6 ms·
No, the EU did not do that. Companies did that and thoughtless website owners, small and large, who decided that it is better to collect arbitrary data, even i
by gond 1y ago
No, the EU did not do that.
Companies did that and thoughtless website owners, small and large, who decided that it is better to collect arbitrary data, even if they have no capacity to convert it into information.
The solution to get rid of cookie banners, as it was intended, is super simple: only use cookies if absolutely necessary.
It was and is a blatant misuse. The website owners all have a choice: shift the responsibility from themselves to the users and bugger them with endless pop ups, collect the data and don’t give a shit about user experience. Or, just don’t use cookies for a change.
And look which decision they all made.
A few notable examples do exist: https://fabiensanglard.net/ https://fabiensanglard.net/
No popups, no banner, nothing. He just don’t collect anything, thus, no need for a cookie banner.
The mistake the EU made was
to not foresee the madness used to make these decisions.
I’ll give you that it was an ugly, ugly outcome. :(
- wskinner 1y ago> The mistake the EU made was to not foresee the madness used to make these decisions. It's not madness, it's a totally predictable response, and all web users pay the price for the EC's lack of foresight every day. That they didn't foresee it should cause us to question their ability to foresee the downstream effects of all their other planned regulations.
- gond 1y agoInteresting framing. If you continue this line of thought, it will end up in a philosophical argument about what kind of image of humanity one has. So your solution would be to always expect everybody to be the worst version of themselves? In that case, that will make for some quite restrictive laws, I guess.
- wskinner 1y agoPeople are generally responsive to incentives. In this case, the GDPR required: 1. Consent to be freely given, specific, informed and unambiguous and as easy to withdraw as to give 2. High penalties for failure to comply (€20 million or 4 % of worldwide annual turnover, whichever is higher) Compliance is tricky and mistakes are costly. A pop-up banner is the easiest off-the-shelf solution, and most site operators care about focusing on their actual business rather than compliance, so it's not surprising that they took this easy path. If your model of the world or "image of humanity" can't predict an outcome like this, then maybe it's wrong.
- gond 1y ago> and most site operators care about focusing on their actual business rather than compliance, And that is exactly the point. Thank you. What is encoded as compliance in your example is actually the user experience. They off-loaded responsibility completely to the users. Compliance is identical to UX at this point, and they all know it. To modify your sentence: “and most site operators care about focusing on their actual business rather than user experience.” The other thing is a lack of differentiation. The high penalities you are talking about are for all but of the top traffic website. I agree, it would be insane to play the gamble of removing the banners in that league. But tell me: why has ever single-site- website of a restaurant, fishing club and retro gamer blog a cookie banner? For what reason? They won’t making a turnover you dream about in your example even if they would win the lottery, twice.
- troupo 1y ago> Compliance is tricky How is "not selling user data to 2000+ 'partners'" tricky? > most site operators care about focusing on their actual business How is their business "send user's precise geolocation data to a third party that will keep that data for 10 years"? Compliance with GDPR is trivial in 99% of cases
- lurking_swe 1y agoWell, you and I could have easily anticipated this outcome. So could regulators. For that reason alone…it’s stupid policy on their part imo. Writing policy is not supposed to be an exercise where you “will” a utopia into existence. Policy should consider current reality. if your policy just ends up inconveniencing 99% of users, what are we even doing lol? I don’t have all the answers. Maybe a carrot-and-stick approach could have helped? For example giving a one time tax break to any org that fully complies with the regulation? To limit abuse, you could restrict the tax break to companies with at least X number of EU customers. I’m sure there are other creative solutions as well. Or just implementing larger fines.
- shagie 1y ago> The solution to get rid of cookie banners, as it was intended, is super simple: only use cookies if absolutely necessary. You are absolutely right... Here is the site on europa.eu (the EU version of .gov) that goes into how the GDPR works. https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations_en https://commission.europa.eu/law/law-topic/data-protection/r... Right there... "This site uses cookies." Yes, it's a footer rather than a banner. There is no option to reject all cookies (you can accept all cookies or only "necessary" cookies). Do you have a suggestion for how the GDPR site could implement this differently so that they wouldn't need a cookie footer?
