Cookies are a simple yes/no question, with the default answer being no. If everyone did what's in the users' best interests, it would be a non-issue.
Cookies are a simple yes/no question, with the default answer being no. If everyone did what's in the users' best interests, it would be a non-issue.
This entire EU regulation is a non solution to a not really existing problem. Yes, third party advertisers use cookies to track you. But they can build technologies to use something else. In the meantime you are a) breaking the internet b) wasting hours of each EU citizens time every year.
Matomo was formerly known as Piwik
* It helps me focus on the content my users need the most, and see what triggers donations.
* It helps me catch and diagnose traffic dips, and react to them.
* It helps me catch and diagnose unexpected issues. For instance, caching changes broke a component that accounts for 30% of my revenue. It would have stayed broken for a whole month if I didn't see the dip in events.
I will replace Google Analytics soon, but even as a tech-savvy person, it's a dreadful task. Google Analytics is free, simple, and incredibly reliable. Setting up your own self-hosted alternative, or paying a monthly fee for an alternative is a lot less desirable.
There are alternatives but as you say sadly none are as easy - probably because none have as much budget behind them. I see a number of comparison articles for gdpr compliant analytics, so it seems to have become its own market of sorts.
I have opted myself out of most Google services due to the intrusive nature, I wouldn't want to impose it on my site visitors (but I also have no need to monetize, so maybe a different ballpark).
Just knowing what I need to do requires me to wear my lawyer hat. Actually doing it requires me to wear my developer hat, or to pay other people a monthly fee.
I will eventually move to another solution, but it has an infinitely lower impact on my users than the problems I help them solve.
I will switch this because I swore to do the right thing [1], and because I have a lot of time on my hands. I can't reasonably expect amateur bloggers to do the same. It's an unreasonable burden on people who don't run a website for a living.
If a hospital would in secret sell my medical records to drug companies in order to get free medical supplies I would object on several grounds. First because they are doing it without telling me. Second because its not their data to sell. Third because it create an unfair market where drug companies who are more ethical get out competed.
They do not ask "can I place cookies"; they ask "Can my third-party trackers and advertisers place markers on your system so that your activity can be tracked across this and other websites".
Don't stare yourself blind on the poorly chosen wording. It's not the "cookie law" either, it's the General Data Protection Regulation. It's not about cookies, it's about regaining control over your personal data, your online behaviour, etc.
Explicitely allowed:
* Cookies for login/session
* Cookies for shopping carts
* Cookies for interface personnalisation (language, etc.)
* Cookies for load balancing
* Cookies to retain user choice regarding cookies
And quite a few other.
1. You can do whatever you need to do to provide the service you're providing. (login cookies, sessions, store their email address, whatever).
2. If you want to process, store, and sell any other user data, you need to ask them first.
So for example if you want to send 100 advertising companies personal data about your users, you need to ask for consent and allow them to decline without restricting their access to you service.
What technology you use to track users is irrelevant, it can be fingerprinting or cookies or anything else.
The only reason why you think the law is bad is because companies are frantically trying to work around it, trying to interpret it in unintended ways to not impact their data tracking ways, and trying to make users hate the law instead of them.
This directive explicitely targets reading/writing into the user terminal without autorisation, hence the application to cookies.
Edit: removed a post, that was not explicative enough.
But the articulation is: ePrivacy says you need to consent to write non-essential trackers. GDPR defines how you can obtain the consent. So both laws take part in this ruling.