Cookie policy notifications have ruined user experience on the web
reddit.com
reddit.com
If a publisher doesn't want to display a GDPR notification to its users there's a simple trick : just don't collect and monetize personal informations!
Exceptions like when you're being ratted out, to many other companies that perform surveillance on you, by a company you have no particular affection for?
http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
(Perhaps surprisingly there is an exemption for "third‑party social plug‑in content‑sharing cookies, for logged‑in members of a social network.")
provider of an information society service explicitly required by the user to provide that service.
For a user logged-in to a social network, the user clearly consents to the social network providing a service. Note that it is not allowed if the user is not logged in to the social network.
EDIT: I see there is an explicit exemption for session cookies: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
Think of it as a 3rd dimension of what's going on where you can retroactively change what you did to something else. http://ansuz.sooke.bc.ca/entry/23
(Though I'd argue that "color" still doesn't meet the core of the copyright problem. E.g., if you drew your own Micky Mouse sketch and published it, you'd probably still get in trouble for copyright violation, even though you never actually copied any material from Disney.
In that case the criteria seems that some humans (the lawyers and judges) believe some other humans (the general public) will reliably associate your drawing with their own concept of Micky Mouse...)
yes reddit and fb and gmail and the like are intentionally crippled when viewed on mobile. why? maybe because the data an app can suck up off your phone is much more valuable. no pesky same-origin policies!
i digress :(
It's still annoying, but not as annoying as trying to click the tiny link.
And then the bottom-bar one, instead of having two buttons, makes the entire field open the app store except for a tiny 'x' in the top right. Talk about unsubtle dark patterns.
Visiting a user page and checking 'top' simply doesn't work, with a note that it will someday. And that's made even worse because the new 'hot' on user pages has some sort of godawful logic that only shows a handful of posts from a given thread. This is painfully apparent with AMAs, where visiting the AMA account and checking all posts is a standard action - after trashing the AMA infrastructure on the business side (the Victoria mess), the same thing is now happening on the tech side.
The new redesign requires every sub to build a new theme just to maintain existing functionality, and is apparently harder to theme for also. I suspect it's an attempt at homogeneity to be more welcoming to new users, but the practical consequence is that sidebars (rules, links, info) have simply vanished. Which means more work for moderators, less info for visitors, and occasionally complete dysfunction for subs that used the sidebar for something important.
And, of course, the redesign is nakedly anti-user in much the same way as the recent TechCrunch one. It's designed to make sponsored-content ads harder to distinguish, sacrifice content space for site features space, and promote time-on-site over user choice and experience.
I retreated to a handful of low-use, well-moderated subs quite a while ago, and with the site changes tarring even those I'll probably give up soon also.
I've even gone to the point of deleting the app on my phone, and, if I have to, I'll open it in mobile browser (and deal with their shit) to check messages/etc in the morning. I need to start trying to wean myself away from it completely, if only to help kill off that online identity.
[1] https://addons.mozilla.org/en-US/firefox/addon/old-reddit-re...
[2] https://chrome.google.com/webstore/detail/old-reddit-redirec...
* Go to your Cookies And Site Data preferences
* Select "Block Cookies And Site Data"
* Click on "Exceptions"
* Add the address of the website you opt-into
* Click "Allow For Session" or "Allow" as you choose.
If this view were more widely adopted, it would maybe pressure browser vendors into being more transparent with users on cookie management and proactively ask them how they want to handle them.
Having cookies be opt-in by default would just punish anyone using cookies for benign purposes.
At a crude estimate, >90% of the sites that show me cookie warnings do everything I actually want them to statelessly. And I have some backup for that, because when I block cookies by default very few sites actually seem to get worse.
Are there clever user-aiding tricks with cookies that I don't realize I'm losing? Or is the average site with cookies purely for tracking and advertising?
(This is all a separate question from "should cookies be blocked by default"; I know a few uses really do suffer badly.)
But I probably sign into <5% of sites I visit, and even many of those are actively user-hostile, like Quora. I understand why Quora wants me to sign in, but from my end of things it's no more worthwhile than being asked to sign into Wikipedia just to read articles.
Broadly, I guess this is a gripe about how my web-use experience has become fundamentally adversarial. Cookies are one of many perfectly reasonable features which I cripple or disable even on respectable top-100 sites because they're used almost exclusively against my interests, but I'm not sure there's a good tech-level fix to that for users in general.
[0] http://www.rkeene.org/viewer/tmp/wwwftp_cgi.c.htm#line182
You can use cookies for necessary operations of the website, which this almost certainly is. Also, country level location data isn't PII, and also doing a geoip lookup that you don't store anywhere also isn't in violation.
However, you have a clear and stated use case for processing that PII so consent is not required, but you are required to mention this processing in your privacy policy. Not publishing this processing is (strictly speaking) a violation of the GDPR, but the processing itself isn't.
