9 ms·
Most websites don't need cookie consent banners
- deleted 9mo ago[deleted]
- 8organicbits 9mo agoI wonder how many people provide consent through these banners. Is it frequent enough to be worth the terrible user experience? I know some sites use dark patterns in their cookie banners, which I consider to be a helpful hint that the company doesn't respect the users.
- johannes1234321 9mo agoConsidering that for most banners the "consent" is the easy option I assume a lot. People want to get rid of the banners. However I claim the point of the bad UX is to make users angry and then have them complain about EU etc. "demanding" those. In order to weaken the regulation of tracking. If they are successful (and they are making progress) "no more cookie banners" is a lot better headlines than "more tracking"
- SchemaLoad 9mo agoThose are technically in violation of the GDPR since the opt out is required to be just as easy as the opt in.
- bradleyy 9mo agoNo, they're directly in violation. This is fully settled; it's just that some companies are counting on it not being "the thing that gets an enforcement action".
- krauses 9mo agoHow is ease of opt out versus opt in objectively measured? Most of the time both options are presented clearly and within a few pixels from each other, but opt-in is usually slightly more eye catching and/or more appealing. But the effort in terms of distance for mouse movement or number of clicks is the same. While that’s a design trick that will improve % of opt-in, how can it be argued that the opt-out was not as “easy”?
- plorkyeran 9mo agoIt is very common for there to be "accept all" and "more options" buttons where rejecting all requires multiple clicks via the latter. The sites which havea "Reject all" button right next to the "Accept all" one that's the same size and such aren't flagrantly violating the law.
- croon 9mo agoThe wording is such [0]: > If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding. > ... It shall be as easy to withdraw as to give consent. Your example does appear muddy, but I also doubt any enforcement targetting such sites. What however is extremely common is an "Accept all" vs "Manage settings" which opens up another panel, where there is still no "Reject all" option, and only various settings where you can "Save choices" which might or might not default to what you want. Such cases are obviously blatant rule violations, both in amount of clicks and obfuscation of consent. [0] https://gdpr.eu/article-7-how-to-get-consent-to-collect-personal-data/ https://gdpr.eu/article-7-how-to-get-consent-to-collect-pers...
- avadodin 9mo agoIn recent pop-ups, you are technically opted out by default(or at least that is how it is presented, I have not actually checked their cookie activity). It is two clicks to confirm that choice and dismiss the pop-up versus one to accept all cookies but if you choose to interact with the site and ignore the pop-up instead, you are supposedly non-essential cookie free by default.
- fennecfoxy 9mo agoExcept there are plenty of websites that are: accept cookies (yes) (no - you must pay), which is an extreme breach of GDPR. But GDPR is toothless and ill thought out.
- graemep 9mo agoThe effectiveness will vary with how well it will enforce, which is up to EU states to decide at the national level.
- reorder9695 9mo agoThen how is it some websites (I think the one I'm thinking of is The Sun or The Mirror) paywall the decline option? Presumably this is just illegal?
- tgsovlerkhgsel 9mo agoThe failure of the EU was to not write into (an updated version of the law) that setting a specific HTTP header means "no", and "no" means "no" not "show me a popup to ask" (i.e. showing a popup in such cases would not be allowed).
- Nextgrid 9mo agoIt wouldn't matter because most of the consent flows you see are already not compliant. The problem is a perpetual lack of enforcement even for the blatant breaches. An HTTP header wouldn't change the situation, websites would still ignore it and still get away with it.
- Dylan16807 9mo agoA mandatory header would get implemented on sites that even halfway try to comply, and it would be extra easy to enforce on fully malicious sites. I think it would be useful.
- tgsovlerkhgsel 9mo agoThe consent flows are good enough that the companies selling them can claim that they're compliant, and enforcement is slow, partly because there are so many things that are not 100% clear. The header would be a relatively clear cut situation, also opening the path to private enforcement via NOYB & Co.
- SchemaLoad 9mo agoIt's always those awful websites with a million popups, adverts, sites that reflow after 10 seconds, etc. They would be horrible to use even without the cookie banners.
