6 ms·
I also used to hate this directive, but when I read the description on the website of the European Commission, it is actually much more nuanced than I thought:
by vincentdm 11y ago
I also used to hate this directive, but when I read the description on the website of the European Commission, it is actually much more nuanced than I thought:
"However, some cookies are exempt from this requirement. Consent is not required if the cookie is: used for the sole purpose of carrying out the transmission of a communication, and strictly necessary in order for the provider of an information society service explicitly required by the user to provide that service."
Source: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm#section_2 http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm#se...
So it turns out the directive isn't as dumb as many believe it to be, but a lot of webmasters wrongly believe that any cookie usage implies having to put up the notice. (Or the nuance was lost on the in-house legal team who briefed the webmaster.)
I run a software-as-a-service company in the EU, but only use cookies for login management. Therefore, I do not need to use the warning. But if I would track my users for advertising etc. I'd have to insert the warning in my web app.
This thoughtless behaviour reminds me of the thousands of websites which include a "(c) YYYY" copyright notice in their footers, despite this being completely irrelevant in modern copyright law.
- kluck 11y agoThanks for the find!
- richardwigley 11y ago>> This thoughtless behaviour reminds me of the thousands of websites which include a "(c) YYYY" copyright notice in their footers, despite this being completely irrelevant in modern copyright law. I'll bite :-) Are you automatically covered then? - companies like Apple still do it .... 'Copyright © 2015 Apple Inc. All rights reserved.'
- vincentdm 11y agoAs I understand it (but I am no lawyer), it was only a requirement in the US until 1989. So if you are a company operating outside the US and none of your copyrighted material dates from before that, I don't see why you should include it. Also, for websites there are many more reliable methods of demonstrating the time of creation. So for some it might have a use, but it seems to me that thousands of webmasters (including myself) have been copying this pre-1989 US-only best-practice, just because it is nice to have something to put it the footer :-)
- seandougall 11y agoThe Copyright Office does suggest that it could still be a good idea, even though it's no longer required: > Use of the notice may be important because it informs the public that the work is protected by copyright, identifies the copyright owner, and shows the year of first publication. Furthermore, in the event that a work is infringed, if a proper notice of copyright appears on the published copy or copies to which a defendant in a copyright infringement suit had access, then no weight shall be given to such a defendant’s interposi tion of a defense based on innocent infringement in mitigation of actual or statutory damages, except as provided in section 504(c)(2) of the copyright law. Innocent infringement occurs when the infringer did not realize that the work was protected. (http://copyright.gov/circs/circ01.pdf http://copyright.gov/circs/circ01.pdf)
- bontoJR 11y agoYes, you are. > A website — graphics, content, visual elements — is copyrighted at the time of development. So putting the copyright notice on the bottom of a site states that the material displayed is not to be used without permission of the owner. In fact, you don’t even need the notice to claim copyright; the law eliminated the requirement of public notice in 1989. Source: http://www.sitepoint.com/what-it-means-to-copyright-a-website/ http://www.sitepoint.com/what-it-means-to-copyright-a-websit...
- hmage 11y agoThis source covers only US copyright law, not EU copyright law, not UK copyright law, not Russian copyright law, not Canadian copyright law, etc.
- M2Ys4U 11y agoArticle 5(2) of the Berne Convention:[0] "The enjoyment and the exercise of these rights shall not be subject to any formality" [0] https://en.wikisource.org/wiki/Convention_for_the_Protection_of_Literary_and_Artistic_Works/Articles_1_to_21#Article_5 https://en.wikisource.org/wiki/Convention_for_the_Protection...
- ma2rten 11y agoIt looks professional.
- cartoonfoxes 11y agoAnd it has the practical value of informing you than someone maintaining the site has at least looked at it within the last year or so.
- seandougall 11y agoOr had the forethought ten years ago to add: © <?php echo strftime('%Y'); ?> ;-)
- damoncali 11y agoYou're supposed to put the year the material was copyrighted, not the current year.
- danmaz74 11y agoYes but as soon as you use Google Analytics, you need to include the notice. As a EU citizen, I think this example shows how stupid laws can come out of good intentions. Why stupid? Because, no matter what the intentions were, the only practical effect is creating a nuisance for web users, who quickly learn to ignore the consent requests.
- 0x0 11y agoI never understood why they didn't force the requirement onto browser makers instead of website operators. Then users could actually enforce their cookie choice by opting out, instead of having to trust every website to be honest in their cookie use.
- kiiski 11y agoBrowsers already have the ability to block cookies and at least Firefox allows overriding the choice for individual sites without needing any plugins.
- 0x0 11y agoThat much is obvious. It's a shame the lawmakers didn't go in that direction.
