4 ms·
> They only need to ask for permission if they want consent for the kind of invasive tracking that the GDPR and related regulations were intended to discourage
by ruthmarx 2y ago
> They only need to ask for permission if they want consent for the kind of invasive tracking that the GDPR and related regulations were intended to discourage anyway.
This is exactly the problem, and exactly why the EU is to blame for those popups.
Instead of outlawing a behavior they had a problem with, they are trying ti discourage it. The way they try to discourage it is why we have all these stupid popups.
- wizzwizz4 2y agoThey did outlaw it. The GDPR's definition of "consent" makes these popups illegal.
- ruthmarx 2y agoThat's not true at all. Most cookie popups are compliant with GDPR - they're still annoying.
- jkaplowitz 2y agoThe vast majority that I see give you an easy button on the first screen to grant consent, but then hide the option to refuse consent on a second screen behind something like "manage preferences". That dark pattern is not compliant with GDPR.
- ruthmarx 2y agoI would say the most I see have accept, reject and manage preferences as buttons, normally with manage preferences being a link rather than a button. The dark pattern you describe isn't on any big business websites for example. Out of curiosity, you mean against the spirit of the GDPR rather than the letter of it, right?
- wizzwizz4 2y agoThe spirit, and the letter too. (It's quite a well-written law.) Article 7, "Conditions for consent": > 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
- jkaplowitz 2y ago> It shall be as easy to withdraw as to give consent. Being as easy to withdraw as to give consent is technically a different thing from being as easy to refuse as to give consent, since consent that is refused was never given in the first place but consent that is withdrawn was previously given. But yeah, courts have been clear that both of these actions must be as easy as giving consent, and both requirements are too often not complied with.
- wizzwizz4 2y agoThe law says that it should be easier to refuse consent than give it. That's thoroughly implied (and then there's Recital 43, if the text of the law isn't clear enough for you).
- jkaplowitz 2y agoWell, true, in the sense that refusing consent is the default.
- ruthmarx 2y agoI don't believe what you quoted supports your point. > It shall be as easy to withdraw as to give consent. It is. You click the reject button.
- jkaplowitz 2y agoSo many sites don't have a reject button immediately parallel to the accept button on the main consent management screen.
- jkaplowitz 2y ago> I would say the most I see have accept, reject and manage preferences as buttons, normally with manage preferences being a link rather than a button. The dark pattern you describe isn't on any big business websites for example. I can accept that our website visiting patterns, and maybe our specific countries of residence within the EU, expose us to different experiences in this regard. I stand by my statement as a description of my own personal experience, but I'm willing to believe your own personal experience too. It's also possible that I've increasingly realized that "reject" allows the companies to get away with illegally misusing the "legitimate interest" basis for data processing, so I've mentally stopped assuming that it means what it says because it often doesn't. See below for more on that. > Out of curiosity, you mean against the spirit of the GDPR rather than the letter of it, right? No, I mean against the letter of it as well. The free, informed consent which the letter of GDPR requires according to public and legally binding official interpretations (such as from the European Court of Justice) is not present when those dark patterns make it harder to refuse consent than to grant it. Similarly, EU courts have been clear that simply wanting to do a bunch of tracking to facilitate more profitable personalized advertising does not legally justify the legitimate interest GDPR processing ground, but so many sites default to allowing processing based on "legitimate interest", including when you click reject for the consent question, for many of the same advertising/tracking partners where the "consent" basis is off by default. They also don't usually have a way to object en masse to these, and it's often tricky to correctly click off every single "legitimate interest" button which is falsely and illegally claimed to be a valid legitimate interest. Plus, I've heard reports that many sites set these cookies even before consent is granted, and/or don't properly respect the refusals of consent and objections to legitimate interest processing. However this is from memory and I don't have stats or evidence to back up this statement. The problem in all of these respects is primarily very weak and reluctant official enforcement of the rules by the relevant Data Protection Authorities and very low fines when they do enforce them. It's more profitable for companies to take the risk on genuine GDPR compliance, beyond some mild public-facing lip service and the lowest-effort bit of engineering they can do to underpin the public-facing lip service.
- ruthmarx 2y ago> I can accept that our website visiting patterns, and maybe our specific countries of residence within the EU, expose us to different experiences in this regard. I stand by my statement as a description of my own personal experience, but I'm willing to believe your own personal experience too. I appreciate your attempting to reconcile different anecdotal experiences. In the spirit of objectivity however, I would insist that big businesses are not breaking the law. > The free, informed consent which the letter of GDPR requires according to public and legally binding official interpretations (such as from the European Court of Justice) is not present when those dark patterns make it harder to refuse consent than to grant it. I think here we've shifted the problem to dark patterns. The problem though is with the popups at all, because even when they are compliant, they are no less annoying, just slightly more clear. > The problem in all of these respects is primarily very weak and reluctant official enforcement of the rules by the relevant Data Protection Authorities and very low fines when they do enforce them. They probably shouldn't have claimed global jurisdiction then. Since that's a big part of what has resulted in so many poorly done cookie banners.