The GDPR Is a Cookie Monster
emarketer.com
emarketer.com
On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every visit to the site, where you have to go through the More Options route every time. And if you ever accidentally click I Consent, then they opt you back in to everything again and then never show you that option box ever again.
Note: I just picked on Mashable, but there are many, many sites following this same dark pattern.
> Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject’s acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent.
It breaks some sites, but after saving settings for your more commonly visited ones, you really don't notice it all that much.
> And if you ever accidentally click I Consent, then they opt you back in to everything again and then never show you that option box ever again.
If this is accurate, then this is another violation of the same article, which also states that "The data subject shall have the right to withdraw his or her consent at any time."
As far as I can tell, you've observed that if you force your browser to stop displaying the cookie preferences overlay, the hidden page becomes visible again.
Does this reveal something controversial that I haven't inferred?
It's of course bullshit.
>All results presented here reflect site activity prior to obtaining consent; the picture may change dramatically once the user provides the affirmative opt-in GDPR requires.
So, meh.
Not legal from the perspective of GDPR, sure, but it seems that everyone is doing it.
/edit: downvoted for stating basic facts, amazing.
I get that everyone is super excited about GDPR, but sorry to say most websites can safely ignore it.
Only sites with a presence in the EU are paying attention. The LA Times is a counter-example of a site that hasn't bothered with GDPR because they didn't feel EU users were worthwhile keeping.
However, collecting data on the 0.5 billion people in the EU evidently seemed worthwhile for most sites.
And similar arguments could be made for why American companies would play nice to the EU.
If your company was unable to comply with GDPR, many wouldn't want business with your company anyway, especially other companies who are trying to comply with it.
Except for military force and incarcerations per capita, the US is lagging behind in almost every statistic compared to China or the EU.
> "The fine is really a last resort," she told Computing. "Even to get to the fine we have to go through a lengthy investigation that might take several months, then we have to take it though the courts. So fines are not our go-to tool."
However. I think with egregious cases like selling data. I am happy that the ICO fined a company for doing that. [1].
[0]: https://www.computing.co.uk/ctg/news/3027593/ico-theres-so-m...
[1]: https://www.theregister.co.uk/2018/08/09/ico_fines_data_brok...
Whether this actually works, only time can tell. But the fact that similar previous legislations went unenforced was a specific concern that the designers of the GDPR intended to address.
But for version 2 of GDPR I'd like to see something like: No landing pages. Content must be served on the first request. And no Captchas for Tor users.
The short-term effect of GDPR is ugly interstitial pages and mandatory consent, but that's not the point of GDPR. The point is to make legally collecting user data difficult, annoying, and onerous in the hope that going forward more companies will eventually decide it's more trouble than it's worth. That'll only work if complying actually is a chore.
Call your local news site and complain if they aren't honoring GDPR to the letter. Call your country's ICO and complain to them too. Talk your friends and family into doing the same. Be a pest; the more annoying the better.
As a matter of fact, I do complain a lot, and I do file complaints about GDPR violations, but convincing my friends and family to even care about this stuff is science fiction (I've tried for over a decade now without success).
Business and engineering culture around website construction is horribly broken with regards to user privacy. Changing that culture is going to take years of consistent pressure which existing interests are going to fight every step of the way.
In my opinion the ugly consent forms are the best thing about GDPR. A problem that techies have known about for years is now visible (and annoying) to the general public. Of course that doesn't restructure the entire internet overnight, but dragging the problem out of the shadows seems like a pretty good opening salvo.
Most people who complain about this just don't want to admit that they're not actually stating basic facts.
- Wikipedia can serve you pages without knowing anything about you
- You can download and use Debian distribution without providing any data about yourself. Microsoft can do the same.
- Internet shops like Amazon or Ebay don't need to track you. They earn money when you buy something and if they delete PII after the order is completed they still have the money. GDPR is not taking them away.
- Google can work just fine without tracking users. They show advertisement in search results, they get paid for it and they don't need to collect everything you have typed to earn profit
- Youtube can show ads and get paid for it to completely anonymous users
- Android and Google Maps don't need to track you. You paid for them when you bought your device, you don't have to pay once more with your data and opt into dubious "help us improve your user experience" scams.
