It appears the positive opt in requirement of GDPR is being universally ignored by the industry.
It appears the positive opt in requirement of GDPR is being universally ignored by the industry.
I'm also wondering if the cookies thing is actually just the other law, but now we're all having to look at the old "we use cookies" notifications in a GDPR light.
Yes, that seems to be what they're aiming for now. It was originally supposed to come into effect alongside the GDPR last month, repealing the analogous ePrivacy Directive that was (and for now remains) in force, and therefore allowing member states to update their national laws to remove the annoying cookie notification requirements. Sadly, it wasn't ready in time.
However reading cookies (and sending the content to a server) obviously is privacy sensitive, although even then it should be noted that users have full control over the cookies. This makes cookies better than e.g. a profile that's stored on Facebook's servers.
However, if you started to track people explicitly, even without a cookie, you needed to inform the user.
How that law got interpreted as a 'put a pop up on everything' is beyond me. Most sites managed to annoy the user with a pop up, and still were not on the legal side of the law as they did not inform which third parties exactly got the information.
Why didn't the EU step up and gave guidance to stop the madness? No idea. In general, they tend to bury you alive under folders when given half a chance.
I don't know what the cookie law status is today. It was supposed to be superseded by the GDPR, but i think it is still active, together with the GDPR.
Many high-profile sites rely on advertising, and that makes things more complicated, since they have a clear business interest to get and share as much data as possible, instead of a "process only data strictly needed" approach others can take.