5 ms·
There is no EU cookie banner law
- deprecative 3y ago[flagged]
- dantyti 3y agowhat cookie thing are you refering to?
- junon 3y agoSexist?
- dantyti 3y agoThe article does have a quip about how society teaches _boys_ about consent, which does imply that they read the article even though their next sentence re “whole EU cookie thing” seems completely out of place
- BiteCode_dev 3y agoWhat's your system prompt?
- dadoum 3y ago> You'll notice the words "cookie" or "banner" appears nowhere in there. That's because they are not in the law at all. > The only thing that matters is that if an entity wants to track people, they have to let them know in a way that is clear and request their approval The author does say that it's not about cookies either. It's about tracking.
- hsbauauvhabzb 3y agoIs there any really good guides on how to be gdpr compliant as an engineer? I want to know what I need to implement in my software so that should I need to respond to a gdpr request, I can action it as required. Someone else can deal with third party notifications etc, but I want to know how to create a ‘nuke this user’ function, but I don’t even know what data a user can supply for identifying purposes (their name? email address? IP?) nor what data I must destroy (name? email? Ip?)
- apricot13 3y agoI’ve had the exact same gdpr training at two jobs (word for word it didn’t change in 3 years!) and it never ever covers the details, it’s all geared to in-office environments and skips over the fact that some systems might need to have these export tools built for them or that they have export but not all the fields. I have had to use gdpr to get data a few times now and while it’s amazing that we can so easily do that now 30 days is never enough because i can tell that the export is being done manually then converted to pdf. Which means my data is no longer inside the system its in bits and pieces in someone's (usually non technical) downloads/desktop folder which feels way less safe to me!
- deleted 3y ago[deleted]
- Lornedon 3y agoSeems like it would be easy to fix this situation even without changing the law. - Forbid browsers from sending the DNT header automatically. They may ask the user. - Consider the DNT header valid consent or withdrawal of consent. - Forbid websites from asking for consent if the header is set.
- wkat4242 3y agoWhy forbid them from setting it automatically? Tracking is meant to be opt-out. Other than that yes this would be the solution.
- iseletsk 3y agoIt doesn't matter where you are as long as you serve someone in the EU. So, if you are in the USA, but your website is serving cookies / collecting logs for the visitors, and one of your visitors is in the EU, you must comply with GDPR. GDPR also requires explicit consent to collect information such as IP addresses (logs) or tracking cookies. I have seen sites just banning all the EU IPs, but I don't think that would work anymore, as California & India have similar laws. I am sure a bunch of other jurisdictions have it by now, as well.
- ninkendo 3y ago> you must comply with GDPR The EU doesn’t have jurisdiction over American companies, there’s no way to enforce this. If your company has a European legal presence, that legal entity may see enforcement, but if you’re an American site operating under American jurisdiction, the EU cannot compel you to do anything. America is a sovereign nation that is not subject to EU laws.
- orwin 3y agoBear in mind that a case that isn't really clear are advertiser networks who work in the EU. Them collecting EU citizen data w/o explicit permission is illegal, and punishment is enforceable. Candy advertising network push girl the cookie banner?
- SAI_Peregrinus 3y agoThe advertising network is then responsible for getting consent. Not the company using the network with no legal presence in the EU.
- wkat4242 3y agoBut they can't. Because if the user doesn't consent, the advertising network is not allowed to even be involved. And most sites don't just use one tracking network but they use many (see some of the convoluted cookie banners where you have to turn off data sharing with several hundred "partners")