7 ms·
I am kind of frustrated by the widespread misunderstandings in this thread. Laws are best when they are abstract, so that there is no need for frequent updates
by uniqueuid 2y ago
I am kind of frustrated by the widespread misunderstandings in this thread.
Laws are best when they are abstract, so that there is no need for frequent updates and they adapt to changing realities. The European "cookie law" does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner.
There is no doubt that the goals set by the law are sensible. It is also not evident that losing time over privacy is so horrible. In fact, when designing a law that enhances consumer rights through informed consent, it is inevitable that this imposes additional time spent on thinking, considering and acting.
It's the whole point, folks! You cannot have an informed case-by-case decision without spending time.
- mpeg 2y agoWhat I find funny about the whole thing is that the grand majority of companies with cookie banners are not implementing them correctly, and therefore are still in breach of the law. I see constantly banners on sites that set tracking cookies by default, and delete them if you reject them in the banner (or even worse, not delete them at all!) – this is not compliant as the cookies were set before consent was given Also see banners where there is only a big "OK" button, with no visible option to reject, this is also not compliant!
- weinzierl 2y agoOne way to see it is that it's their way of passive-aggressive protest against a law they don't want. Maybe the aim was never to abide by the law, just to pretend and annoy people enough to draw them on your side.
- dominicrose 2y agoA clear example of passive-aggressive protest was from Google, the removal of links to Google maps from the search results. Instead of providing a choice of multiple map providers, they just completely removed the links. To clarify: I'm in Europe (France).
- dspillett 2y agoOr Apple's childish hissy-fit, deliberately breaking offline app support in response to an edict about app stores.
- dspillett 2y agoI take an even more cynical view: their intent is far from passive. They want the end user to be irritated in the extreme. When users complain they'll say “we have to do this, the law says so, look, everyone else is doing the same thing” in the hope that people will support later action to have the privacy protections wound back.
- ryandrake 2y agoThe message from these antagonistic companies is clearly: "Look at what they made me do to you!" And users (even here in the HN comment section) fall for it. Like a beaten spouse. Yessssssss, it's the evil EU.... Why do they force you to beat me up?
- ragnese 2y agoOh, it's definitely malicious compliance. I have no doubt.
- zelphirkalt 2y agoAnd not to forget: Giving consent and rejecting to give consent must take equal effort, otherwise you are not compliant. This is veeeery easy to do. Literally just place 2 equal buttons next to each other ... Basically, all you need to do is not to spend additional effort to F things up. But surprise surprise! Most companies act as too incapable to implement it correctly. I _wonder_ what the reason could be ...
- sourcecodeplz 2y agoLook at how Google does it for Blogger. There is an OK button and a "Learn more" one. There is no reject. Are you saying they are breaking the law? EU would love nothing more than to levy more fines.
- actionfromafar 2y agoI always assumed they were and are breaking the law.
- MagnumOpus 2y agoThey are breaking the law. But enforcement lies with national agencies (unlike antitrust where the EU commission itself enforces). Most national agencies don’t bother, only the French CNIL had levied penalties - pretty much on every one of the big ad tech companies in the Faamgs, Bytedance and Twitter…
- atoav 2y agoYes. GDPR says on Consent: > The basic requirements for the effectiveness of a valid legal consent are defined in Article 7 and specified further in recital 32 of the GDPR. Consent must be freely given, specific, informed and unambiguous. In order to obtain freely given consent, it must be given on a voluntary basis. The element “free” implies a real choice by the data subject. Any element of inappropriate pressure or influence which could affect the outcome of that choice renders the consent invalid. Pretty clear, isn't it? There have been subsequent rulings stating that not giving a equally styled no/reject option or letting people choose between one yes option and thousand separate no options is already a influence that nullifies consent. Also specific means you can't just tell them you have to use a cookie for technical reasons and use it for tracking later — they might have given you consent for that cookie for the purpose you told them about, not for the purpose of tracking. All kinds of actors try to bend the rules here, while the rules are verh clear.
- eitland 2y ago> EU would love nothing more than to levy more fines. They aren't paying attention then. The market abuse that has allowed Chrome to become as dominant as it is has been a lot worse than what Microsoft did with IE.
- Cthulhu_ 2y agoYou'd think that the $160+ million fine given to Google for incorrectly implementing their consent thingy would be a deterrent, but clearly not. While the OP of this comment chain stated that laws are best if they are abstract, I think in this case the EU should have mandated an implementation as well, for example a browser based consent setting. Can be global, can be per-website. But the (ad)tech companies wouldn't like that, because as it turns out if given a fair choice, the majority of people would not opt-in, and they don't like that. Even though a small percentage of visitors that do opt in would already generate statistically significant results. It's the same with the alternative, e.g. US sites simply not allowing access from the EU. They could just not have tracking. Advertisers could serve non-tracking ads, based on e.g. IP geolocation. But they don't like that because it's not as targeted as before the EU laws.
