5 ms·
> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very we
by phh 1y ago
> do away with the worthless cookie banners requirement
There is no such requirement. You're free to make a website that doesn't require cookies.
This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one.
(I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy would probably be max 10 lines)
> cut some generous but reasonable slack to small organizations.
I can't say for other countries, but in France there is already already a lot of slack even for bigger organizations. We have mainstream websites that are obviously violating the GDPR (most visited cooking site, most visited tv content provider, not allowing free choice of refusing tracking)
- snowwrestler 1y agoYou are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.
- davedx 1y agoNo. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?
- otherme123 1y agoHow do you interpret this about strictly necessary cookies, from gdpr.eu? > While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.
- llm_nerd 1y agoShould is aspirational language, and is not legally binding or even coercing. It's like an encouraged practice. Cookie banners where sites have to say "we're sharing your details with 287 partners" are okay because they should be shameful for the industry. Cookie banners where you're explaining basic technologies of the web -- "we store a cookie to create a stateful session with your browser" -- are obnoxious noise that do only harm.
- ivan_gammel 1y agoJust put it on the Privacy Policy page on your website, as many websites do.
- ta1243 1y agoSure, you pop all that nonsense on the privacy policy page linked at the bottom of your page, down near that "terms of use" nonsense
- snowwrestler 1y agoThis is correct.
- diggan 1y ago> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.
- snowwrestler 1y agoI spent months implementing GDPR compliance with a set of EU-based lawyers. Most businesses are not actually GDPR compliant, even to this day. I assume this is a big reason the EU is willing to take another look at what is required for compliance.
- diggan 1y agoAnd what exactly is making it complicated? I've also helped a bunch of organization become compliant, some were easier than others. The ones that were harder were the ones that generally didn't have good processes with data in the first place, where everything was scattered all over the place and everyone had access to everything. It makes sense to me that it's harder to be compliant if you were borderline malicious with how you treated personal data before GDPR.
- Zanfa 1y agoFrom my experience, companies taking months to get GDPR are ones that want to tick the box, but don't want to follow the law, so they have to go through the trouble of justifying gathering unnecessary data for themselves and their 873 trusted partners. They usually end up noncompliant anyway because GDPR is a pretty sensibly written law that you can't just work around with a crappy popup, but enforcement has unfortunately been lacking.
- jdlshore 1y agoI think you’re confusing the ePrivacy Directive, which regulates cookies, and the GDPR, which regulates PII.
- schrototo 1y agoThis is simply not correct. You absolutely DO NOT need to obtain consent for strictly necessary first-party session cookies (such as would be used by an online shopping cart, for example, or to maintain a persistent login) [1]. [1] https://gdpr.eu/cookies/ https://gdpr.eu/cookies/
- deleted 1y ago[deleted]
- snowwrestler 1y agoI didn't say "obtain consent," I said serve a cookie banner. If you are only setting essential cookies, the banner can just say "This site is using cookies," with no opt-out or preferences button. But it does need to appear.
- notjustanymike 1y agoConsent for non-essential cookies, like analytics, is required. You must also provide a clear link to your cookie usage policy, and a simple way to opt-out. This notification is not necessary if you only use functional cookies; for example, using a cookie to only show an on-boarding tutorial once is acceptable. Organizations, and typically lawyers, skew conservative and lazy. A little cookie-consent cottage industry popped up to handle GDPR, so instead of worrying about the regulations most companies pay the small monthly service charge for a third party to handle consent. The consent companies built the most compatible solution, a banner, with the most conservative options as default to prevent any legal quandary. Most public facing sites do have analytics (usually LOTS of analytics) and ads, so the banner is mandatory for them. If you understand the regulations, and don't violate them, then consent is not necessary.
- amiga386 1y agoThis is definitely not the case. https://eur-lex.europa.eu/eli/reg/2016/679/oj https://eur-lex.europa.eu/eli/reg/2016/679/oj You are required to OBTAIN CONSENT from people you want to process the personal data of. Their consent must be INFORMED by telling them who you are and what you intend to do with their data. Their consent must be FREELY GIVEN and can be WITHDRAWN at any time. That's what's at stake; not the cookies/state themselves, but how you intend to process the data of individuals. As long as you are not profiling natural individuals, no matter how they leave traces, then you don't need to ask for their consent. It's bad-faith people, who clearly want to process personal data, who make a huge fuss and tell you everyone needs a cookie banner. Mainly because they are raging that they can't data-mine and monetise every last byte of data they can get, without the consent of the individuals they're profiting from.
- snowwrestler 1y agoPlease take a close look at the cookie banner that loads on the page you linked. It says: > This site uses cookies. Visit our cookies policy page or click the link in any footer for more information and to change your preferences. And then there are two buttons: "Accept all cookies" and "Accept only essential cookies". The banner is doing two things. 1) It is notifying you that the site uses cookies. 2) It is requesting your consent for non-essential cookies. Think about this for a moment, why is it doing both things? Why doesn't it just say "Do you consent to non-essential cookies? Yes | No"? Do you think this website added an extra sentence to their banner just for fun? If you want to use essential cookies, you don't need to ask for consent. That is true. But you do still need to inform the visitor that you are setting cookies. Just as this banner does in its first sentence.
- deleted 1y ago[deleted]
- abdullahkhalids 1y ago> (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy would probably be max 10 lines) The privacy policy is here [1], linked in the footer. It also very clearly says: "For deletion requests, please contact us at privacy@ycombinator.com.". [1] https://www.ycombinator.com/legal/ https://www.ycombinator.com/legal/