There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services.
There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services.
Certainly not. If I didn't check a box saying "I want to receive commercial emails related to your products and services" I expect not to receive those. I might unsubscribe from the whole thing if I don't have any other means of avoiding those useless commercial emails.
Most email marketing service providers don't even support multi-interest opt-out page, or charge a lot for configuring your unsubscribe page this way (like a multiple of list size for each option gasp), so this makes it impossible for email recipients to choose what emails types to opt-out of so marketers in turn don't bother to collect unbundled consent.
Comparison of some market leading ESPs (see multi interest opt out row): https://www.bigmailer.io/bulk-email-marketing-services/
Very much so; the pop-ups interrupt and obstruct, breaking immersion. I sincerely hope a browser gets brave enough to start blocking those obstructions by default.
It irks me how every "Cookies" banner is an unpaid advertising billboard saying, "Your privacy is valuable to us. Yours faithful, EU".
>This too shall pass.
For now, uBlock Origin[1] + the ruleset from I Don't Care About Cookies[2].
--
[1] https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
Here is a trick for website owners: don't track your users. No need for any popup anymore.
You do not need consent for cookies that power basic website functionality or a feature the user is trying to use. So setting a cookie when someone logs in or adds an item to their shopping cart.
Note that they provide notification of necessary cookies, and default opt-out of analytics cookies.
> You do not need consent for cookies that power basic website functionality or a feature the user is trying to use.
This is correct, you do not need consent for necessary cookies. You do, however, have to provide notification that necessary cookies are being set.
> Although the exemption applies to both the provision of information and the gaining of consent, it is good practice to continue to provide clear information about all cookies including those that are strictly necessary, and if personal data is involved then you will be required to do this under the fairness and transparency requirements of data protection law.
I'm not a lawyer and I can't give you legal advice. I can just report that the legal advice that was given to me was that any cookie setting activity needs to be notified, even if consent is not required.
One potential discrepancy is that we are being prepared for the e-Privacy Regulation (which is not yet in effect), while it looks like the page you linked to covers the e-Privacy Directive.
No. It leads to non-acceptance by default. If you are seeing forms where you are opted in to data capture by default that isn't a core part of the service, that's a breach.
Now we are in a sort of transition phase where laws are written but companies interpret them themselves (badly) and there are few guiding cases.
I look forward to the next phase when the notices will be gone or say “did you know you can enable tracking so we show more relevant ads that we get more money for showing?”. I’ll say no regardless of how much I enjoy that content.
Laws are only effectivr if they're enforced, and right now the tracking laws of the GDPR don't appear to be enforced, or have any sort of method for reporting, which is really really disappointing
Currently the country's regulators (such as ICO in the UK) are swamped with GDPR complaints and are prioritising the most egregious cases. I imagine cookies are a way down the list.
In terms of reporting, you tell the company itself first, if you don't get satisfaction you report to your own European country's regulator, or that where the company is based.
We need a standard for managing these controls on the browser side, which major browsers can then implement. It wouldn't surprise me if people were already working on something like that. If I reject ads from google doubleclick specifically, they should be pre-rejected for every subsequent website that asks the same question. Likewise for the various cookie purposes.
(I do understand the unfortunate potential for fingerprinting here...)
Really? Any chance you could share some examples, because my strong impression is that a clear 95% of those I see are not compliant.
If the permissions were managed by the browser then cookies could be managed directly on the client side without server side interference, and preferences could be communicated to the website via headers (like DNT but GDPR requires a lot more granularity, and is also legally enforceable in the EU).
https://www.i-dont-care-about-cookies.eu/
It lets you specify a global setting to what extent you want to be tracked, and communicates that to sites that support the extension's "standard".
Like the "Do Not Track" header field?
https://en.wikipedia.org/wiki/Do_Not_Track
Perhaps it will work if introduced as a GDPR header field.
GDPR does not forbid websites to ask or even deteriorate your experience (afaik). Perhaps that should change.
I wholeheartedly agree on your point though, that if i reject 'A' on one site, it could be assumed by the browser i'd like to reject 'A' on the next site. Perhaps the same kind of block could occur like they do with faulty ssl settings, just stating that you blocked 'A' on some site ,and this site is using the same, with a button to proceed if you accept that fact.
It's illegal. End of.
Note that you can still 'sell' Web content for forcing your customers to see advertisments. You just aren't allowed anymore to track that on a person-by-person basis.
Or the opt out page just leads to instructions to disable cookies in your browser.
not true, i mark all those as spam, if there is a "newsletter checkbox" i check it out, but if they have hidden it somewhere i dont care, mark as spam and next.
No. Most of the services out there require an email to sign up to the service itself. Using that email for anything beyond the core provision of the service I signed up for is a breach. If I bought a fucking pencil sharpener from your website, any communication beyond keeping me abreast of (and optionally checking if I was happy with) my order is abusive.
And this by itself says a lot, but not what people usually think it says.
In fact, you don't need any kind of cookie popups _unless_ they're tracking cookies. Any reasonable use of cookies for site-specific reasons (authentication, session, csrf, load-balancing, settings) is already allowed with no need to opt-in[1].
The reason why cookie popups are so widespread is two-fold:
1. Because indeed most sites track you to death, and are unwilling to back off even if it costs them visits (many people just close the tab upon being presented with all but the least obnoxious popups). In this perspective, the GDPR is working as intended;
2. General ignorance about the cookie exceptions. You can hardly blame the regulators for that. In fact, AFAIK the GDPR clarified a few things that were ambiguous WRT cookies. That backfired horribly, but just beacause ignorance is rampant.
[1] https://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
If the site respect users privacy it will not track the users and don't need the warning
In other words, your privacy has value to them, and they are eager to shaft you that privacy to extract the value.
I have a simple heuristic: if there is a big overlay preventing me from looking at the content, I just disable javascript altogether for the site. Most of the time this result in a clean experience with just the text I was interested in in the first place. If it breaks the article I close the tab.
"Communications" as in "valuable information", like letting you know somebody logged into your account. That's fine and unaffected by the GDPR.
If by "communication" you mean unsolicited advertisements about the company you are describing illegal behavior that was already illegal before the GDPR. "I agree to be contacted for marketing purposes" checkboxes are ubiquitous precisely because without my opt-in they can't.
Indeed, mandatory acceptance is not a meaningful choice and hence explicitly ruled out by the GDPR.
> There is a reasonable expectation that when you submit your email to a company in exchange for their service, they will email you communications relating to their products and services.
Sure, and all necessary use of information is just fine and unproblematic. Just the additional spying on top of that requires an additional, unforced opt-in.
By banning consent bundling GDPR is designed to make this exchange of value illegal.
And no, it's not "reasonable" because it leads to situations where the only way to pay for a service is with your PII.