- jolmg 2y ago> I see constantly banners on sites that set tracking cookies by default, and delete them if you reject them in the banner (or even worse, not delete them at all!) – this is not compliant as the cookies were set before consent was given Depends on what you consider to be "cookies were set". I think it's a valid argument that cookies aren't set until a "Set-Cookie" HTTP header is sent to the server. The banner is just a form to decide whether or not to set the cookies prior to actually doing so. The banner switches aren't the cookies themselves.
- mpeg 2y agoWhat I mean is a lot of sites will add tracking cookies like say through a google analytics tag before the user has actually accepted them. Then, if the user clicks to reject cookies in the banner they remove the tracking cookies etc – but this is not compliant since if the user takes no action they are being tracked by default.
- jolmg 2y agoOh. Then I agree.
- bawolff 2y ago> The European "cookie law" does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner. Would there exist any other method of implementing it that would be substantially different? Its hard to imagine. I suppose they could implement it by not having tracking cookies. I think the ideal situation is that people could just set it as a browser preference and be done with it. Oh wait they already can.
- GJim 2y agoSetting a browser preference is not giving explicit opt-in informed consent to handle my personal data (for that is what this is about) on a case by case basis. That is what the law requires. Blame the unnecessary gathering of personal data (and think about why they want it!), not the 'cookie law'.
- dspillett 2y agoIt is more than about using cookies, despite the regulations being informally called cookie laws, any tracking and storage of PII is covered. > Would there exist any other method of implementing it that would be substantially different? A checkbox or button, anywhere on the page, that you can click to opt-in or ignore to not op-in. Once clicked the site/app has consent to track that consent, so the box can stay ticked (or be moved out of the way entirely as long as a way to retract consent is easily available, perhaps via an obvious link in page footers). Done. Informed consent implemented in a way that doesn't irritate any user (those that care either way, and those that don't care at all). They could even include a short bit of text begging people to opt in because it helps their site/app make more money from advertisers, without going as far as a pop-over or otherwise wasting a large portion of screen space. > Its hard to imagine. For those with very little imagination, perhaps. > … ideal situation is that people … set … a browser preference …. Oh wait they already can. Only with regard to cookies, and perhaps other local storage, which as I stated at the top is not at all the whole matter. And even within those limitations those options are rather ineffective against the experienced stalkers that the advertising industry consists of, because they can and will simply ignore things like DNT and will work around cookie/localstorage/other blocks using various other fingerprinting tricks.
- GJim 2y ago> I am kind of frustrated by the widespread misunderstandings in this thread. SV and the advertising industry thrives on those misunderstandings. Put simply, there is no need for "cookie banners" unless those cookies are being used to track or personally identify me (hello advertisers!), in which case, I need to give my opt-in informed consent to allow this; and so I should. Hardly surprising SV and the advertising industry campaigns against "cookie banners", rather than their own unethical trading in personal data without consent.
- ryandrake 2y agoSilicon Valley in general has a huge problem understanding consent. If the world was a night club, "Silicon Valley" would be that creepy guy who goes up to everyone saying "You're dancing with me now, unless you opt out [Yes | Ask again later]."
- weberer 2y agoI am informed and chose "No" each time. Why do EU lawmakers not allow me to automatically say no? All they have to do is add a line to the law enforcing companies to respect the DNT or GPC header. https://en.wikipedia.org/wiki/Do_Not_Track https://en.wikipedia.org/wiki/Do_Not_Track
- daveoc64 2y agoTracking isn't the only thing that the law covers.
- crote 2y ago> Why do EU lawmakers not allow me to automatically say no? What do you mean? There is no law banning companies from honoring a DNT header, companies just choose not to do so. The law already allows it, it just doesn't mandate it.
- weberer 2y ago>What do you mean? ... The law already allows it, it just doesn't mandate it. That's exactly what I meant by: >All they have to do is add a line to the law enforcing companies to respect the DNT or GPC header.
- sangnoir 2y agoMicrosoft, in its eagerness to hit Google's revenue, universally set DNT on its browser of the day, which muddied the water on informed consent, and gave Google and other trackers an excuse not to respect it, since it wasn't technically the user requesting not to be tracked, but Microsoft.