- tfgg 11y agoAnd browsers have had such options (block all cookies, prompt to accept, etc.) built in to them since the very beginning of cookies, except everyone turned them off because they were annoying! So now websites had to add them! And they are just as annoying! ARGH! A more useful directive would have been some sort of legally-backed "coloured cookie" type system, where a cookie has to declare for what purpose (session, internal analytics, adverts, site-to-site tracking, etc.) it's for, so browsers can then selectively block those categories. That would be useful, because then you could punish people who lie about the purpose of their cookie.
- 0x0 11y ago
- taejo 11y agoThere are many examples, including "This product may contain traces of ..." and California's Prop 65: "This building contains substances known to the State of California to cause ..." It's required in some cases, but never forbidden, so one can avoid liability by just posting it everywhere, robbing it of its informative content.
- somesay 11y agoWhile it's also about liability, there seem to be people deadly allergic to even small amounts of e.g. nuts. Those notices are shown when production machines are also shared used for other products and cleaning is never completely safe.
- taejo 11y ago... and it's a heck of a lot cheaper to put a notice on the product than to make your peanut-free products in a cleanroom.
- scotty79 11y ago> directive isn't as dumb as many believe it to be, I think directive is exactly as dumb as the effect it causes. Regardless of lawmakers intentions or even the letter of the law.
- antocv 11y agoThe same person who tried to justified the cookie law (and no she didnt change her mind, thinks the cookie law and EU is flawless still), just recently took a stance for geo-blocking, saying the practice of restricting access to information based on geographical location may in times be necessary. Ah, okay so when, and she didnt say. But that person hangs around with EU parlamentarians.
- vincentdm 11y agoI agree that the general effect is still dumb, but I meant that the directive isn't as "technologically illiterate as many believe it to be". I was pleasantly surprised that the legislators were aware of the necessity of cookies for login management. At least it allows me to keep my web app clean of this pollution...
- mseebach 11y agoIt is very much technologically illiterate not to foresee this exact effect.
- Navarr 11y agoI think the (C) YYYY notice is more for people who "forget" that items are copywritten automatically.
- raverbashing 11y agoMaybe also as a point of naming the official institution responsible for that page
- deleted 11y ago[deleted]
- damoncali 11y agoNot exactly. It has legal purposes - IANAL (and someone correct me if I'm wrong), but I believe it has to do with proving willful misuse (which matters somehow) and establishing a date of copyright. I believe that the idea is to put the earliest date of copyright, not the current year, which is a common practice.
- oliwarner 11y agoSure, there are allowances for technically essential cookies but in practice almost everybody is using third-party services like Google Analytics. For a physical business with a brochure website, tracking how people use their site is more essential than any session cookie. I'm not saying I necessarily disagree with the idea behind the law, rather that almost everybody uses cookies and making everybody announce that doesn't mean we're suddenly all informed. An implicit /cookies/ or /cookies.html or even a domain-level TXT record would be just as informative, without clobbering user experience with a message that everybody is now blind to. As others have said, copyright notices are as much about preventing infringement as they are anything else. Consider them similar to a "Thieves will be prosecuted" signs in shops.
- aethertron 11y agoWith regard to the law, at least the UK interpretation, 'essential cookies' aren't ones that are essential for the website-operator's business purposes. The term is restricted to cookies that are essential for what the visitor has requested. source: https://ico.org.uk/for-organisations/guide-to-pecr/cookies-and-similar-technologies/ https://ico.org.uk/for-organisations/guide-to-pecr/cookies-a...
- oliwarner 11y agoThat's my point. Things that are so commonplace should be implicit.
- aethertron 11y agoI guess the legislators didn't think the general public was informed enough about cookies for them to meaningfully, implicitly consent. I don't think many people read the already mandatory privacy policies, so I'd have to agree. That the use of, say, 3rd party analytics cookies is so commonplace seems neither here nor there. (For the record: I would prefer a technological, rather than legislative solution here.)
- tjansen 11y agoEven if you use cookies legally without the cookie warning, there would still be the risk of getting a cease&desist or even a lawsuit from someone who does not understand the distinction and/or uses automated tools to find violating sites. At least in Germany, sending such cease&desists is a lucrative business for many lawyers and organizations.
- Tloewald 11y agoSeems like that's a problem with the legal system, not this law. Presumably the same thing happens with other poorly understood laws.
- currysausage 11y ago> This thoughtless behaviour reminds me of the thousands of websites which include a "(c) YYYY" copyright notice in their footers https://www.youtube.com/watch?v=6x0cAzQ7PVs&t=6m45s https://www.youtube.com/watch?v=6x0cAzQ7PVs&t=6m45s (6:45–8:27) TL;DW: "It's actually not there for legal reasons, [...] it's there as punctuation." (No longer necessary for them, still a nice anecdote.)