From Recital 26 (https://gdpr-info.eu/recitals/no-26/):
> The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.
One datapoint from Germany: We were largely unaffected by cookie notifications before GDPR, because of a local law (TMG) that superseded the EU “cookie law”.
Since GDPR we are in the curious situation that every small and medium sized business plasters it’s website with extravagant opt-in notification pop-ups while the worst privacy offenders, like the nations largest newspapers, bombard you with all kinds of cookies with no notification at all.
Just one example I tried a few moments ago:
spiegel.de one of the most widely read German-language news sites set 54 cookies from lots of different domains plus local storage usage. No cookie notification whatsoever.
Another example: bundesregierung.de, the official government website, states in it’s privacy policy that they set a web analytics cookie (Matomo) but they don’t show a notification either.
Sad thing for them, they won’t be able to pretend they didn’t knew (which will be a good lesson taught)
IMO, you do this when you open the browser. Why does every website need to explain how the internet works?
There are many things that are technically easily possible, but prohibited unless certain nontechnical conditions are met. Tracking cookies is one of them.
Opening a browser doesn't constitute freely opting in to your specific use of data; at most it constitutes not opting out, but that's not legally sufficient.
Does this also apply to localStorage and other offline storage methods?
I'm inclined to believe this + the cookie banners are also a lot of "well site X did it like that, we probably should do that as well" instead of reading and understanding the actual rules.
The easy way out would of course be to not violate the GDPR, but with 3rd party advertisers that's a bit painful.
I still don't know why big publishers don't just own the ads themselves, that is, have an ad department, have them approve ads and return statistics to the advertisers, have tracking all on the same domain, etc.
No matter what your notifications and T&C says, the default UX path where the user clicks "meh, whatever, go on" until the popup disappears won't give the site any legal consent to use data because informed, specific, freely given opt-in consent didn't happen.
That's an asinine law if I ever saw one. Telling me how I should run my business? Really? From what vantage point, if I may ask?
If I had a company, I would ignore the whole thing and invite them to cross the pond and try their crap in my jurisdiction, under my laws. Or just block them altogether. If they want to go back to the middle ages, let them.
I guess the authors understood that without that clause, there would be an obvious loophole that would indeed lead to nothing more than annoying pop-ups and reduce the desired consumer choice to name-only. So they took the logical step to close the loophole.
Of course many businesses are trying to counter with a pop-up anyway. But then, that's not the fault of the regulation.
For the common use cases of data by random websites, there really are two common scenarios GDPR-wise:
1) Whatever you're (not) doing with the user data falls under one of the multiple GDPR valid reasons for use that do not require user consent: in this case a clear and informative description in an easily accessible privacy policy is sufficient, and the notification/"agreement" isn't needed for GDPR compliance, the popup is useless.
2) Whatever you want to do with user data requires user consent, but you're not going to get GDPR-valid (informed, specific, freely given and opt-in) consent. There are specific sites that can get meaningful consent because users really want it (e.g. genealogy sites come to mind), but for the random "we want to track you for advertising purposes and share it with 200 third parties", it's not realistic. And the popups don't (can't) help you with that. A popup that allows you to opt out... well, if it's not opt-in, the consent isn't valid in the first place; if the user goes "meh, whatever", then that doesn't count as opt-in consent. If the user is required to "agree" to continue, then that doesn't count as freely given consent. If the user isn't clearly told everything before they intentionally opt-in to every single use case because they want you to do that particular thing, then that doesn't count as specific, informed consent. If you do implement all these things properly, then most users aren't going to opt-in in the "ad-tracking" scenario (which is the GDPR intended result), so companies don't want to implement it properly.
So the nasty popup doesn't really grant you consent anyway (the process is inevitably missing at least one of these key criteria for valid consent), so GDPR-wise it's useless anyway.
javascript:(function()%7Bvoid([].forEach.call(document.querySelectorAll('body *'),e=>/fixed|sticky/.test(getComputedStyle(e).position)&&e.parentNode.removeChild(e)))%3Bdocument.body.style.overflow%3D'auto'%3Bdocument.body.style.height%3D'auto'%7D)()They don't state it clearly, but every cookie means: "By accepting this cookie you agree to be tracked on the Internet, and allow that data to be sold."
(or, "We don't really understand cookie-law, and we didn't actually need to put this up".)
Once you know that, it's easier to ask yourself: "Do I really need to read this? Also given that it's likely a sub-par publication, because tracking usually implies layouts and techniques optimised to keep you on the site and optimise data collection."
Particularly the egregious dark-pattern ones: "Click this giant green button to let us track you out the wazoo, or click this tiny misleadingly-named link to drag you through a six-hour hell of settings dialogs which will drop you out without actually changing anything the instant it thinks it can get away with it."