3 ms·
Which is not compliant with GDPR if those were the only two prominent options. Disagree must be as prominent as Agree.
by Rygian 2y ago
Which is not compliant with GDPR if those were the only two prominent options.
Disagree must be as prominent as Agree.
- andrewla 2y agoWait, are you implying that regulations are hard to comply with, poorly documented, and enforcement is extremely selective to the point where they no longer achieve their intended function? Big news if true. They should do something about that.
- Muromec 2y agoit's not that it's hard to comply, it's fighting malicious compliance which is hard. nevertheless, it's a good damn question why every single operator that has "accept all" and doesn't have "reject all" right there on the consent banner isn't fined on the spot. I think the commission noted this behavior and malicious compliance is already factored into the DMA act. The "deregulation" of GDPR could as well be retrofitting all the lessons learned into the GPDR v2.
- andrewla 2y agoThat's cute. Worth noting first that this is not really the GDPR (nobody here has said that it is directly, but in other threads people are making that assumption), this is the ePrivacy Directive (which is probably what the EU should be revising in light of these universally hated popups). The EU hands out arbitrary fines to large companies that range in the hundreds of millions of dollars, and ask companies to comply with these "technology-neutral" guidelines [1] which are so opaque that it is impossible to decipher when you are and are not in compliance with them. > The methods for giving information, offering a right to refuse or requesting consent should be made as user-friendly as possible This is wonderfully clear and explains exactly when you will and won't be the victim of extortion-level fines from the EU. You call it malicious compliance; sure, but when this is what everyone else is doing, and you decide that you want to go against "industry norms" for your website, you are painting a giant target on your back. [1] https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32002L0058:en:HTML https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...
- Rygian 2y agoI honestly don't see how your comment makes sense. Tt's the GDPR (published in 2016) that mandates that consent must be freely given. Using a 2002 directive to justify your point is disingenuous. You could have selected instead the 2020 guidelines [1] that are extremely detailed and address this point explicitly: [quote]Example 17: A data controller may also obtain explicit consent from a visitor to its website by offering an explicit consent screen that contains Yes and No check boxes, provided that the text clearly indicates the consent, for instance “I, hereby, consent to the processing of my data” […][/] > You call it malicious compliance; sure, but when this is what everyone else is doing, and you decide that you want to go against "industry norms" for your website, you are painting a giant target on your back. Non sequitur. Surely refusing to engage in malicious compliance paints _less_ of a target on your back, especially when that "malicious compliance" is actually non-compliant. [1] https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf https://www.edpb.europa.eu/sites/default/files/files/file1/e...
- andrewla 2y agoI mean, have you ever had to deal with regulators? Departing from industry norms will 100% be used against you in any regulatory proceeding, no matter how minor. It is naive to think otherwise. Regulators go after big pockets and The guidelines you link to are advisory, not legal, and they trace back to the ePrivacy regulations (although the notion of "consent" was modified by the GDPR; it's not clear which interpretation applies -- ePrivacy regulations, which are still in effect, also require consent). "The obligation is on controllers to innovate to find new solutions that operate within the parameters of the law and better support the protection of personal data and the interests of data subjects." This is standard boilerplate shit that says "you have to follow the regulations, not whatever is in this doc". I honestly don't know what to tell you. The cookie popups are an offense in every possible way; they fail to accomplish their intended purposes, they burden users with useless interactions that provide no protection, and they burden website developers with useless busywork to document compliance to hopefully avoid retaliatory punitive fines if you draw the attention of regulators or EU officials. That these policies find supporters on HN of all places is beyond my comprehension.