way to add to the public budget.
- swores 3y agoA cookie like that doesn't need to contain any personal information and therefore does not need a user's consent to store under GDPR. As a cookie it does need the user to be notified (ePrivacy Directive aka its 2009 "cookies law" update), but that is/can be covered as part of the original request that the user clicks to reject optional cookies. The only reason to forget that a user said no is because it's a hostile interface designed to get users to give in and give their "consent".
- bad_user 3y agoCookies for functionality that's necessary, i.e. expected by the user, are completely legal without any consent or notification. Fact of the matter is, when you see a cookie banner, that's always for spyware shit that the service doesn't really need to serve the user (e.g., analytics, tracking).
- swores 3y ago> Cookies for functionality that's necessary, i.e. expected by the user, are completely legal without any consent or notification. No that is not the case, though it's easy (and common) to mistakenly think that - in part due to the confusing nature of the various regulations and in part due to how frequently companies and websites purposefully misinterpret them for their benefit. Firstly, there are legitimate reasons to ask for consent to store user data that relate to providing a service (eg if the service is storing a user's personal medical records, or many many possible functions within many services). Secondly, even without personal information being used or stored, and therefore no GDPR to worry about nor consent needing to be sought, cookies are a separate matter. A different EU law (the 2009 update of the "ePrivacy Directive") requires EU users be notified of any cookie use - even something as obviously reasonable as providing the functionality of a "keep me logged in" checkbox, if you're doing it with a cookie (edit: or even something equivalent like using fingerprinting on the server side to remember people) you need to notify the user. See, for example, the UK ICO's (the relevant department for dealing with UK's implementation of GDPR, ePrivacy Directive, etc) guidance on it: > This means that if you use cookies you must: > - say what cookies will be set; > - explain what the cookies will do; and > - obtain consent to store cookies on devices. > PECR also applies to ‘similar technologies’ like fingerprinting techniques. Therefore, unless an exemption applies, any use of device fingerprinting requires the provision of clear and comprehensive information as well as the consent of the user or subscriber. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies/what-are-the-rules-on-cookies-and-similar-technologies/#rules1 https://ico.org.uk/for-organisations/direct-marketing-and-pr... A cookie being necessary for actual core functionality does allow skipping over requiring consent, but not skipping the notification part. Which is why 14 years ago, years before GDPR arrived, EU sites all started putting "cookie banners" up, most of which didn't ask for consent and just appeared on the first site visit for each user even if they didn't actively dismiss it, since showing it once was widely considered to count as having notified. Sorry for such a long comment, but the fact that these topics are so widely misunderstood means I think it's important not to make things worse by accidentally spreading misinformation like that in your comment.