4 ms·
Or you could just stop spying on people. No cookie banner is required for functionally necessary cookies.
by tomp 2mo ago
Or you could just stop spying on people.
No cookie banner is required for functionally necessary cookies.
- deleted 2mo ago[deleted]
- jebronie2 2mo ago[flagged]
- Etheryte 2mo agoNot wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.
- jebronie2 2mo agoNo, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality. You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent. Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.
- kodebach 2mo agoWell if the cookie comes from a third party it implicitly allows tracking. Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
- jebronie2 2mo agoIP addresses are PII according to german law, that debate has been settled long ago by final court-rulings afaik. "Well if the cookie comes from a third party it implicitly allows tracking." Yes, because this makes tracking possible you have to gather consent first, regardless if tracking actually happens. Very bad solution, they could just define how data can be legally used, instead of also overreaching by defining how data can be legally transmitted.
- jeremyjh 2mo agoPutting assets on a 3rd party server is indeed a great way to track people. They can completely fuck off with all of that as well.
- jebronie2 2mo agoThat's the problem with the regulation: It defines how data can be legally transmitted instead of defining only how data can be legally used, resulting in nasty side-effects like making embedding third-party content illegal even if its not used for tracking.
- buzer 2mo agoThis is actually slightly narrower exception than people (and regulators) think. The exception is: > strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites. And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
- ApolloFortyNine 2mo agoWhat I hate about EU laws is they tend to word these things like this. People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business. People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario. Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.
- GJim 2mo agoSo you think letting the scummy AdTech industry do whatever they want everywhere is the better "strategy"?
- IMTDb 2mo agoApparently the eu official website really needs to track you then. For what’s essentially just static content. I’ll consider dropping cookies banner when their website can work without. Stop the “do as I say not as I do” EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr https://european-union.europa.eu/index_fr
- zelphirkalt 2mo agoThey apparently hired incapable people to build that. Very silly to build it in a way that kind runs contrary to what the intentions of the very laws they are making are. I get similarly upset, when I see Google tracking on official websites of government or public institutions.
- micromacrofoot 2mo agothey use third party cookies, just read their linked info on it and it's fairly clear why they have a banner if they didn't use third party cookies they wouldn't need it
- TurdF3rguson 2mo ago> Apparently the eu official website really needs to track you then. No, they don't really need to track you, that's why it requires consent to do it. They are doing exactly what they say. In other words, they're not saying don't track your visitors. They're saying get consent first.
- latexr 2mo agoYou could try to understand why that’s the case, instead of assuming maliciousness or incompetence. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi... > Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
- iammrpayments 2mo agoIt’s not that easy to make a distinction between what is necessary.
- ThatMedicIsASpy 2mo agoOutlawing user tracking/profiling and selling their data would be the biggest change to the internet.