> They're not "selling mental-health information" as if they're violating HIPAA or something. They're just ordinary websites with ads and other tracking cookies
> This is more of the silly kind of half-truths that were used to put cookie warnings on nearly every site on the internet. Don't fall for it.
I’d suggest instead that your post is the kind of “silly half-truth” that people shouldn’t fall for.
As the article points out (and which you neglected to mention):
> And in the case of particularly sensitive data, such as health information, this consent must be explicit.
> But the PI investigation found many cookies were installed on people's devices before any consent had been given.
Contrary to your “it’s just an ordinary website, and ordinary websites use cookies, nothing to see here” narrative, these are websites that specialize in giving health advice. The knowledge that a person is seeking advice and tests for indicators re: depression is absolutely sensitive health information (insurance companies and potential employers would happily weaponize that information given half a chance), and the law therefore required explicit consent before using those cookies and forwarding those depression indicator survey answers to third-party marketing data-aggregation affiliates, which these websites did not seek.
This is a clear-cut violation.