4 ms·
There would be a few fixes, if the politics would be interested in actually fixing this loophole. - deny is the default: one button to deny everything but one
by Kovah 2mo ago
There would be a few fixes, if the politics would be interested in actually fixing this loophole.
- deny is the default: one button to deny everything but one accept button for every partner
- respect DO NOT TRACK, and force software/hardware providers to enable it by default
- making payments for non-tracking illegal
- remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything
- and probably: prohibit any other dark pattern, or at least make it extremely hard to implement
- AndroTux 2mo agoRespecting Do Not Track is the most important thing here. They absolutely could have forced all browser vendors to implement that feature, and force website owners to honor it. Instead, we got cookie banners.
- orwin 2mo ago> - deny is the default: one button to deny everything but one accept button for every partner Yes, that's in the law. I you do not click on consent, the default is deny everything, and a button to refuse everything should be easy to access. > - making payments for non-tracking illegal In the law too. > - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything True, this loophole was introduced by UK/US lobbyists at the time if I remember correctly. My (very small, 3 dev) company at the time worked on health data and managed to find itself in the arcanes of Brussels because anything related to PII security was good news for us. - and probably: prohibit any other dark pattern, or at least make it extremely hard to implement This is the courts who can judge that. The main issue with the gdpr law is local enforcement. It is honestly well written and easy to understand, which is why you have so much legal loopholes, but EU courts are RAI rather than RAW (our fast americanisation is changing that though).
- danaris 2mo ago> and a button to refuse everything should be easy to access. Part of the problem with this is the website operators who maliciously interpret this to mean "also refuse the cookie that says what I selected", so you have to select it every time you visit. (I even hit a site a few weeks ago that required it on every page when I refused.)
- lII1lIlI11ll 2mo ago> making payments for non-tracking illegal This keeps surfacing in discussions about tracking. I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise or require you to pay to opt-out? Is this just an entitled leftie thing ("Elon Musk should pay for my Instagram!") or is there a genuine though-out plan for another reasonable business model?
- fwlr 2mo agoI would have them make money by selling me products, rather than selling me as a product.
- lII1lIlI11ll 2mo agoHow is "Payed subscriptions tier without tracking" not a product? Isn't it exactly what Instagram offers in Europe?
- troupo 2mo ago> I'm wondering how do you propose for b2c software companies to make money if they can't either properly advertise Advertising does not require invasive and pervasive tracking. There's no world in which a b2c company needs my precise geo location for 12 years: https://x.com/dmitriid/status/1817122117093056541 https://x.com/dmitriid/status/1817122117093056541 Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual.
- lII1lIlI11ll 2mo ago> Advertising does not require invasive and pervasive tracking. Why are you so opposed to pay for a tier without tracking? I'm still not following. > Why the hell are people defending 24/7 monitoring at scale that would make even Stasi or Stalin pause and think "are we going too far?"? 1984 wasn't an instruction manual. Stasi or KGB weren't "opt in" for their citizens while social networks definitely are. For example, Twitter won't allow me to access the images in the post you linked because I deleted my account as soon as Musk completely enshittified it and I'm doing just fine without it.
- troupo 2mo ago> deny is the default Article 6 and 7 of the GDPR > respect DO NOT TRACK, and force software/hardware providers to enable it by default There is other software and other areas of human activity than just cookies and browsers. Also, with "deny is default" you shouldn't really nead the DNT. But tell that to the ad/tracking industry > making payments for non-tracking illegal Generally derived from GDPR. See e.g. recital 43 https://gdpr-info.eu/recitals/no-43/ https://gdpr-info.eu/recitals/no-43/ > remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything It's there because actual legitimate activities like security audits or fraud detection would not be possible. EU expects companies to act as adults, but here we are. > prohibit any other dark pattern, or at least make it extremely hard to implement This cannot be properly specified. And existing laws and regulations already cover that. See the article we're commenting under. And noyb's previous cases: https://noyb.eu/en/where-did-all-reject-buttons-come https://noyb.eu/en/where-did-all-reject-buttons-come