[1] https://developers.google.com/analytics/devguides/collection...
[1] https://developers.google.com/analytics/devguides/collection...
Do you have a reference for this? It not how I understand GDPR, and I am not clear which part of it would apply here when personally identifying information is not being tracked.
GA pseudoanonymizes visitor data, but the does not exempt site operators from adhering to the consent mechanisms of the GDPR.
What I'm trying to understand is why the addition of an opaque cookie value necessarily changes the situation, such that consent is required.
It's very possible I'm missing something here; genuinely trying to learn what that is.
See article 6 1/a-f for lawfulness of processing.
Without consent there only remain select few conditions, none of which apply to the operation of GA for visitors without a legal contract with the site operator on a different level (ie. customer relationship).
It is only a matter of time..
EU mandated that all websites (residing in EU) to obtain informed consent before they can store or retrieve information on a visitor's computer or web-enabled device.
This is not limited to "cookies". The law doesn't even mention the word "cookie". It covers localStorage and any TBD technology in the future.
There are exceptions for "strictly necessary" like a store would not have to get consent to operate a shopping cart on the website as thats can be considered critical to the purchasing and checking out. However storing what you browsed for recommendation purposes is not, and therefore that would require consent.
There's also optional functionality that can track users via the first party cookie. Passing login id, for example, to GA.
it also sets a third party DoubleClick cookie
I have never witnessed that. Can you link to a site that uses only Google Analytics where that happens?Maybe you confused Analytics and Adsense?
So, I suppose I should have said "can set", though remarketing is very common.
https://developers.google.com/analytics/devguides/collection...
EU mandated that all websites (residing in EU) to obtain informed consent before they can store or retrieve information on a visitor's computer or web-enabled device.
This is not limited to "cookies". The law doesn't even mention the word "cookie". It covers localStorage and any TBD technology in the future.
There are exceptions for "strictly necessary" like a store would not have to get consent to operate a shopping cart on the website as thats can be considered critical to the purchasing and checking out. However storing what you browsed for recommendation purposes is not, and therefore that would require consent.
Are there any website still blocking EU visitors or has that been solved?
I remember when GDPR was introduce lots of website simply decide to shut off EU IP access and redirect them to a page saying not available to EU.
Furthermore, GDPR has caused a massive decrease in the number of newly registered domains that are successfully recognized as spam:
> Prior to the implementation of GDPR, security researchers were able to identify and block 1.8 million newly registered malicious domains in October of 2017 alone. Fast forward to February of 2019 and that number drops to less than 160,000.[0]
And it has caused a major annoyance for the general public, who mindlessly consent to almost every "consent" prompt they are given.[1]
Companies are also at the mercy of their regional government when it comes to compliance. A company in Greece was fined 150,000 euros, not because the law made it illegal to process data in the way they did, but because the reason they provided for processing was the "wrong" one.[2]
> PWC asked its employees for permission to process their personal data when it should have used a different legal basis (combination of contract, legal obligations and legitimate interest). [(2)]
In effect, their effort to follow the law made them break the law, even though their actions were legal under Article 6, Section 1 of the GDPR.[3] This flies in the face of the EU's language in 2018, where they suggested that companies attempt to follow the "spirit of the law" rather than to worry about dotting i's and crossing t's.
Oddly enough, regulators seem to be pleased with this outcome of seemingly arbitrary enforcement.
[0]: http://www.circleid.com/posts/20191213_the_high_cost_of_priv...
[1]: https://www.cnbc.com/2019/05/04/gdpr-has-frustrated-users-an...
[2]: https://iapp.org/news/a/just-say-yes-gdpr-consent-is-not-as-...