- deleted 2y ago[deleted]
- pickledoyster 2y agoYes. It's not the regulation but the misguided implementation that's to blame. Sites and cookie banner plugins could just accept DNT signals from browsers and no productivity would be lost.
- randomdata 2y agoDNT does not provide informed consent. It may, if set to not track, imply denial, but the reverse is not true. If DNT is accepting or unset, the site needs to fall back to the banner to get consent. And at that point you may as well prompt everyone with the banner instead of complicating the codebase with extra logic for a DNT edge case.
- ben_w 2y agoMm. For existing privacy options — location, microphone, camera — Safari on iOS has the options of "ask"/"deny"/"allow". I wouldn't be surprised by legislation for a Do Not Track option in DMA designed Gatekeepers' browsers, defaulting to "ask", where all three options must be handled accordingly by websites. "Ask" would also have to be the default behaviour when no preference is transmitted.
- randomdata 2y agoAgain, as the law in question requires informed consent, "allow" and "ask" end up being the same thing. A new DNT law as you propose would contradict the other law of which we speak.
- Ntrails 2y agoInformed generalised denial could be accepted and no cookie banner shown surely? In much the same way no banner is required if no cookie is being set.
- account42 2y agoI doubt there would be any concerns with "complicating the codebase" (really?) if there was a Yes-Track header that gave consent but no negative signal.
- egorfine 2y ago> does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner. Good luck explaining alternative technology to the lawyers and then to the lawyers of the other party in court should the need arise, and then to the judge. While you are technically 100% right, I believe you will have a truly hard time implementing anything other than the cookie banners.
- scotty79 2y ago> Laws are best when they are abstract ... Laws are only as good as their real world consequences.
- zelphirkalt 2y agoThere is a kernel of truth in that, but lets not forget, that laws alone don't have any consequences. It is the willingness to force people to comply with the law, that has the actual consequences. If our judges and governments and forces in general are not willing to pursue violations of the law, then we can have any law we want, it still won't matter. We do need more law enforcement on GDPR! A lot more.
- scotty79 2y ago> laws alone don't have any consequences That's a very weird claim about something that the whole purpose of is to have at least some consequences.
- scotty79 2y ago> You cannot have an informed case-by-case decision without spending time. Forcing me to make an informed decision where I don't care about the result is the one of the major ways of wasting my time. If you wanted to create a good law about this you should make it so I only have to make a case-by-case decision if I care about my privacy (as it's currently exploited) and do nothing if I don't.
- GJim 2y ago> Forcing me to make an informed decision where I don't care about the result The UK and EU have decided _society_ cares, about the dangers due to unregulated sharing of personal data; hence the law requires informed consent to do this. If _you_ don't care, then that is your prerogative.
- dspillett 2y ago> Forcing me to make an informed decision where I don't care The laws do not force that. Informed consent before tracking could be implemented other ways, perhaps even more easily. The companies choose to force you to make the decision, rather than making it something you could choose to click or choose to ignore, because forcing that increases the chance that people who do care will accidentally opt-in and people who don't care will get irritated and (as is evident in places in this thread) incorrectly blame the law. The companies make a point of inconveniencing people like you who don't care, so they can weaponise you against those of us who do. The companies are doing this to you, not the law.
- scotty79 2y agoCompanies want to track me. I want companies to track me. So what's the source of the friction if not law itself or its direct consequences? I think other parties try to force me to care when I don't by introducing all that friction. There's a talk about DNT. What's the reason no browser has "Please do track me and do whatever you wish with the data you manage to gather."? I think it would be quite popular. So it's probably prevented by the law itself.
- 2y ago
- shadowgovt 2y agoWhich is fine, but as an individual I'd just rather auto-click "accept all" and go on with my life. Be nice if that could be done without the button. If I don't want to be informed, there should be a way for me to signal my willingness to participate in uninformed consent.
- brookst 2y agoI partly agree but feel you’ve conflated a few things: - Laws are best when abstract. This is true. Laws work best when they cover a class of behavior, not specific behaviors. - Requiring informed consent is good. This I disagree with with because it is a hard to measure outcome. Abstract, yes, but to the point where nobody knows what it means. The only way to meet this in spirit is to go so far overboard that nobody can ever say you didn’t try hard enough. - Mandating that huge populations spend time to make informed case by case decisions. This is like mandating pi=3. As soon as this became the goal the whole enterprise was doomed. The only way this happens is with notaries and witnesses , which is far too heavy a burden for visiting a website. The whole thing is noble intent, but disproportionate to the problem and not aligned with the putative goals. Regulation can be good, and it should be abstract, but it cannot mandate abstract outcomes. Imagine if speed limit signs said “speed limit: optimized balance of reduced time to destination and net cost of carbon emissions and amortized risk of accidents”
- skydhash 2y agoI’d say the ability to have speed limits is the regulation. How it’s implemented vary depending on the road. Regulations should be abstract so that the implementation can be sensible and adaptive to the context. And everyone knows what “informed consent to tracking”. If you’re building something, you know when you intrude on your users’ privacy. But everyone chose forgiveness instead of permission, and now I throwing a fit when the latter is required.