- pixelat3d 9mo agoI have been on a call with a CMP where they got mad at me for not resetting our user's preferences and because our 'do not accept' was high due to the fact i refused to de-promote it via a dark pattern. I kid you not. fwiw; looking at our stats for the past year: No consent: 40.8% Full Consent: 31% Just closed the damn window: 28.1% Went through the nightmare selector: 0.07% ~1.5M impressions from GDPR areas
- Yizahi 9mo agoMost of the sites use dark patterns in the banners, from not presenting decline option to hiding and renaming it to be unrecognizable. For example I make an effort in always picking Decline All option if available and the practice shows that I click on Allow All in about 20-30% of all banners, because it was impossible to avoid. So I safely assume that general population clicks Allow All even more.
- Pooge 9mo agoFrom what I understood—but I think it's been added more recently—declining all optional cookies must be as easy as accepting all cookies.
- Yizahi 9mo agoExactly, it is defined in the GDPR law that declining should be as easy and accessible as accepting. So all of those companies with dark patterns are breaking the law.
- TechRemarker 9mo ago“You DO need consent for: Third-party tracking cookies like Google Analytics, Facebook Pixel“ Since most websites use GA then yes most need the banners. You could say most sites don’t need GA but that’s a different argument.
- stevenkkim 9mo agoGA is free while Fathom and Plausible are not. I think that's the main reason why GA is so popular and therefore why most sites need cookie consent banners.
- metabagel 9mo agoThat’s the argument made by the article.
- pixelat3d 9mo agoWhich is why this article has no value. The title is completely disconnected from market reality
- tonymet 9mo ago"Advertising or behavioral tracking cookies" Any real business needs to do behavioral tracking for campaign conversions, add-to-cart, customer acquisition, funneling, retention, personalization, etc. I love how we all hate cookie banners and say they are unnecessary, but are salaries are all paid by apps that do behavioral tracking. Only hobby blogs can get by without it.
- carlosjobim 9mo agoYou can track conversions exactly without using analytics or cookies, by using promotion codes.
- tonymet 9mo ago"you can" and no one does.
- bflesch 9mo agoIt is very convenient when you can point to others for moral absolution when the victims are invisible to you.
- tonymet 9mo agoI’m describing what people are doing .
- carlosjobim 9mo agoIt's not that uncommon. It's a completely reliable solution to the problem of attributing sales and knowing how much each advertising channel generate individually in sales. But taking into account that almost all jobs in advertising depend on keeping it "a mystery", it's no surprise that relatively few companies do it. After all, it looks better if you tell your boss or your customer that they had 40 000 "impressions" thanks to your campaign, rather than 400 definite sales.
- Hnrobert42 9mo ago
- bluegatty 9mo agoUnfortunately culprit may the privacy laws, irrespective of their good intentions, precisely because the 'banner' does not materially do anything but create an arbitrary annoyance. It's not a better experience, it's a worse experience, because users will click on 'whatever' and therefore the goal of the privacy laws are not met. Given the current situation - things would be improved by merely providing users with a consistent way to check on cookie status aka with a 'privacy link' up top that always gives clear info about privacy - but with no popup. Or - given the current situation - it may be more appropriate to be more assertive with privacy and not allow one-click opt-in because it's just too much? The fact is, the popups are just bad - the don't accomplish what the are trying to accomplish and we need a more UX friendly way to regulate. Which could be lighter or more restricting, one way or another. I think we should accept that certain kinds of tracking should be allowed by default for many cases. It don't think it's a violation of privacy for companies to map an individuals experience across their property, as long as user is anonymous, there are other checks etc. Sharing data between sites is completely another thing altogether.
- buzer 9mo ago"You DON’T need consent for: First-party cookies used just for your own analytics (in most cases)" They claim that, but the page they link to as the source says "You must...Receive users’ consent before you use any cookies except strictly necessary cookies.". So what exactly makes them think that first-party analytics cookies are "strictly necessary"? The Mastodon link in the at the start of page doesn't seem to work.
- gamblor956 9mo agoExactly. Analytics is one of the types of data for which permission is explicitly required. Session auth cookies are the only ones the EU considers strictly necessary.
