[0]: http://ec.europa.eu/justice/data-protection/article-29/docum...
Note that you can use your webserver logs for analytics and that doesn't require the cookie banner.
In the EU, tracking user IPs actually requires consent. Even logging them does.
If the cookies are used for tracking, like Google Analytics, then yes, it needs to ask the user for consent.
And that’s not a warning, but actual "yes/no", and in the no case, it may not set a tracking cookie, or have set a tracking cookie already.
Most sites (except for a few dozen German and Dutch ones) just redirect you somewhere else, though, if you refuse to be tracked.
The law requires user consent, in form of a click on a banner or scrolling the page, before setting any cookie.
http://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:320...
Complete law: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
Paragraph 66 talks about cookies.
A later exception was made by the EU for session cookies.
Guidelines for webmasters:
http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm#se...
It has a sample banner which is similar to those which most users display.
Spanish official directives (with further protection because of a local law called LSSI): https://www.agpd.es/portalwebAGPD/canaldocumentacion/publica..., page 17. Also comes with a sample banner
Did you really think that everyone else was wrong or didn't read the law and is programming these banners as some sort of fad?
However, OP is right, governments spy on our webcams and analyze our traffic, and that's ok, but we need a stupid banner that overrides browser preferences to avoid all but session cookies. Duh.
This is the official stance of the ICO[1], the UK national authority: there was a need to educate users what cookies were when the directive was passed. No such need exists now. ICO itself briefly used consent overlays, but does not anymore (EDIT: Aaaaand they've apparently use them again; I'll try to find the policy release where they say this is not necessary.). Cookies not used for tracking of persons never needed any consent, as they have no privacy implications.
People who make their living creating cargo-cult UI designs, have predictably added cargo-cult law-compliance to their toolset. It is beyond stupid.
Wrong. If I disable cookies in my browser, I can't log in to websites anymore, so they need to be allowed. A whitelist would be very inconvenient. On top of that, it's not explicit allowance, it'd be implicit (i.e. opt-out instead of opt-in).
I don't know if British legislation is different, but this is illegal at least in the Netherlands.
It has never been enforced that way to my knowledge, anywhere in the EU. Which law or court decision says that it is actually illegal?
How does my browser know that one PHPSESSID is used for tracking, and another is a session? You probably mean until I close the browser, which would be never -- at least, I would never want to, but I do every few months for browser updates. (My laptop always goes in suspend/sleep mode.)
> Ditto for third-party cookies
I don't know what third-party cookies are anyway, and I bet my peers could not give me an accurate description either. We're all in the software business, be it game development or general software development or something.
Two gave a rough description but couldn't answer a question about whether embedded Like buttons would work if the user is logged into Facebook. Another just said "I don't know".
I'm not sure "the public is informed about all their options by now". The ones who really care generally use uBlock, ABP, Self-Destructing Cookies, Ghostery, etc., the rest just click "ok" because the sites do not inform them about these aforementioned possibilities: that wouldn't be in their interest.
> Duplicating UI in a website is a solution looking for a problem
Oh I agree it's an issue, I hate this cookie wall as much as anyone. I would love for there to be no need to ever see this wall.
> It has never been enforced that way to my knowledge, anywhere in the EU. Which law or court decision says that it is actually illegal?
I am not sure fines have been dealt, but the Dutch ACM ("authority for consumer and markets", literally translated) did give out warnings to non-compliant sites and they subsequently places cookie walls.
The law simply says no such cookies may be placed, it doesn't say "for a few months while users are unaware, and after that, oh well, have some fun picking your own privacy laws as you wish."
And yes, I know functional cookies and simple tracking is allowed if you don't invade a person's privacy. This means practically every major website knowingly tries to invade your privacy, because they have these walls in place. What do people say? "Fucking government does not understand the internet, look at all these walls." What should we be saying? "Wait why are they trying to create detailed profiles of me in the first place?"