9 ms·
At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interes
by terminalbraid 2y ago
At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations.
Interesting timing with the digital sovereignty movement.
- diggan 2y ago> do away with the worthless cookie banners requirement Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. > cut some generous but reasonable slack to small organizations Some more slack you mean, since they already have a lot of slack compared to larger organizations? What exactly is so cumbersome for a small business to comply with? They're generally "common sense" requirements, and most organizations who already take care of their data basically had to do nothing to be compliant. What are you doing that is so complicated or essential that it's hard to comply, as a SME?
- volemo 2y ago> Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. Companies will never "understand the regulation correctly" because it's not in their interests. That is why the regulation should be bulletproof: as concise as possible while forcing the exact behaviour regulators intend.
- diggan 2y ago> possible while forcing the exact behaviour regulators intend That's what I'm seeing happened? 1. Companies store personal data willy nilly 2. Regulators create directives that force companies to stop doing that, or at least be upfront about it 3. Companies who still want to do it, are at least up front about it, telling users what is happening 4. Users now complain about regulators that companies are letting them know, missing the fact that the only companies who are adding those banners, are companies who are hellbent on doing these things anyways. The blame seems misdirected to me.
- deleted 2y ago[deleted]
- thomastjeffery 2y agoCookie banners are not a requirement in the first place. They are a convention set by giant risk-averse consequence-free tech companies, and followed by everyone else.
- phh 2y ago> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy would probably be max 10 lines) > cut some generous but reasonable slack to small organizations. I can't say for other countries, but in France there is already already a lot of slack even for bigger organizations. We have mainstream websites that are obviously violating the GDPR (most visited cooking site, most visited tv content provider, not allowing free choice of refusing tracking)
- snowwrestler 2y agoYou are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.
- davedx 2y agoNo. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?
- otherme123 2y agoHow do you interpret this about strictly necessary cookies, from gdpr.eu? > While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.
- llm_nerd 2y agoShould is aspirational language, and is not legally binding or even coercing. It's like an encouraged practice. Cookie banners where sites have to say "we're sharing your details with 287 partners" are okay because they should be shameful for the industry. Cookie banners where you're explaining basic technologies of the web -- "we store a cookie to create a stateful session with your browser" -- are obnoxious noise that do only harm.
- jajko 2y agoNope and nope, same rules are for all. You want to steal private data, you will be labeled. If it comes from libs, maybe don't use shitty private data stealing libs? Move fast and break things - fuck that, anybody smart enough can project to what sort of society it leads down the road.
- arrty88 2y ago> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again
- rekoil 2y agoThe plug-in is called Consent-o-Matic and was built by students at Aarhus University, Denmark. You can read more about it and how to set it up here: https://consentomatic.au.dk/ https://consentomatic.au.dk/
- Epa095 2y agoCan it auto-reject them?
- worldsayshi 2y ago> Consent-O-Matic is a browser extension that recognizes CMP (Consent Management Provider) pop-ups that have become ubiquitous on the web and automatically fills them out based on your preferences – even if you meet a dark pattern design. Sometimes a website might not use standard categories, and in that case, Consent-O-Matic will always try to submit the most privacy preserving settings. https://consentomatic.au.dk/ https://consentomatic.au.dk/ So sounds like that should be somewhat supported.
- rekoil 2y agoIt can.
- Muromec 2y agoactually, you don't need to actively reject, it's the operator which has to obtain active informed consent, so default option is "no consent given"
- abdullahkhalids 2y agoI have a Firefox extension that deletes all cookies after I close all tabs related to a site.
- 2y ago
- DarkWiiPlayer 2y agoThe cookie banners are largely a cargo cult and don't have to be nearly as annoying as they are. Websites just love to say "we have to do this" rather than improve their UX because the latter just means more work while the former gets people to be wrongfully upset at GDPR.
- daveguy 2y agoI think cookie banners are a not-so-subtle sabotage of the GDPR. The more annoyance they can associate with GDPR the more the customers will want to water it down. And bonus, it's completely deniable.
- ryandrake 2y agoAnd it's largely working. Even on a site like HN where you'd expect people to be educated about this stuff, we have people claiming that GDPR (and not their own data collection practices) forces them to pop up a cookie banner.
- snackbroken 2y agoOn a site like HN you'd expect a significant proportion of people to be willfully ignorant and/or make excuses about this stuff because it helps them sleep at night. I have been suspecting for a while that the "consent" escape hatch was a concession to get GDPR past the advertising industry's army of lobbyists. Making the problem in-your-face-visible is hopefully only the first step in garnering support from the public. It's much easier for a politician to point to all the obnoxious pop-ups and say "look at this despicable behavior! These companies choose to nag you at every opportunity because abusing your privacy makes them a couple cents. They should just not be allowed to do that."
- DarkWiiPlayer 2y agoNah, next step would be to pull the UX noose tighter and tighter, limiting things like number of clicks to reject non-essential cookies, restricting data loss (like if you already filled in some form data, etc.), maybe even limiting how much of the screen they're allowed to take until the user clicks on "read more" or whatever, etc. I don't think this is necessarily going to happen, but that would be the reasonable next step from where we are now: boiling the advertiser frog slowly and with changes that users would consider uncontroversially positive.
- e2le 2y ago>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. It doesn't help the situation that a large number of sites seem to maliciously comply with these regulations. [0]: https://gdpr.eu/cookies/ https://gdpr.eu/cookies/
- ApolloFortyNine 2y agoIf your salary would drop 95% tomorrow if you didn't tell everyone at the office 'I may remember this conversation' every time you see them, what would you do? Non targeted ads pay 90+% less than targeted. Sure it's not 'required', but the vast majority of businesses would fail overnight if their revenue dropped 90%.
