But how does one avoid asking every time when cookies are blocked? What other implementation option is possible? This is what cookies are for.
Local storage? Detect if cookies are blocked? Or, simply don't use cookies for purposes other than providing the service - which exempts you from the need to show the message?
This, or as a minimum: Don't track people who has the DNT header set.
But yes, the userbase for those is so small that we can assume that people with the header on simply don't want to be tracked.
These intrusive popups and banners, on the other hand — especially the new post-GDPR in-your-face ones which I have to dismiss before I can even read a simple article — have ruined the user experience of the web. And my ad blocker doesn't seem to be able to block them.
There's a lot of hand wringing about tracking but what harm does it actually do?
Edit: I see somebody chose to express disagreement via mouse rather than keyboard. Interesting.
PS: I didn't downvote, I never do - I'm a downvote-hater :-)
Yes, it is. Although we're constantly updating the code, my team's responsible for a web site for which the data model is nearly a decade old. And the overall business process that it feeds is about 25 years old. We don't know everywhere that the user's data goes in order to export it. Building the support to do so is pretty big. And being able to expunge their data on request is huge, given that data models were constructed without thought to a requirement that the user data be purgeable. It turns out that the requirement isn't quite that broad, but then the legal advice to help determine where it does need to be done isn't cheap.
Strong added value to who? If Google Analytics disappeared tomorrow do you think the average internet user would be at all impacted?
Remember, GDPR is about protecting the user.
For example, do email addresses on the comments on a blog site fall under that protection? If so, there are some agencies in charge of enforcing GDPR that are violating GDPR on their sites...
THat doesn't mean you can't use email addresses without asking; ie if the comment system uses emails to notify people of replies or moderative actions, then it's totally legit to collect it for exactly this purpose.
You only need consent if the personal data collected isn't strictly necessary for the operation of your site, ie if you use tracking cookies and sell emails to advertisers.
That is not unclear at all. They absolutely do.
That doesn't mean you can't have them, but it means you need consent, you need to be clear about how you will use them and you need to let people withdraw consent.
A reasonable person who is even minimally informed about GDPR will know that an email address is covered by GDPR, hence it is "clear".
I want to emphasize - you can be right or wrong about the GDPR, but that's not the same thing as being right or wrong about whether people are confused by it.
I think it should be obvious that debating feelings or perceptions or emotions of other people tends to lead to unproductive interpersonal interactions, but perhaps others have not noticed this phenomenon. I can't imagine winning a debate with someone over whether they are trolling or not. Even if it's really obvious, nobody can see inner motivations for sure.
At the point where one can prove that one part is too (trollish || stupid) I think it is reasonable to limit how much we care about their opinions.
It's not about e-mail addresses. It's about personal information. It's not about what data you can have. It's about how you can use data.
You don't own my personal information, I do. If I give my information to you, you can only use it in whichever ways I consented to when I gave it to you. If you want to use it for something else, you need to ask me again. And you can't just give me a blanket CYA contract to sign just so you can decide later.
This is precisely how it would work in normal everyday social interactions. If I go to a Mom & Pop shop and give them my number so they can call me when my favorite brand of soup is back in stock that doesn't mean they can call me to tell me about random new stuff they carry or give my number away to someone else.
Personal information is owned by the person it is about. It gets murky with aggregates (but the GDPR helps you figure out which ones are still considered personally identifiable) but it's blindingly obvious for things like "enter your e-mail address".
Do you have an e-mail input in a contact form? I'm going to assume that'll be used so you can respond to me although it'd nice of you if you say that explicitly right there on the form. If it's a comment form, why do you need my address? Who will it be shown to? What are you going to do with it? Where will it be stored and how can I tell you to delete it later? That's why you now need to think up a Privacy Policy: these are questions you always had to answer for yourself but now you're legally required to make conscious decisions about this.
Is this too much of a hassle? That likely means you didn't have any good reason to collect that information in the first place. Great! Personal information is a liability and it's better to collect less of it than more. Although that may disappoint future Zuckerbergs, collecting people's private information (even if they give it away voluntarily) imbues a lot of responsibility on you if you don't want to be completely careless. And the GDPR is an example for a policy that gives that responsibility teeth and punishes companies who are careless.
You don't want to store passwords in plaintext. You don't want to hoard credit card details or medical data. Personally identifiable information is no different. The GDPR just provides ways for you to store and use that information legally, in addition to reiterating that privacy and control of your personal information is a human right.
I'm sure there will be a significant price tag just for training people to be compliant with it.