- Netflix gets money from you anyway and doesn't need to track you
- Facebook doesn't need to track you across the web. It can show ads and get paid for it anyway.
Look around. Most of businesses can earn money without collecting any personal information. The ones who can lose because of GDPR are only shady marketing agencies, legal spam conpanies, data brokers and three-letter agencies. I don't feel sorry for any of them.
We should think about better protection of privacy and anonimity rather than worry about profits of Californian corporations wanting to make everyone their product.
Of course they _can_ serve ads randomly, but they're competing to provide the best value for those buying ads.
That tracking allows them to build more accurate models on what ads a user will click on and then tailor ads to the user causing increased ad click rates which results in more revenue.
And I'm not really concerned about the big companies. I'm concerned about all the news agencies that are barely scraping by with targeted advertising revenue. Remove the targeting and web journalism will get even worse as they have to layoff more people and resort to even more clickbaity news.
Regarding news sites, they have a lot of opportunities to earn money, for example, publish sponsored articles. They can also use subscription model. It is better than have mobile apps that scrap data from your phone, Google Maps that track every your step, and data brokers you never heard of but they have full information about you. We should not sacrifice our privacy only because someone out there cannot make the ends meet.
Google won't shut down if you stop it from tracking users' location. People will still search the internet and buy smartphones.
> In a September 2017 study of 250 US digital marketers by Viant, about 60% of respondents said they will no longer rely on cookies for the majority of their digital marketing within the next two years.
The absence of any description about what they will use instead is frustrating.
This becomes important in the context of third party cookies that want to track you across apps. Hence why cookies are not a reliable method of identification on mobile.
Hope this clears it up. :)
(To clarify, it wouldn’t be particularly odd if companies were found to violate GDPR; but the selective move from cookies to other technologies doesn’t change the legal situation.)
Also being in the EU I'm used to these cookie dialogues, except before GDPR if I wanted to opt-out (assuming that it was even an option) I'd often have to wade through multiple pages, opting-out of the tracking which would take a while, especially since they were usually using every dark pattern in the book.
Now with GDPR I still get the messages but everything is opt-in instead of opt-out and I can just click the (sometimes obfuscated) "I refuse" and carry on. It's actually a huge quality of life improvement as far as I'm concerned.
Is there something I need to configure?
I know, that's so glib that it's laughable. That's the point.
We currently have a status quo where user analytics are very valuable while the cost of collecting them is minimal. That strongly incentivizes site owners to collect and store as much data as possible. In this moment we have a business culture and a set of engineering best practices that's grown up around those incentives.
GDPR changes the incentive structure by imposing a cost on the collection end, in the hope that site operators will start being significantly pickier about what analytics they want to collect, when, and from whom. The end goal is a cultural change in how we collectively build websites. But culture doesn't change on a dime. It takes time for the existing actors to accept and adapt to a new normal, especially one that's more hostile to their interests.
Be pissed off. Pissed off is an appropriate response to the horrible UX you're being exposed to. But be pissed off at the people showing you the horrible UX. It's in their power to stop, they just don't want to.
(Good that I don't generally visit the local Internet much anyway.)
- I don't care about cookies: auto accepts all cookies
- Cookie AutoDelete: auto deletes all cookies
So now you can track me all you want... until I leave your website and all the cookies are gone (unless whitelisted).
https://bugs.chromium.org/p/chromium/issues/detail?id=78093
You'll either have to clear local storage manually or get a privacy-oriented browser.
As a site admin, I have no problem honoring your request to not be tracked. I just can't wait until I don't have to deal with the nightmare that is OneTrust anymore.
https://en.wikipedia.org/wiki/Do_Not_Track
It never ceases to amaze me the number of companies that "value" my privacy but still somehow ignore the do not track header.
I also find the idea of secret shadow profiles to slightly immoral for the same reason.