- pelorat 1y ago> Do you have a suggestion for how the GDPR site could implement this differently so that they wouldn't need a cookie footer? Well, it's a information-only website, it has no ads or even a login, so they don't need to use any cookies at all. In fact if you look at the page response in the browser dev tools, there's in fact no cookies on the website, so to be honest they should just delete the cookie banner.
- shagie 1y agoAt https://commission.europa.eu/cookies-policy_en#thirdpartycookies https://commission.europa.eu/cookies-policy_en#thirdpartycoo... you can see the list of 3rd party cookies they use (and are required to notify about it). You Tube Internet Archive Google Maps Twitter TV1 Vimeo Microsoft Facebook Google LinkedIn Livestream SoundCloud European Parliament In theory, they could rewrite their site to not require any of those services.
- varenc 1y agoThis is why the EU law was nonsense. Many of those cookies listed are just because of they want embed things like YouTube or Vimeo videos. Embedding YouTube to show videos to your users is massively cheaper and easier than self hosted video infrastructure. The idea that the GDPR's own website just implemented GPDR "wrong" because they should just avoid using cookies is nonsense and impractical.
- eddythompson80 1y ago"If you have a dumb incentive system, you get dumb outcomes" - Charlie Munger
- varenc 1y agoIf the law incentivized practically every website to implement the law in the "wrong" way, then the law seems wrong and its implications weren't fully thought out.
- constantcrying 1y agoBut this is a failure on the part of the EU law makers. They did not understand how their laws would look in practice. Obviously some websites need to collect certain data and the EU provided a pathway for them to do that, user consent. It was essentially obvious that every site which wanted to collect data for some reason also could just ask for consent. If this wasn't intended by the EU it was obviously foreseeable. >The mistake the EU made was to not foresee the madness used to make these decisions. Exactly. Because the EU law makers are incompetent and they lack technical understanding and the ability to write laws which clearly define what is and what isn't okay. What makes all these EU laws so insufferable isn't that they make certain things illegal, it is that they force everyone to adopt specific compliance processes, which often do exactly nothing to achieve the intended goal. User consent was the compliance path to be able to gather more user data. Not foreseeing that sites would just ask that consent was a failure of stupid bureaucrats. Of course they did not intend that sites would just show pop ups, but the law they created made this the most straightforward path for compliance.
- gond 1y agoThat possibly cannot be the common notion to frame this. I agree with some parts it but also see two significant issues: 1. It is even statistically implausible that everyone working at the EU is tech-illiterate and stupid and everybody at HN is a body of enlightenment on two legs. This is a tech-heavy forum, but I would guess most here are bloody amateurs regarding theory and science of law and you need at least two disciplines at work here, probably more. This is drifting too quickly into a territory of critique by platitudes for the sake of criticism. 2. The EU made an error of commission, not omission, and I think that that is a good thing. They need to make errors in order to learn from them and get better. Critique by using platitudes is not going to help the case. It is actually working against it. The next person initiating a EU procedure to correct the current error with the popups will have the burden of doing everything perfectly right, all at once, thought through front to back, or face the wrath of the all-knowing internet. So, how should that work out? Exactly like this: we will be stuck for half an eternity and no one will correct anything because if you don’t do anything you can’t do any wrong! We as a society mostly record the things that someone did wrong but almost never record something somebody should have done but didn’t. That’s an error of omission, and is usually magnitudes more significant than an error of commission. What is needed is an alternative way of handling and judging errors. Otherwise, the path of learning by error will be blocked by populism. ——- In my mind, the main issue is not that the EU made a mistake. The main issue is that it is not getting corrected in time and we will probably have to suffer another ten years or so until the error gets removed. The EU as a system needs to be accelerated by a margin so that it gets to an iterative approach if an error was made. I would argue with a cybernetic feedback loop approach here, but as we are on HN, this would translate to: move fast and break things.