3 ms·
Guidance from the regulators has been abundantly clear on this point. You'll notice all the big players have a "reject all" button because they would get fined
by snackbroken 1y ago
Guidance from the regulators has been abundantly clear on this point. You'll notice all the big players have a "reject all" button because they would get fined otherwise. We're well past the point where anyone can make a reasonable excuse of ignorance, making it onerous to opt out is simply banking on lax enforcement.
I, for one, think it's time to start busting some proverbial kneecaps if we ever want publishers to take the matter seriously. The other alternative is to outlaw the collection of personal information without a legitimate purpose (consent or no) _and then_ come down hard on violators. The industry has had ample time to regulate itself and has chosen profit over ethics at every opportunity.
- rjsw 1y agoThe linked site states that it does not collect personal information until you click on the "agree" button, in what way is that non-compliant with the GDPR?
- snackbroken 1y agoLike I said upthread, > Not having an option to reject that is as convenient as the one to accept is not compliant with GDPR. The law, guidance provided by regulators, and court rulings are all quite clear on this: Consent must be freely given, the consent form must not be coercive in any way. This includes (but is not limited to) making rejecting more difficult than accepting, degrading the quality of service for those who reject, gating the service behind accepting, or requiring payment from those who reject. Collecting personal information without prior consent would obviously also be a (worse) violation of the law.
- rjsw 1y agoIn this case, rejecting is easier than accepting, just don't click on anything.
- snackbroken 1y agoIf you don't click on anything then you are gated from the service. The service provider may not impose obstacles to using the service without providing consent that are not present when providing consent.
- rjsw 1y agoThe GDPR just requires that if a service provider wants to process personal data then it has to follow certain rules. I don't think it prevents that service provider from restricting access to their service in some way, that is just outside the scope of this law.
- snackbroken 1y agoSure, if you want to restrict access to your service or plaster your website with annoying pop-ups just for fun, the law doesn't cover that. It only cares about this in the context of processing personal data. Essentially: If you wish to process personal data on the basis of consent, then the consent must be freely given, and consent is not freely given if you engage in coercive or deceptive practices, which includes providing a consent form that has an "accept all" option but no "reject all" option. Here's the relevant text of the regulation: > 1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data. > 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding. > 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. > 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.