- p_l 2y agoThey should consider that it's playing against fines of up to 20m EUR or 4% turnover (not income)
- ivan_gammel 2y agoIf you heavily rely on performance marketing, your business model is anyway in trouble. In the past businesses survived with non-digital marketing channels just fine.
- Muromec 2y ago>Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. So if I use telemetry to catch some dirty frontend blob throwing a hissy fit of an exception and that telemetry is tracking sessions rather than individual events (hello ms app insights) -- is that functional or, statistics or etc?
- 2y ago
- Hojojo 2y agoI don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.
- ivan_gammel 2y agoThey should not be careless, but they can be spared some paperwork as long as they stay compliant with the spirit of regulation.
- diggan 2y agoIf you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.
- Hojojo 2y agoThis pretty much. I've had a lot to do with GDPR in the projects I'm involved with. It's largely trivial if you aren't already doing terribly risky things, in which case yeah, it's a pain, but it doesn't change the necessity of fixing issues that put user private data at risk (with or without the GDPR existing). GDPR just puts more incentive on solving issues in regards to privacy instead of just letting companies shrug and move on because it's not their problem if data is stolen or leaked or letting them do what they want with the data without permission.
- ivan_gammel 2y ago>If you're careful about how you store personal data in the first place Unfortunately this is a really big "if" looking at typical businesses. They have no idea about how compliance should work and they also hire barely qualified people to marketing teams (often interns), who may accidentally add some privacy-breaking stuff. To prevent that they hire an external DPO and then deal with the paperwork for that DPO, who never visits the company onsite and never meets real people touching privacy topics. So no, it's not a breeze, because there's generally no enough expertise and temptation to use American non-compliant MarTech is high. One possible solution to that could be a pan-European registry of data processors with enough metadata to a) generate privacy policy, b) request correct consent, c) provide a compliance implementation checklist for non-trivial cases. There could be a small fee for adding services to this registry, but that would make maintaining compliance much easier.
- ta1243 2y agoThere is no such requirement, unless you want to steal peoples data or track them, and why would you want to do that?
- bad_user 2y agoThe cookie banners aren't worthless. The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). As an EU citizen, I'm not concerned about your need to observe my behaviour or to prevent ad-click fraud. What I care about is websites sharing my navigation history with Google or the rest of the advertising industry, so yes, I'd like to be informed of it. Personally, instead of having banners, I'd just ban the practices altogether (e.g., targeted advertising, 3rd party analytics), which would certainly simplify business.
- tzs 2y ago> The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). There's quite a lot between "engaged in spyware shit" and "service that the user expects". For example if I want to add first party analytics to my site, the data from which I will use solely internally to try to figure out what pages people like and which they do not like, it is not "spyware shit" if I explain what I'll be using the data for and get permission from the user--and getting that permission needs a cookie banner.
- Gud 2y agoAre cookie banners really a requirement in that case? I think as long as you don’t share the data with a third party you’re in the clear?
- schnubbidubb 2y agoMatomo for example has an explanation how to gather data without having to display a banner: https://matomo.org/faq/new-to-piwik/how-do-i-use-matomo-analytics-without-consent-or-cookie-banner/ https://matomo.org/faq/new-to-piwik/how-do-i-use-matomo-anal...
- 2y ago
- pabs3 2y agoBrowsers should be the things handling cookies, not websites.
- kuschku 2y agoThe law doesn't care whether the tracking happens via cookies, localstorage, fingerprinting, or a private investigator looking through your window. All require approval that is just as easy to deny as it is to accept. The browser may be able to block cookies, but that's not a solution for the other options.
- youngtaff 2y agoNot so sure they can be trusted to have the users interests at heart e.g Chrome and 3rd parties cookies, Topics/Fledge
- milesrout 2y agoThey already are.
- pabs3 2y agoThey definitely aren't cookie opt-in popups in any browser. Nor is there coarse-grained cookie management, like what websites implement. Nor fine-grained cookie management, like they should have.
- milesrout 2y agoBe the change you want to see in the world. It is supposed to be a user agent. Instead of imposing this cost on everyone else, if you think it is important to be able to have fine grained control over cookies, make it happen. Advantages: 1. A single UI in each browser instead of a different one on each website 2. The functionality would be built and maintained by someone with allied rather than adverse interests to the user. Also you can disable cookies quite easily and whether your UI supports it or not is totally irrelevant anyway. If you use a web browser that sends cookies to websites then that you have authorised it to do so is your responsibility. Use a different browser or don't use one if you don't like it.
- phkahler 2y ago>> a) do away with the worthless cookie banners requirement My understanding is that if your site doesn't use cookies, you don't even need that. Don't use cookies, don't collect or share personal data, and GDPR is complied with. Apparently from TFA it sounds like even then you have a lot of proving it to the government, and that's a hassle.
- awiesenhofer 2y ago> do away with the worthless cookie banners requirement They wont, since they were never "required" nor are they part of the GDPR > cut some generous but reasonable slack to small organizations They will, thats the whole reason they are changing it!
- kuba-orlik 2y agoThe GDPR does not enforce the use of cookie banners. Cookie banners is an IAB idea. My suspicion is that they were created to make people angry at GDPR, but they have nothing to do with GDPR. On most website that I've analyzed (and it's quite a lot - into hundreds), you can remove the cookie banner and the website would be just as GDPR (in)compliant as with the cookie banner.