5 ms·
Well, yeah, but isn't the EU also responsible for all the trash cookie-consent notifications I get from every website now? Overall, I'm happy they're actively
by chargingmarmot 3y ago
Well, yeah, but isn't the EU also responsible for all the trash cookie-consent notifications I get from every website now?
Overall, I'm happy they're actively involved. The hands-off attitude in the US is terrible.
- frankvdwaal 3y agoNo, it's the builders of the consent notifications who are responsible for that. They are often skirting or even breaking EU law to make it a headache to refuse. The GDPR says, for example, that refusal should be just as easy as acceptance. Having to click to another screen to do that is... not that. In reality a cookie consent notification can just as well be a small widget somewhere with an accept and refuse button, but it's the builders of these frameworks that have a vested interest in getting you to press accept. I've applied for a job at one of these companies about a year ago, and I asked them about it. They said to me that according to their metrics, there's about 30% more acceptance if they only bury their Refuse button, so it's a legal risk they are willing to take. Needless to say, when they invited me for a second conversation, I politely refused. No, the shitty cookie screens with dark patterns is not the responsibility of the EU - although you could make the argument that the EU should have been stricter or more prescriptive.
- mft_ 3y agoIt's not just the dark-pattern cookie popups that are a problem - it's having any mandatory cookie popups --even the fairly-designed ones-- on virtually every website that you ever open. That's what's crappy about the implementation. I once read a light-hearted analysis of the cumulative time wasted by humanity due to the original USB plugs/sockets being unidirectional. I suspect a similar analysis of these cookie popups would be shocking. Hah, first Google hit: https://www.linkedin.com/pulse/billions-hours-now-being-wasted-clicking-web-site-cookie-tas-dienes/ https://www.linkedin.com/pulse/billions-hours-now-being-wast.... (Not sure I agree with the numbers used, but the order of magnitude probably isn't too far wrong)
- MaKey 3y agoCookie banners are not mandatory. If you're just using technical cookies you don't need a banner at all. Websites with them want to track you, that's why they have them. They need to ask for your permission to do so, which I think is a good thing. So instead of being mad at the EU we should be mad at those websites trying to get as much data as possible from their users.
- olivierduval 3y agoActually, websites could "not track" BY DEFAULT (so no popup) and have a nice widget in a corner asking for consent to track, explaining why they need it, without this widget being obstructive... The problem is definitly NOT THE REGULATION but the way that websites have become a data/cash machine...
- account42 3y ago> Actually, websites could "not track" Yes, why not stop there?
- RunSet 3y agoIf you don't collect data you don't need to ask permission to collect data. https://lokilist.com/about.php https://lokilist.com/about.php Likewise, a "privacy policy" explains the extent to which your privacy will be violated.
- speleding 3y agoThe regulation could have been much better though. For one, it's unclear if Google Analytics cookies qualify. Spain and Austria say one thing, The Netherlands says another, so out of an abundance of caution websites put them everywhere. I also think it would have been very feasible for the EU to define that a browser could ask for consent once and then apply that to many/all sites by sending a header. So the popup would only be needed for people without a browser that has implemented it.
- 3y ago
- Sander_Marechal 3y ago> The GDPR says, for example, that refusal should be just as easy as acceptance. Not true, actually! GDPR is a framework, and every EU country implements a national law according to that framework (e.g. the Dutch implementation is called "AVG"). The specific requirement that refusal must be as easy as acceptance is not in the GDPR, but several countries added it to their national implementation of the GDPR.
- frankvdwaal 3y agoThis is a misconception that I've seen going around, and I still wonder where it came from. The Dutch implementation is called "Uitvoeringswet Algemene Verordening Gegevensbescherming", which, as the title states, is the law that implements the GDPR. "AVG" is just a translation for "GDPR", not the name of the law that implements it. The Uitvoeringswet describes how the GDPR functions within Dutch law, for example, it describes the role that the Dutch Data Protection Authority plays. You can read the Uitvoeringswet right here: https://wetten.overheid.nl/BWBR0040940/2021-07-01 https://wetten.overheid.nl/BWBR0040940/2021-07-01 The GDPR (in Dutch AVG, in French RGPD, in Spanish RGPD, etc.) actually DOES state that it should be just "as easy to withdraw as to give consent" in Article 7. The directive (2016/679) can be found here: https://eur-lex.europa.eu/eli/reg/2016/679 https://eur-lex.europa.eu/eli/reg/2016/679.
- underdeserver 3y agoEh. > "as easy to with as to give consent" The full Article 7, section 3, in English, says: > The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. I think this can be interpreted as, you ask for consent, it doesn't have to be as easy to say no, but once consent is given - it should be as easy to withdraw it as it is to re-give it after it was withdrawn. Somewhat badly worded, in my opinion. It doesn't unambiguously say "refusing consent every time it is requested should be as easy as accepting it."
- breisa 3y ago
- berkes 3y agoAlso, and too often overlooked or silently ignored: You don't need cookie popups! Really. You don't. You only need to get consent to track users with software you don't run yourself. Or when you sell your data off to other companies. Both are, unfortunately, the norm. But there's absolutely no technical reason to have these in place. Non at all. Plenty of alternatives for tracking that doesn't need consent. Or just not sell your customers' data off. I would be infuriated if I found the bakery down the street is selling its security footage with my face on it, next to my sales and spending in that bakery. I'd expect them to at least warn me about this at the door. So I can then buy my bread elsewhere. That's what a consent banner is!
- hallway_monitor 3y agoThank you for this accurate analogy. Similar to what if the post office delivered all your mail for free but they also opened it and read it in order to send you advertising.
- partitioned 3y agoThen enforce the law. Making the regulation and letting people halfway get around it and not holding them accountable just made things worse for everyone
- bretpiatt 3y agoAuto-deny and move on? https://www.ghostery.com/blog/how-to-block-cookies-on-most-browsers https://www.ghostery.com/blog/how-to-block-cookies-on-most-b...
- AshamedCaptain 3y agoDisabling cookies will cause _more_ of the "cookie prompts" to appear, not less. Some pages these days even will prevent visiting them unless they can set a cookie... Also, cookies are not the only method of tracking which is supposed to be disabled when you hit Deny.