Clarifying GDPR
dev.to
dev.to
The cookie notices of old have turned into full-screen modal dialogs that are deliberately designed to be as obnoxious as possible. These dialogs list hundreds of cookies under multiple tabs and are filled with legalese that any normal person will immediately dismiss. A common trick seems to be to have an “accept all” button that is prominently displayed, but if you want to reject every cookie you have to click onto another tab, click a button to toggle all the switches off, then click “save & exit”. The “save & exit” button is often initially off-screen, and the worst offenders even disable elastic scrolling on mobile to make it as annoying as possible to reach. These shenanigans make private browsing mode particularly intolerable. I hope to see a legal judgement that makes these dark UX patterns explicitly illegal, but I’m not holding out hope. Either way, asking users to decide which third-party companies can set cookies is plain stupid and ripe for abuse.
To this lay user, so far this law appears to be a complete disaster for web usability, and business as usual for the big players (Google, Facebook, Quantcast etc). In fact, you could argue that the GDPR concentrates power in the hands of those megacorps. I am a privacy advocate but I think the GDPR is a joke, at least as far as tracking cookies are concerned.
That's pretty much par for course with any regulation. Regulation creates a barrier to entry for new players which means that existing players benefit. Just like Microsoft wants AI regulated now that they're an established and large player in the space.
If there's enough of a net benefit for consumers is a separate issue.
¹ EU companies/organizations have to apply the GDPR to everyone
GDPR is so much hassle right now that hurt small business more than those big Internet giants.
I disagree that the GDPR is "so much hassle". Just look at the checklist in the article, it's nothing special.
Would also be interesting to see a legal critique of the equally common practice of assuming the user gave consent the minute they scroll the page or click anything on it. Seen a few companies argue that, and I suspect it's probably not compliant with GDPR (no matter how they spin it).