- close04 2y ago> nobody knows what it means The definition of consent is provided here. [0] There are clear application guidelines. To me it takes being intentionally obtuse or malicious in the interpretation when reading the text to come to the conclusion "I don't know what it means so I'll do the thing that benefits me". Imagine blowing through a stop sign and trying to explain that you don't know what it means, the Earth is moving so you could never really be in compliance. You're not wrong but it's clear that your incompliance doesn't come from a place of honest misunderstanding. > Mandating that huge populations spend time to make informed case by case decisions It's mandating that the user is given the tools to provide informed consent, not that they must use them properly. If you need to know what it means, the text is clear. If not and never needed to read it, it's easy to conclude it's hard, impossible even. [0] https://gdpr.eu/article-4-definitions/#:~:text=%E2%80%98-,consent,-%E2%80%99%20of%20the%20data https://gdpr.eu/article-4-definitions/#:~:text=%E2%80%98-,co...
- ApolloFortyNine 2y ago>Laws are best when they are abstract, so that there is no need for frequent updates and they adapt to changing realities. Couldn't disagree more, people (and even companies) have a right to know if they're breaking the law. Broad laws just make everyone (potentially) guilty. It's ripe for abuse and corruption.
- uniqueuid 2y agoThis is not what I meant. Laws are made concrete and understandable through either case law (harder for citizens to anticipate IMO) or through statutory interpretation in civic law traditions. Both (eventually) offer a clear understanding of the meaning and scope of a law.
- GardenLetter27 2y agoSuch basic functionality as cookies shouldn't need explicit consent. The consent is you navigated to the webpage, if you don't like it you can use a browser that doesn't set cookies.
- vundercind 2y agoTracking people with cookies is the part that requires consent. Setting cookies that aren’t used to track people, doesn’t require consent. The consent is for tracking that happens to use cookies, not for cookies themselves.
- GardenLetter27 2y agoBut you can configure all that client-side anyway. You choose what you save on your computer and send in responses, not the server sending you the HTML. The current situation is absurd, the EU just doesn't understand technology.
- TheCoelacanth 2y agoTracking is not configurable client-side. Blocking cookies is not sufficient to prevent tracking. Is it the EU that doesn't understand technology or you?
- happymellon 2y agoMe navigating to a webpage is far from consent. How do I even know that you want to try and farm my personal data until I go there? Perhaps you should put a click through gateway that states that "proceeding on to this website will sell your personal information to spammy, scummy advertising".
- GardenLetter27 2y agoSetting a cookie isn't farming personal data. You can configure your web browser to only send first-party cookies back and never set others. Or configure a subset of domains. If you're worried about it you should be doing that anyway, since the cookies could be set despite the pop-up (or some websites might ignore the consent pop-up requirement entirely).
- marcosdumay 2y ago> You cannot have an informed case-by-case decision without spending time. No, that's bullshit. Nobody is after case-by-case decisions. People are under DoS attacks from corporations throwing single-sided contracts into them until they make a mistake and accept something. Those boxes are just that, harassment, done in the hope people will pay them to go away.
- GardenLetter27 2y agoBut you're the one saving and sending the cookies anyway - not the website. If you don't want to send some of them, then just configure your client not to do that. It's bizarre that the onus is put on the websites themselves to request consent before requesting that the client sets the cookies.
- TheCoelacanth 2y agoThe law isn't about cookies; it's about tracking regardless of the technical means used to implement it.
- Rattled 2y agoSome of the most intrusive cookie banners I've seen are on EU institutional websites. If they can't find a way to provide access to information without pages of consent boxes what hope have the rest of us. The law came ten years too late and focused on a narrow technical step rather than the privacy goals directly.
- franga2000 2y agoNo user wants informed case-by-case decisions, we want to not be tracked. Making this a question that needs to be explicitly answered was already a bastardisation of the original intent of privacy legislation. A competent legislator would've required a user agent level option (like a more advanced version of DNT) that can be set globally and overriden per site. This could be written vaguely enough to not require patching as technology changes. And even if we wanted case-by-case consent, a standardised format and actually enforced rules against coerced consent would've also been quite easy to do.