4 ms·
As far as cookie popups go (and recognizing you probably know this so it’s more a general comment), GDPR doesn’t encode cookie popups into law, but the entire i
by qkeast 8mo ago
As far as cookie popups go (and recognizing you probably know this so it’s more a general comment), GDPR doesn’t encode cookie popups into law, but the entire industry follows the pattern of cookie popups in response to the underlying requirement of informed consent. Companies could choose to not collect as much info, or take other approaches, but cookie popups are the default.
- causal 8mo agoYeah it's wild we blame GDPR instead of the companies that decide tracking us is worth our inconvenience
- SpicyLemonZest 8mo agoGDPR does not formally require cookie popups (and the cookie stuff predates GDPR as such anyway). But it's challenging to the point of impracticality to run a website with so few cookies that a popup is not required. The EU's official resources on data protection, for example, have a popup. (https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations_en https://commission.europa.eu/law/law-topic/data-protection/r...)
- latexr 8mo ago> But it's challenging to the point of impracticality to run a website with so few cookies that a popup is not required. It is not. They even list more types of cookies which do not need consent than the ones which do. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi... > The EU's official resources on data protection, for example, have a popup. Because it’s mandatory for them, not because the cookies are invasive. See the top of the page of the link above: > Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
- bruce511 8mo ago>> But it's challenging to the point of impracticality to run a website with so few cookies that a popup is not required. Nonsense. It's easy to create a site that doesn't need a cookie pop-up. Indeed the mere existance of a cookie pop-up screams "we are tracking you and selling your info".
- dathinab 8mo ago> point of impracticality to run a website only if your site insist to use any of the widely used Ad networks through there are Ad Networks which base ads on what is on your site instead of who visits and the popup you link is _not_ a GDPR popup but is related to some other older and very misguided law(s). (Not EU wide laws, but EU sites want to be compliant with every member countries laws.) Having a EU decision which requires countries to remove this older misguided laws has been on the agenda for years. It's just given that most sites anyway will have popups (e.g. for Google Ads) things move way way way to slow :(
- kstrauser 8mo agoYou're right, for sure. It'd be nice if the law included an explicit exception for local cookies for routine site operation purposes. I haven't put any time into nailing down the wording, but something that communicates "sites are allowed use 'authentication cookies' to validate a user's ability to make server requests" would be most welcome. Then you could actually have an incentive to remove the cookie banner on sites that only use cookies for session authentication. You don't also use them to integrate with your marketing analytics kraken? Sweet! You don't have to have a banner or other notice!
- mhitza 8mo agoIf you use cookies only for authentication it can be a single note on the login form.
- latexr 8mo agoYou don’t even need that. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi... > Cookies and similar technologies that generally do NOT need consent > (…) > Authentication cookies, for the duration of a session
- dathinab 8mo agoneeding consent and informing the user are two distinct concepts I think you did need to explicitly tell the user about it. But I think (not fully sure) they did relax that recently so just listing it in you Privacy Policy or similar should be enough by now. But also due to how enforcement is designed it's not that you really had to worry about anything if you only have non-censent requiring cookies and list them clearly in the privacy policy. Worst case a privacy agency tell you to "improve on it" without penalty. It's just which site (or app) today doesn't use something like Google Ad Network, or Metas Ad Network, or Apples Ad network. All of which do not support ads without tracking (which still are very viable, e.g. select ads based on what the side/ad is about).