- latexr 9mo ago> Session auth cookies are the only ones the EU considers strictly necessary. There are several others which are permissible. The EU has six examples. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi...
- buzer 9mo agoThis is what European Commission has determined to be acceptable for them. One very important distinction here is, as far as I understand, that EC is not bound by ePrivacy Directive as directives bound member states and require them to include them on their national law. The text on that website does state that some DPAs have found some first-party analytics acceptable, but that's not something that is confirmed by CJEU. And ePD does not have single-stop shop so you need to follow every DPAs directions if you are offering services to that DPA's country.
- deleted 9mo ago[deleted]
- Aloisius 9mo ago
- colesantiago 9mo agoThe way not to need cookie consent banners is to not do analytics tracking in the first place.
- dijit 9mo agoI often wonder what value it actually is. Sure, you might understand your demographics better.. if you presume that the analytics are faultless at telling you this- which they're really not. If you care about how your site is used, you don't need to set any cookies.
- jackp96 9mo agoFor my company, being able to view the user journey throughout the site in the analytics is pretty valuable. We don't care who the specific users are - but the tracking gives us an idea of how many people use the site? do they have a good experience? are they giving us money? do we have a bug somewhere we're missing? etc. All that is valuable as a business.
- dijit 9mo agoBack in the day we used to track user activity via a "hit id" (basically a random string) that was generated on the backend that added a "post" request to every page. Idk if that was a good idea or not. We depended on cookies for your cart and stuff.
- Dylan16807 9mo agoThe regulations are about tracking, and a chain of form fields and a cookie need to follow basically the same rules.
- egorfine 9mo agoFor some sites and businesses that's the right approach. For some.
- shevy-java 9mo agoI consider all those pop-ups to be illegal. The use case in my opinion does not warrant pissing off users by distracting them via such pop-ups. Here I classify slide-ins the same as pop-ups. I don't even read what is written there since I already don't care. I kind of have to use extensions to workaround this spam. The EU bureaucrats are very confused here - they cost a lot of money and don't really improve much at all. Plus, when they hand over data to the USA from EU citizens, it already puts them at logical odds - either you are consistent in what you do, or you simply shouldn't act in an orthogonal manner that degrades the user experience via laws. That's just nonsensical.
- _heimdall 9mo agoWhy would pissing off users be illegal? Websites can do whatever they want, I don't like those popups and just leave the page when they show up.
- decremental 9mo ago[dead]
- Madmallard 9mo agoCookie consent banners make me immediately think if I should just leave the site and not care about the content.
- bradleyy 9mo agoDisclaimer: I work on a consent product. If you're in any way something beyond a hobbyist, you should probably get legal advice about whether you need to get affirmative or implicit consent, whether you need to handle universal opt-out signals (in California, Global Privacy Control signals are now legally required to be respected), etc. Simply saying "oh I'm only tracking local cookies" might not even be enough in GDPR because the act of writing any cookie is actually covered under the law (because you're storing something on the user's computer). You're required to disclose that these cookies are in use. And a proper consent banner will immediately handle your GPC signal, and generally not show you anything (California now requires a visual notification that your preference has been respected). I understand what the author is actually saying: you can design sites that don't require the tracking tools requiring consent. And yes, while true at a certain (small) scale, when you have hundreds of millions or billions of page loads per month, and several development teams, a partnership group, and a lot of moving parts, you'll forgive me for thinking this is impractical. Consent banners don't have to be awful, I promise.
- latexr 9mo ago> the act of writing any cookie is actually covered under the law (because you're storing something on the user's computer). You're required to disclose that these cookies are in use. The page describing the law has more examples of cases where you do not need consent than the ones you do. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi...
- terrycody 9mo agoI think if you are using Google adsense, u have to show this annoying thing to all your visitors...
- exabrial 9mo agoCorrection: none of them do. The Biggest misunderstanding in how tech works by the EU ruined usability for eternity.
- tessierashpool9 9mo agowouldn't be so sure about that in Germany, even if technically and legally true. i've heard too many times about spamigation cases where shysters send mass cease and desist letters. even if those are complete bullshit and without substance you're well advised to respond and competent at that - which means you'll have to invest in a lawyer ... yadda yadda.