DNT only works if the assumption is that users who make no choice can be treated as consenting (which is no longer the case under GDPR). But if you set DNT by default you're not asserting "this user doesn't want to be tracked", you're just making it impossible to tell whether the user explicitly opts out or hasn't made a choice (and therefore actually do consent).
If tracking is opt-out rather than opt-in (i.e. if we disregard GDPR and similar privacy laws and go with how US startups have operated so far) that means DNT is no longer a reliable signal for opting out and thus meaningless.
Implications about consent and privacy aside, DNT only works if it is used with intent. In the absence of intent, by making it the default without the user's knowledge, it becomes ambiguous and therefore pointless.
To put it differently: if there had never been any browsers that set DNT by default (except maybe browsers explicitly marketing themselves as "privacy first" like Brave does), you could use DNT as an explicit assertion that you do not consent to being tracked. This means it could actually serve as a technical implementation to opt-out of any "implied consent" allowed by the GDPR and making use of your right to control your data.
But thanks to Microsoft randomly slapping on the header to piss off Google, DNT is now too ambiguous to infer any of that.
It shows some reduction in cookies served before user interaction but it isn't clear is this is due to GDPR or other changes that have been made over the 3 month period.
My summary is that the data found is not statistically significant given the relatively limited sample size and lack of any control sample to compare against showing usual variation over a 3 month period.
Seriously, having to opt-in on a per-site basis has led me to loathe the GDPR. It's a usability disaster. I never thought I'd hate anything more than the "sign up for our newsletter" pop-ups... but these are even more pervasive.
If I'm the kind of person who hates cookies/tracking, I'll just install a blocker and block it everywhere, and then whitelist any domains I need to.
It just makes me feel like the GDPR was a win for lawyers and legalese, and nobody else.
Sounds like P3P ( https://en.wikipedia.org/wiki/P3P )
> Neither side wants these things messing up the browsing experience so, unlike the ad wars, we can work together.
Personally, I absolutely want to know when sites are trying to spy on me and sell the data. Despicable crap like that should be forced out into the public, not quietly agreed to by the browser. That's exactly what GDPR is for.
It's best to assume they're all doing that to some degree whether they tell you they are or not. For one, most of the world isn't beholden to EU law. Also, bad players don't play by the rules and by the time you know they're bad, it's too late.
> Despicable crap like that should be forced out into the public, not quietly agreed to by the browser.
But the cookie law doesn't fix that problem, or any problem for that matter. The notifications are 100% pointless and we're stuck with them because of a stupid law. If anything, having a standard way to block the notices might encourage more users towards a real fix for the tracking problems, which is using something like uBlock Origin (just don't tell that to the site owners that don't want users having tracking blockers).
Note that GDPR doesn't say things like "cookies need a consent form"; rather, it requires that data processing is only performed if a certain valid reason is given. One valid reason is that the service offered by the site couldn't be achieved without the processing. That's fine. If something's not required to perform the service (i.e. shady stuff), the only valid reason for doing it is if consent is given; hence the awful forms.
You shouldn’t be allowed to ask for consent to do tracking or targeting as a pop up. The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data) and any option to consent to anything outside this must be a hidden option.
That is: sites should have to work 100% without popups and shouldn’t be allowed to use “marketing cookies” (for tracking and ad targeting)
Otherwise we just traded one nuisance for another.
I think GDPR does actually say this.
> any option to consent to anything outside this must be a hidden option.
You're right that this would be a difference (although I imagine sites would still end up covered in dark patterns trying to get users to enable it)
Even supposedly serious outlets like WaPo does this. Full screen splash that says “by using the site you agree to targeted ads”. Why even bother with that when it’s so blatantly in violation? Isn’t it almost better to not look like you are deliberately in violation like that?
It’s not even a dark pattern, it’s just a big fat splash explaining how they don’t care about the GDPR and intend to show me targeted ads using tracking cookies.
If this was brought in through regulation, that's a different story.
I could probably make a million dollars selling companies a "customer acquisition score" using phony baloney math if they place my script on their website.
Let’s just ban companies from using the internet! That will stop internet advertising for good. Thank God smart politicians like me care so much.
It certainly seems to help EU citizens, like myself.